ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

4.5% Of Breaches Now Extend To Fourth Parties

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-50623
Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom

CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg.

Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files.

9.899% KEV ransomware
  • Cleo Harmony before 5.8.0.21
  • Cleo VLTrader before 5.8.0.21
  • Cleo LexiCom before 5.8.0.21
moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments)
CVE-2024-55956
Unauthenticated File Upload RCE in Cleo Harmony, VLTrader, and LexiCom

CVE-2024-55956 is an unauthenticated command-execution flaw (CWE-77) in Cleo's managed file transfer products: by default the Autorun directory automatically imports and runs files, so an unauthenticated attacker can import Bash or PowerShell commands that execute on the host. It is triggered over the network with no authentication and no user interaction (CVSS 3.1 score 9.8), by sending crafted import requests to a vulnerable Cleo server. Successful exploitation yields arbitrary command execution on the server, enabling data theft, lateral movement, and ransomware deployment. Any organization running Cleo Harmony, VLTrader, or LexiCom before 5.8.0.24 is affected — typically enterprises using these servers for EDI and partner file exchange. The flaw is actively exploited in the wild: it was added to CISA KEV on 2024-12-17 with known ransomware use (widely attributed to Cl0p), EPSS is 94% (top percentile), and confirmed downstream breaches such as WK Kellogg's have been tied to it.

Do: Upgrade all Cleo Harmony, VLTrader, and LexiCom instances to 5.8.0.24 or later immediately, per the CISA KEV required action to apply vendor mitigations or discontinue use. If patching is delayed, restrict or remove internet exposure of the server. Because exploitation is confirmed and ransomware-linked, inspect the Autorun directory for unexpected imported files, review application logs for executed commands, and hunt for signs of data exfiltration or staging.

9.894% KEV ransomware PoC
  • cleo Harmony before 5.8.0.24
  • cleo VLTrader before 5.8.0.24
  • cleo LexiCom before 5.8.0.24
largetens of thousands of installations (Cleo cites 100,000+ business customers; public internet scans showed roughly 1,000–2,000 exposed instances)
Full article492 words · extracted from helpnetsecurity.com · click to collapse

Security teams can no longer afford to treat third-party security as a compliance checkbox, according to SecurityScorecard. Traditional vendor risk assessments, conducted annually or quarterly, are too slow to detect active threats.

third-party breaches increase

35.5% of all breaches in 2024 were third-party related, a 6.5% increase from 2023. This figure is likely conservative due to underreporting and misclassification. So while you’re updating your firewall rules, somewhere in your supply chain a vendor might be inadvertently letting in the very attackers you’ve been working to keep out.

46.75% of third-party breaches involved technology products and services, a drop from last year’s 75%, signaling a diversification of attack surfaces. File transfer software remained the top third- party breach enabler, with Cl0p exploiting vulnerabilities in Cleo software (CVE-2024-50623 and CVE-2024-55956) to launch large-scale attacks.

Cross-industry technology was four times more commonly exploited than industry-specific technology, reflecting the broad reach of supply chain risks. Retail and hospitality saw the highest third-party breach rate (52.4%), followed by the technology industry (47.3%) and the energy and utilities industry (46.7%).

4.5% of breaches now extend to fourth parties, one breach triggers multiple organizational failures.

Healthcare in the spotlight

The healthcare sector had the most third-party breaches (78) but a below-average rate (32.2%).

Healthcare suffers from the most breaches overall (242 incidents, 24.2% of all breaches), but a smaller percentage of these breaches involve third parties than the cross-industry average. This isn’t due to greater resilience against third-party attacks, but rather reflects the sheer volume of direct attacks targeting healthcare organizations.

A notable source of third-party risk comes not from external vendors but from within an organization’s own corporate family. The risk from subsidiaries and acquired companies represents a blind spot in many security programs. Subsidiaries and acquisitions account for 11.75% of third-party breaches globally.

Ransomware attacks are correlated with third-party breach vectors

There is a significant correlation between ransomware attacks and third-party breach vectors, suggesting that supply chain vulnerabilities are becoming increasingly central to ransomware operations. 41.4% of ransomware attacks now start through third parties.

Cl0p remains the most prolific group but saw its share decrease from 26% to 17% year-over-year. Despite this decline, Cl0p’s share remains more than twice that of the next most active group (17% vs.8.2%). LockBit continues to hold second place despite law enforcement disruption.

Ransomware attacks represented a larger share of third-party breaches (34.6%) than of overall breaches (29.7%), a 4.9% difference.

Singapore (71.4%) had the highest third-party breach rate, followed by the Netherlands (70.4%) and Japan (60%). The US reported a lower rate (30.9%), falling 4.6% below the global average.

“Threat actors are prioritizing third-party access for its scalability. Our research shows ransomware groups and state-sponsored attackers increasingly leveraging supply chains as entry points. To stay ahead of these threats, security leaders must move from periodic vendor reviews to real-time monitoring to contain these risks before they escalate throughout their supply chain,” said Ryan Sherstobitoff, SVP of SecurityScorecard’s STRIKE Threat Research and Intelligence.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/05/27/third-party-breaches-increase/