Software company Cleo has issued a patch to resolve a vulnerability affecting its file sharing products, Cleo Harmony, VLTrader, and LexiCom. Initially identified as CVE-2024-50623 and patched earlier, systems were found to still be vulnerable. Cybersecurity firm Huntress discovered the issue and noted that 24 partner organizations, primarily in the consumer products, shipping, and retail supply industries, have been compromised. A malware named Malichus has been deployed by the hackers. Cleo has urged customers to apply the patch and block certain IP addresses exploiting the bug.

Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections – CyberSecurityNews
Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections CyberSecurityNews