Risky Bulletin Newsletter
December 11, 2024
Risky Biz News: Improperly patched Cleo bug exploited in the wild
Presented by
![Catalin Cimpanu](/static/img/catalin-cimpanu.jpg)
News Editor
The Termite ransomware group is believed to be behind a wave of attacks exploiting an improperly patched vulnerability in Cleo file transfer products.
The attacks started on December 3 and have compromised at least ten organizations, according to security firm Huntress Labs.
The Termite group is exploiting a bug initially patched at the end of October that impacts Cleo file-transfer products such as Harmony, LexiCom, and VLTrader.