https://www.theregister.com/2025/07/02/cl0p_rce_vulnerability/
https://vulnerability.circl.lu/vuln/gcve-1-2025-0002
… According to CIRCL’s summary: “An authenticated endpoint on the Cl0p operators’ staging/collection host passes file-or directory-names received from compromised machines straight into a shell-escape sequence.” Alexandre Dulaunoy, head of CIRCL, said he doesn’t expect the team that developed the data exfiltration tool to take any corrective action to fix the vulnerability. …
Regards