Cleo is a vulnerability tracked by ThreatCluster, appearing in 8 threat clusters built from 7 intelligence report mentions.
Cleo is a vulnerability tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity July 24, 2026.
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP…
Two critical vulnerabilities, CVE-2026-2699 and CVE-2026-2701, have been identified in Progress ShareFile's Storage Zones Controller, allowing unauthenticated attackers to perform remote code execution and potentially…
Dartmouth College has confirmed a data breach involving the Clop extortion gang, which leaked data stolen from its Oracle E-Business Suite servers. The breach notification revealed that at least 1,494 Maine residents…
The Clop ransomware group is conducting a data extortion campaign against Gladinet CentreStack file servers. This attack exploits multiple security vulnerabilities in CentreStack and its related product, Triofox,…
DoorDash confirmed a data breach that occurred on October 25, 2025, when an employee fell victim to a social engineering scam. The breach exposed personal information including names, email addresses, phone numbers, and…
Dartmouth College has confirmed a data breach resulting from an attack by the Clop extortion gang, which exploited a zero-day vulnerability in its Oracle E-Business Suite. The breach occurred between August 9 and August…
The Clop ransomware gang breached the University of Phoenix's network in August 2025, compromising the data of nearly 3.5 million students, staff, and suppliers. The university disclosed the breach on its official…
DoorDash confirmed a data breach on October 25, 2025, where an unauthorized third party accessed personal information of customers, delivery workers, and merchants. The breach was caused by an employee falling victim to…
Cleo is a vulnerability tracked by ThreatCluster, appearing in 8 threat clusters built from 7 intelligence report mentions.
The most recent intelligence report mentioning Cleo on ThreatCluster is dated July 24, 2026. Activity was first observed October 29, 2025, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, Cleo most frequently co-occurs with Midnight Blizzard, Volt Typhoon, Data Breach, DDoS, Phishing, among 12 tracked related entities.
The most significant recent cluster is “Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM” (9 articles · Updated July 24, 2026). Cleo appears across 8 threat clusters in total, listed above with sources.
Cleo appears in 7 intelligence report mentions across 8 deduplicated threat clusters, aggregated from 17,000+ monitored sources.