Patch or Peril: A Veeam vulnerability incident

While the vulnerability CVE-2023-27532 was made public in March 2023 and subsequently patched by Veeam for versions 12/11a and later for Veeam Backup & Replication software, Group-IB’s Digital Forensics and Incident Response (DFIR) team recently observed a notable incident related to this vulnerability. Author: AlienVault

Related Tags:
svhost

FortiGate

CVE-2023-27532

veeam

VPN

T1555

T1133

ransomware

T1078

Associated Indicators:
2C56E9BEEA9F0801E0110A7DC5549B4FA0661362

107EC3A7ED7AD908774AD18E3E03D4B999D4690C

5E460A517F0579B831B09EC99EF158AC0DD3D4FA

149.28.106.252

149.28.99.61