A newly identified security vulnerability in the Cl0p ransomware group’s data exfiltration utility has exposed a critical remote code execution (RCE) flaw that security researchers and rival threat actors could potentially exploit. Alexandre Dulaunoy states that “no official patch or cooperation from the malware authors is expected,” highlighting the unique challenge of vulnerability disclosure in the cybercriminal ecosystem. The vulnerability essentially allows for command injection attacks against the very systems used by the Cl0p group to manage their criminal operations.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 03 Jul 2025 06:35:20 +0000