Aon Ransomware Claim Reopens Cleo CVE-2024-50623 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Insurance and risk-advisory giant Aon surfaced in cybersecurity headlines on October 7, 2026, after researchers and outlets including Rescana and BleepingComputer flagged renewed activity tied to the Termite ransomware group’s exploitation of a two-year-old flaw in Cleo’s managed file-transfer software. The claim is still developing. As of this writing, there is no public confirmation that Aon itself was breached, encrypted, or had data stolen, and the exact link between Termite and any Aon-specific incident remains unverified. What is well documented, and worth unpacking in detail, is the vulnerability at the center of the story: CVE-2024-50623, a flaw in Cleo’s file-transfer products that has haunted enterprise networks since late 2024.

Aon Named in Fresh Ransomware Reports, But Key Facts Remain Unconfirmed

Aon’s name began circulating alongside the Termite ransomware group in reports published this week. The coverage ties back to exploitation of Cleo’s file-transfer software, a vulnerability class that has repeatedly drawn ransomware crews looking for a fast path into corporate networks. Multiple named outlets picked up the story, but none of the public reporting reviewed so far pins down the incident date, the systems Termite allegedly accessed, any ransom demand, or the volume of data supposedly taken from Aon. Aon has not issued a public statement confirming or denying an intrusion.

That gap matters for anyone trying to size up the real risk here. A company being named in a ransomware report is not the same as a company being breached. Ransomware groups routinely claim victims on leak sites to pressure them into paying, and those claims sometimes don’t hold up under scrutiny. Until Aon confirms or a forensic investigation becomes public, the responsible read is that Termite’s history with the Cleo vulnerability is confirmed, while its application to Aon specifically is not.

Who Is Termite? The Group Researchers Have Linked to Cleo Exploitation

Termite emerged as a name researchers attached to a wave of file-transfer attacks in December 2024. Security researcher Kevin Beaumont was among the first to call out the pattern publicly, writing that “Termite ransomware group operators (and maybe other groups) have a zero day exploit for Cleo LexiCom, VLTransfer, and Harmony,” a claim reported by Help Net Security. That single observation kicked off a scramble among incident responders, who began finding the same exploitation chain across dozens of Cleo installations within days.

Attribution to Termite specifically was reported as uncertain at the time, and it still carries that caveat in the current Aon-adjacent reporting. Ransomware groups don’t always operate with clean boundaries. Access brokers sell footholds, affiliates rebrand, and the same exploit chain can get reused by more than one crew. That ambiguity is a normal feature of ransomware reporting, not a sign that the underlying vulnerability data is shaky.

CVE-2024-50623: The Vulnerability That Keeps Resurfacing

CVE-2024-50623 is an unrestricted file-upload and download vulnerability in Cleo’s file-transfer products that can lead to remote code execution. It affects versions of Cleo Harmony, Cleo VLTrader, and Cleo LexiCom prior to 5.8.0.21. Cleo advised customers to upgrade to that version to close the hole. The bug was first disclosed in October 2024, then reported as actively exploited in the wild by December 2024, a timeline that lines up with Beaumont’s research and the broader wave of incident-response reports that followed.

What made this flaw particularly stubborn is that the first patch didn’t fully close the door. Incident responders at Huntress found that systems running the patched 5.8.0.21 build were still exploitable through a related code path, telling researchers that “this vulnerability is being actively exploited in the wild and fully patched systems running 5.8.0.21 are still exploitable.” That finding forced Cleo to revisit its fix and pushed the vulnerability’s effective remediation timeline out further than customers expected, which helps explain why a flaw from late 2024 is still generating headlines nearly two years later.

Why File-Transfer Software Keeps Drawing Ransomware Attention

Managed file-transfer tools like Cleo Harmony, VLTrader, and LexiCom sit in a uniquely exposed spot. They’re built to move sensitive files between a company and its partners, so they typically have inbound internet access, broad permissions to the file system, and connections to internal networks that process orders, invoices, and shipping data. A single flaw in that layer gives an attacker both a way in and a direct line to valuable business records, without needing to pivot through a less-exposed system first.

Ransomware crews have caught on to this pattern over the past several years. Rather than phishing individual employees one at a time, groups increasingly hunt for a single unpatched edge appliance or file-transfer gateway that can unlock dozens of downstream victims at once. Cleo’s products fit that profile. Enterprise customers often run them unattended, patch cycles lag, and the software’s core job, accepting files from outside parties, makes it hard to lock down without breaking business processes.

Timeline: From Disclosure to the Latest Aon Headlines

The table below lays out the public timeline for CVE-2024-50623, built from vendor advisories and the research cited above. The final row reflects this week’s reports, which remain unconfirmed pending an official Aon statement or independent forensic findings.

