A critical zero-day vulnerability in Cleo file-transfer software is under active exploitation, about six weeks after the company issued an advisory for a previously disclosed CVE, researchers said ...
Security researchers have warned customers of the popular file transfer software vendor Cleo that a zero-day vulnerability ... which allows command files to be automatically processed, may also ...
Upon inspection, this rogue file invokes the native Import function of the Cleo software to process another file dropped in the temp folder on disk and called LexiCom6836057879780436035.tmp (name ...