// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H→
The Termite ransomware group breached Aon by exploiting CVE-2024-50623 in Cleo file-transfer software. The vendor's initial 5.8.0.21 patch proved ineffective; version 5.8.0.24 is the first working fix.

The Termite ransomware group compromised Aon on October 6, 2026, with public disclosure on October 7, 2026. Initial access came through CVE-2024-50623, a vulnerability in Cleo managed file-transfer products. The vendor's patch in version 5.8.0.21 proved ineffective: systems believed to be protected remained exposed to exploitation until the subsequent 5.8.0.24 update.

Key Takeaways
  • Aon was compromised on October 6, 2026 by Termite; public disclosure followed on October 7, 2026.
  • The vector is CVE-2024-50623 in Cleo LexiCom, VLTransfer, and Harmony, enabling unauthenticated RCE.
  • The initial 5.8.0.21 patch did not fix the vulnerability; version 5.8.0.24 is the first effective fix.
  • Termite enumerates network shares, deletes shadow copies, stops security and backup services, then encrypts files.

The Vector: From Unauthenticated Upload to Remote Execution

CVE-2024-50623 is classified as a critical vulnerability. According to Cleo's vendor advisory, the flaw resides in an unrestricted file upload/download mechanism in Harmony, VLTrader, and LexiCom. Abuse of this functionality leads to remote code execution without prior authentication.

The severity is maximal because it requires no valid credentials or user interaction, making exploitation scalable and automatable. Huntress documented in-the-wild exploitation of this vulnerability starting in December 2024, with at least 10 victims identified in the initial wave.

The Patch Gap: 5.8.0.21 Gave Defenders a False Sense of Security

Cleo released version 5.8.0.21 as its initial response to the vulnerability. However, technical sources verified that the fix did not actually mitigate the defect. Huntress Labs recreated a proof-of-concept confirming the vulnerability persisted on fully patched systems. Beazley Security reported that systems updated to 5.8.0.21 continued to suffer active exploitation.

"even systems updated to version 5.8.0.21 were reportedly vulnerable, suggesting the group's exploitation techniques are sophisticated and may bypass existing patches" — Rescana, citing Splunk analysis

The discrepancy between the released patch and the effective patch created a particularly dangerous exposure window: organizations that had promptly applied the update found themselves in a state of false security. Cleo subsequently released version 5.8.0.24, which sources indicate is the actual corrective fix. The exact date of this second release is not specified in the available dossier.

What Termite Does After Initial Access

Once a foothold is established, the Termite group deploys a chain of actions geared toward maximum disruption. According to Splunk's technical analysis, the malware uses the SHA256 hash 30a8cf3e6863030c762b468bf48d679f3dd053a80793770443938fa18de89617.

Documented techniques include enumeration of network shares via the Windows WNetOpenEnum and WNetEnumResourcesW APIs. The group deletes shadow copies with vssadmin.exe to prevent data recovery. It stops security and backup services via ControlService(). It accesses protected drives using SetVolumeMountPoint().

Termite has a consolidated track record. It previously attacked Blue Yonder in the supply-chain sector. It hit Genea in Australia in the healthcare sector with approximately 940 GB of data exfiltrated. It has targeted organizations in consumer products, trucking, shipping, and food services.

Why This Case Matters Beyond a Single Victim

The case extends beyond Aon, which manages sensitive client and policy data in the risk-management and insurance sectors. More than 4,200 businesses use Cleo software, with public customer names including New Balance, Barilla America, and TaylorMade.

The exposure is sector-wide: managed file-transfer platforms are critical infrastructure for B2B exchanges, often with direct access to ERP and logistics systems. The systemic issue is independent patch verification. When a vendor declares a corrective update, the security community lacks automated tools to confirm its effectiveness.

Reverse engineering and testing are required—work that, in the Cleo case, was performed by Huntress Labs. The interval between the initial patch and the effective patch was actively exploited by attackers.

Immediate Actions

Organizations using Cleo products must verify they have installed version 5.8.0.24, not 5.8.0.21. Beazley Security confirms that versions prior to 5.8.0.24 are affected by the vulnerability.

Organizations should check logs for signs of CVE-2024-50623 exploitation, particularly unauthorized file uploads in Harmony, VLTrader, and LexiCom products. They should scan their networks for the SHA256 hash 30a8cf3e6863030c762b468bf48d679f3dd053a80793770443938fa18de89617.

They should monitor for network share enumeration, execution of vssadmin.exe for shadow-copy deletion, and stopping of security and backup services. These actions are indicators of compromise consistent with Termite's documented TTPs.

Provenance Limits

The report of the Aon attack comes from Rescana, which cites HookPhish as the source of the October 7, 2026 disclosure. Technical confirmation of Termite's TTPs, the ineffectiveness of the 5.8.0.21 patch, and the correction in 5.8.0.24 comes from Splunk, Huntress, and Beazley Security.

However, these technical sources do not independently verify the specific victim Aon. No official statement has been released by Aon or law enforcement at the time of publication. The volume and nature of any data compromised in this specific attack are not detailed in public sources.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. rescana.com
  2. beazley.security
  3. support.cleo.com
  4. splunk.com
  5. hookphish.com
  6. huntress.com