DateEventStatus
October 2024CVE-2024-50623 publicly disclosed as an unrestricted file-upload/download flaw in Cleo Harmony, VLTrader, and LexiComConfirmed
December 2024Kevin Beaumont flags Termite’s exploitation of Cleo products; reported as actively exploited in the wildConfirmed
December 2024Huntress finds systems on patched version 5.8.0.21 remain exploitable via a related code pathConfirmed
Late 2024-2025Cleo issues further guidance; customers urged to fully update and review exposureConfirmed
October 7, 2026Aon named in reports connected to Termite’s Cleo exploitation; incident specifics not verifiedUnconfirmed

Cleo’s Affected Products at a Glance

Each of Cleo’s three flagship file-transfer products carried the same underlying flaw, since they share core components. The table below summarizes what’s publicly documented about the vulnerable versions and the fix.

ProductVulnerable VersionsRemediation VersionVulnerability Type
Cleo HarmonyPrior to 5.8.0.215.8.0.21, plus follow-up guidanceUnrestricted file upload/download, RCE path
Cleo VLTraderPrior to 5.8.0.215.8.0.21, plus follow-up guidanceUnrestricted file upload/download, RCE path
Cleo LexiComPrior to 5.8.0.215.8.0.21, plus follow-up guidanceUnrestricted file upload/download, RCE path

Market Impact: What a Ransomware Claim Against a Risk Advisor Would Mean

Aon isn’t just any company in this story. It’s one of the world’s largest insurance brokers and a major underwriter and advisor on cyber risk itself, which is exactly why a ransomware claim tied to its name draws outsized attention even before any facts are confirmed. If Aon were confirmed as a Termite victim through a Cleo-adjacent flaw, the irony would be sharp: a firm that sells cyber-risk guidance to other companies caught by the same category of enterprise software exposure it advises clients to patch.

That irony is also exactly why skepticism is warranted until confirmation lands. Ransomware groups have an incentive to name high-profile targets, confirmed or not, because the headline value alone can pressure a company into early engagement with negotiators. Markets and clients watching this story should separate the reputational risk of being named from the operational risk of an actual confirmed breach, since the two carry very different consequences for insurance pricing, client trust, and regulatory exposure.

Competitive Comparison: Cleo vs. Other Enterprise File-Transfer Targets

Cleo’s products aren’t the first managed file-transfer platform to end up at the center of a ransomware or data-theft campaign, and they almost certainly won’t be the last. Progress Software’s MOVEit Transfer was hit by a mass-exploitation campaign in 2023 tied to the Cl0p group, which used a SQL injection flaw to pull data from a large number of downstream organizations connected through law firms, universities, and government contractors. Fortra’s GoAnywhere MFT suffered a similar fate the same year, also linked to Cl0p, through a deserialization bug that let attackers create new admin accounts remotely. Accellion’s legacy File Transfer Appliance was targeted even earlier, in 2021, in a campaign that again fed into Cl0p’s extortion pipeline.

The pattern across all four cases, including Cleo, is strikingly consistent. A single flaw in software built to move files between organizations becomes a mass-exploitation event because so many unrelated companies run the same product with internet-facing exposure. Where Cleo’s situation diverges is in the drawn-out patch saga. MOVEit and GoAnywhere both saw their critical flaws closed in a single round of patching. Cleo needed more than one pass before researchers stopped finding exploitable paths on “fixed” systems, which extended the exposure window and likely explains why exploitation reports are still surfacing in 2026, two years after initial disclosure.

Industry Voices on Ransomware Risk and Incident Response

Separately from the Aon-specific claims, Aon’s own cyber-risk executives have spoken publicly in recent commentary about the broader ransomware landscape their clients face, a backdrop that frames why a story like this draws attention regardless of its final outcome. Christian Hoffman, Chief Executive Officer of Cyber Solutions North America at Aon, has said plainly that “companies of all sizes and in all industries are at risk of a ransomware attack,” a view he shared in commentary carried by AM Best.

Adam Peckman, Aon’s Head of Cyber Solutions for Asia Pacific, has made a similar point about how the response side of these incidents has changed. “The response to ransomware has become increasingly more complex,” Peckman wrote in an Aon blog post on ransomware resilience. He also flagged a shift in extortion tactics that fits the pattern seen in file-transfer attacks like the Cleo campaign, noting that “bad actors continue to target sensitive data and leverage online platforms to amplify reputational harm on the targeted business and data subjects, at times through direct harassment of employees, customers, or executives.”

Those comments were made as general industry observations, not as statements about any specific Aon incident, but they’re a useful lens for reading this week’s reports. If Termite or any other group did obtain data through a Cleo-linked compromise, the playbook Peckman described, public pressure campaigns aimed at reputational damage rather than pure system lockout, is exactly the model file-transfer-focused ransomware groups have followed since the Cl0p-driven MOVEit and GoAnywhere waves.

