logo

Akira and Fog ransomware now exploit critical Veeam RCE flaw

ID: 54856b17-ef46-5b40-a25f-3e8cfadb3234

STIX ID: report--54856b17-ef46-5b40-a25f-3e8cfadb3234

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical deserialization RCE vulnerability (CVE-2024-40711) in Veeam Backup & Replication was disclosed and patched in September; proof-of-concept code was released after a delay but attackers quickly weaponized the flaw. Sophos X-Ops observed Akira and Fog ransomware deployments leveraging the Veeam flaw alongside compromised VPN credentials to create local admin accounts and exfiltrate backups (rclone), and the report notes prior Veeam exploits used by financially motivated groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.