{"id":2573,"date":"2024-10-11T19:54:11","date_gmt":"2024-10-11T18:54:11","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=2573"},"modified":"2024-10-11T19:54:11","modified_gmt":"2024-10-11T18:54:11","slug":"new-ransomware-attacks-explore-recent-vulnerability-in-veeam-software","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/new-ransomware-attacks-explore-recent-vulnerability-in-veeam-software\/","title":{"rendered":"New Ransomware Attacks Explore Recent Vulnerability in Veeam Software"},"content":{"rendered":"<p><h1>Recent Veeam Vulnerability Exploited in Ransomware Attacks<\/h1>\n<p>\nOne of the significant threats to businesses and organizations in today&#8217;s digital realm involves Ransomware attacks.<\/p>\n<p>Recent findings indicate that attackers are exploiting a vulnerability in Veeam Backup &amp; Replication, a well-established data protection and management software, posing a severe challenge for cybersecurity teams on a global scale.\n<\/p>\n<h2>Veeam Exploit Uncovered:<\/h2>\n<p>\nThe unpatched and misconfigured Veeam Backup &amp; Replication servers have been targeted by ransomware operators, as reported by Sophos, a global leader in cybersecurity solutions.<\/p>\n<p>The vulnerability identified as CVE-2020-10915, is a critical command injection vulnerability.<\/p>\n<p>This vulnerability allows the execution of arbitrary commands, potentially leading to a full system compromise.\n<\/p>\n<h2>Real-world Exploitation:<\/h2>\n<p>\nSophos reported that attackers are breaching certifications by exploiting the exposed software&#8217;s XML External Entity (XXE) Injection vulnerability along with the command injection flaw.<\/p>\n<p>Later, they deploy the Ragnar Locker ransomware noting that the ransomware was present in systems having Veeam\u2019s product.\n<\/p>\n<h2>Preventing Veeam Ransomware Attacks:<\/h2>\n<p>\nConsidering the severity of the vulnerability, it becomes increasingly crucial for businesses and organizations using Veeam\u2019s product to update their systems ASAP.<\/p>\n<p>Patches correcting the CVE-2020-10915 vulnerability were already released in April 2020 with version 9.5.5.<\/p>\n<p>However, systems not updated with these patches are amenable to exploitation.<\/p>\n<p>In addition to patching, it is recommended to review system configurations to prevent unauthorized access.\n<\/p>\n<h2>Conclusion:<\/h2>\n<p>\nIn an era of hyper-connected systems, cybersecurity has become a major concern.<\/p>\n<p>As the Veeam vulnerability situation demonstrates, lax security strategies can result in dire consequences.<\/p>\n<p>It&#8217;s essential to maintain updated systems and never overlook the importance of regular patches and security configurations.\n<\/p>\n<h2>Follow-Up Reading:<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.veeam.com\/kb3145\">Veeam Software Official Technical Update on the vulnerability<\/a><\/li>\n<li><a href=\"https:\/\/community.sophos.com\/kb\/en-us\/134186\">Sophos Advisory Report on Ragnar Locker ransomware<\/a><\/li>\n<li><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-10915\">CVE-2020-10915 Detailed Report by CVE Program<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Recent Veeam Vulnerability Exploited in Ransomware Attacks One of the significant threats to businesses and<\/p>\n","protected":false},"author":1,"featured_media":2574,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-2573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=2573"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2573\/revisions"}],"predecessor-version":[{"id":2614,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/2573\/revisions\/2614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media\/2574"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=2573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=2573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=2573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}