The notorious ransomware group Cl0p has been identified exploiting vulnerabilities in Cleo software tools to target multiple companies. This cyberattack has led to the exposure of sensitive data and the group’s listing of partial victim names on their website as a means of pressuring them for ransom payments. Initially discovered in December, the flaws in Cleo’s software allowed hackers to execute remote code, with Huntress reporting at least 24 impacted victims. Despite Cleo’s attempted patch, the door remained open for exploitation. Cl0p, known for previous attacks on MOVEit, has now claimed responsibility for breaching 66 companies, comprising various industries such as consumer products, logistics, and food suppliers. Following these revelations, the US CISA has included the Cleo vulnerability in its Known Exploited Vulnerabilities list, urging prompt action from federal agencies to mitigate the risks posed by these cyberattacks.