Ransomware Gangs Exploit Critical Vulnerability In Veeam
ID: fdc6f184-216e-5844-a0b2-19187233f26f
STIX ID: report--fdc6f184-216e-5844-a0b2-19187233f26f
Feed Name: Cyble Blog
Veeam Backup & Replication contains a critical unauthenticated remote code execution vulnerability (CVE-2024-40711, CVSS 9.8) that has been exploited in the wild to deploy Akira and Fog ransomware and exfiltrate data; thousands of internet-exposed instances were identified, attackers leveraged exposed VPN gateways and port 8000 to trigger Veeam processes, create privileged local accounts (e.g., “point”), and use tools like rclone, while Veeam released patches in early September 2024 and organizations are urged to patch, restrict exposure, enforce MFA, and monitor for indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