Historical Context: A Two-Year-Old Flaw Still Making News

It’s unusual for a vulnerability disclosed in October 2024 to still be generating fresh headlines in October 2026. Most CVEs tied to a ransomware wave fade from the news cycle within a few months of the initial patch. CVE-2024-50623’s longevity traces back to three compounding factors: the multi-stage patch failure Huntress documented, the broad base of enterprise customers who treat file-transfer appliances as low-maintenance infrastructure, and the fact that ransomware groups tend to revisit known-good exploit chains against networks that never fully remediated.

That last point is the one security teams underestimate most often. An unpatched or partially patched file-transfer appliance doesn’t become safe just because the initial exploitation wave moved on to new headlines. Attackers maintain lists of previously vulnerable infrastructure and periodically rescan for systems that were never fully brought current, which is a plausible explanation for why a Termite-linked campaign tied to Cleo is still surfacing new named victims years after the original disclosure.

What to Watch: Five Predictions for the Weeks Ahead

  • Aon will likely face pressure to issue a public statement confirming or denying the breach claim, given its visibility as a major insurer and the reputational stakes of staying silent.
  • Expect incident-response firms and researchers to publish updated scans of internet-facing Cleo installations still running pre-5.8.0.21 builds, since mass-scan follow-ups are standard after a named victim resurfaces an old CVE.
  • If Termite’s involvement is eventually confirmed, cyber insurers, Aon included, will likely use the case internally to tighten underwriting questions around file-transfer software patch cadence.
  • Other Cleo customers who never fully remediated CVE-2024-50623 should expect their own names to surface in ransomware leak-site claims over the coming months, following the same delayed-exposure pattern seen with MOVEit and GoAnywhere.
  • Regulators and cyber-risk analysts will likely cite this story, confirmed or not, as another argument for mandatory patch-verification audits on internet-facing file-transfer software, not just initial patch deployment.

What Companies Running Cleo Software Should Do Now

Regardless of how the Aon story resolves, any organization still running Cleo Harmony, VLTrader, or LexiCom should treat this week’s headlines as a prompt to re-verify patch status rather than assume a 2024 update settled the matter. Confirm the installed version is current, re-check for the secondary exploitation path Huntress identified even on “patched” systems, and review outbound network logs for unusual file-transfer activity dating back to late 2024. Given how many months passed between disclosure and full remediation guidance, a surprising number of installations may still be exposed without anyone realizing it.

Security teams should also treat any named-victim ransomware claim, Aon’s included, as a trigger to check their own exposure rather than dismiss it as someone else’s problem. The same exploit chain Termite used against one Cleo customer works identically against any other unpatched instance, which is precisely the dynamic that turned a single vulnerability disclosure into a two-year string of ransomware headlines.

Frequently Asked Questions

Has Aon confirmed it was hacked?
No. As of October 7, 2026, Aon has not publicly confirmed a breach, ransomware encryption, or data theft. Reports have named Aon in connection with Termite’s exploitation of a Cleo vulnerability, but incident-specific details have not been independently verified.

What is CVE-2024-50623?
It’s an unrestricted file-upload and download vulnerability in Cleo Harmony, Cleo VLTrader, and Cleo LexiCom that can lead to remote code execution. It affects versions prior to 5.8.0.21.

Who is the Termite ransomware group?
Termite is a ransomware group that researchers, including Kevin Beaumont, linked to active exploitation of the Cleo vulnerability starting in December 2024. Attribution of specific later incidents to Termite, including any link to Aon, has been reported with uncertainty.

Is updating to Cleo version 5.8.0.21 enough to be safe?
Not necessarily on its own. Huntress found that some systems running the patched 5.8.0.21 build remained exploitable through a related code path, so organizations should confirm they applied Cleo’s full follow-up guidance, not just the initial version bump.

How does this compare to the MOVEit and GoAnywhere breaches?
All three involve a single flaw in managed file-transfer software that let a ransomware or extortion group access many downstream organizations at once. Cleo’s case stands out because the vulnerability required more than one round of patching before researchers stopped finding exploitable paths.

What should companies still running Cleo software do?
Verify the installed version is current, confirm the secondary exploitation path has been closed, and audit file-transfer and network logs going back to late 2024 for signs of unauthorized access.

Why is a cyber insurer like Aon being named in a ransomware story notable?
Aon is one of the largest cyber-risk advisors and insurance brokers in the world. A confirmed breach at a company that underwrites and advises on cyber risk would carry outsized reputational weight, which is part of why the claim drew wide attention even before any facts were verified.

Where can I check if a vulnerability is being actively exploited?
The National Vulnerability Database entry for CVE-2024-50623 and vendor advisories from Cleo remain the most reliable starting points for checking current exploitation status and remediation guidance.

——————————————————–


Click Here For The Original Source.

.........................