Security News

Are Your SaaS Backups as Secure as Your Production Data?
2024-05-23 11:14

Conversations about data security tend to diverge into three main threads: How can we protect the data we store on our on-premises or cloud infrastructure? What strategies and tools or platforms...

Veeam fixes auth bypass flaw in Backup Enterprise Manager (CVE-2024-29849)
2024-05-22 08:32

Veeam has patched four vulnerabilities in Backup Enterprise Manager, one of which may allow attackers to bypass authentication and log in to its web interface as any user.Veeam Backup Enterprise Manager is an application that is used to manage the Veeam Backup & Replication solution - a backup/restore app for virtual and physical machines and cloud-based workloads - via a web console.

Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass
2024-05-22 03:45

Users of Veeam Backup Enterprise Manager are being urged to update to the latest version following the discovery of a critical security flaw that could permit an adversary to bypass authentication...

Veeam warns of critical Backup Enterprise Manager auth bypass bug
2024-05-21 22:24

VBEM is a web-based platform that enables administrators to manage Veeam Backup & Replication installations via a single web console. It's important to note that VBEM isn't enabled by default, and not all environments are susceptible to attacks exploiting the CVE-2024-29849 vulnerability, which Veeam has rated with a CVSS base score of 9.8/10. "This vulnerability in Veeam Backup Enterprise Manager allows an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user," the company explains.

Week in review: Veeam fixes RCE flaw in backup management platform, Patch Tuesday forecast
2024-05-12 08:00

Veeam fixes RCE flaw in backup management platformVeeam has patched a high-severity vulnerability in Veeam Service Provider Console and is urging customers to implement the patch. May 2024 Patch Tuesday forecast: A reminder of recent threats and impactThe thunderstorms of April patches have passed, and it has been pretty calm leading up to May 2024 Patch Tuesday.

Veeam fixes RCE flaw in backup management platform (CVE-2024-29212)
2024-05-08 09:06

Veeam has patched a high-severity vulnerability in Veeam Service Provider Console and is urging customers to implement the patch. Veeam Service Provider Console is a cloud platform used by managed services providers and enterprises to manage and monitor data backup operations.

Sophos Study: 94% of Ransomware Victims Have Their Backups Targeted By Attackers
2024-04-12 15:44

The Sophos research revealed the extent of the popularity and effectiveness of ransomware groups targeting corporate backups. Only 26% of companies with compromised backups were fully recovered within a week, compared to 46% of those without compromised backups.

Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrators
2024-01-19 11:24

In the current digital landscape, data has emerged as a crucial asset for organizations, akin to currency. It’s the lifeblood of any organization in today's interconnected and digital world. Thus,...

Akira ransomware attackers are wiping NAS and tape backups
2024-01-12 14:06

NCSC-FI has received 12 reports of Akira ransomware hitting Finnish organizations in 2023, and three of the attacks happened during Christmas vacations. "Of the ransomware malware cases reported to the Cybersecurity Center in December, six out of seven involved Akira family malware," they added.

Finland warns of Akira ransomware wiping NAS and tape backup devices
2024-01-11 15:01

The Finish National Cybersecurity Center is informing of increased Akira ransomware activity in December, targeting companies in the country and wiping backups. Wiping the backups amplifies the damage of the attack and allows the threat actor to put more pressure on the victim as they eliminate the option of restoring the data without paying a ransom.