Cl0p broke into Cleo with two zero-days — and the first patch didn't stop them
The group systematically exploited CVE-2024-50623 and CVE-2024-55956 in Cleo MFT products between October and December 2024, affecting over 180 organizations. The October patch failed; a second CVE had to be issued six weeks later.