12 Dec 2024
Biztonsági szemle
Intrusions leveraging widespread Cleo zero-day underway
Attackers using U.S., Canadian, Moldovan, Lithuanian, and Dutch IP addresses targeted vulnerable Cleo LexiCom, Harmony, and VLTrader instances to facilitate the writing of new files into the targeted endpoints' autorun directory, triggering the deployment of XML configuration-containing ZIP files.
Read more