Vendor
Veeam ONE Security Bypass Vulnerability
1 TTP 1 CVEA vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.
Information Disclosure Vulnerability in Veeam Backup & Replication
1 TTP 1 CVEA local information disclosure vulnerability in Veeam Backup & Replication, identified as CVE-2024-40713, allows authenticated local attackers to gain unauthorized access to sensitive data.
Multiple Critical Vulnerabilities in Veeam Backup and ONE Products
Multiple vulnerabilities, including CVE-2026-58070 and CVE-2026-65641, affect Veeam Backup & Replication and Veeam ONE, potentially allowing unauthorized access to sensitive backup data and security policy bypass.
The Gentlemen Ransomware Group Activity
1 rule 3 TTPsThe Gentlemen ransomware group leverages VPN/firewall exploits to gain initial access, utilizes BYOVD techniques to disable security tools, and propagates ransomware via the NETLOGON share.
Multiple Vulnerabilities in Veeam ONE
2 TTPsVeeam ONE is affected by multiple security vulnerabilities that may allow a remote attacker to achieve arbitrary code execution, perform SQL injection, disclose sensitive information, or escalate privileges.
Veeam Backup & Replication: Vulnerability Enables Privilege Escalation
1 TTPA vulnerability in Veeam Backup & Replication allows a local attacker to escalate privileges on the affected system.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 5 CVEs 178 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
Vulnerability in Veeam Backup & Replication Allows Privilege Escalation
1 IOCA privilege escalation vulnerability has been discovered in Veeam Backup & Replication, affecting versions prior to 12.3.0.65, which allows an attacker to elevate their privileges within the system.
Vulnerability in Veeam Backup & Replication Allowing Remote Code Execution (CVE-2026-44963)
3 rules 2 TTPs 1 CVE 2 IOCsA critical remote code execution vulnerability, tracked as CVE-2026-44963, has been discovered in Veeam Backup & Replication versions prior to 12.3.2.4854, which could allow an unauthenticated attacker to execute arbitrary code on affected systems, leading to full compromise of the backup infrastructure and potential data exfiltration or destruction.
Multiple Vulnerabilities in Veeam Products Allow Remote Code Execution
2 rules 1 TTP 1 CVEMultiple vulnerabilities in Veeam ONE and Service Provider Console allow remote code execution (CVE-2026-32998) and an unspecified security issue, potentially leading to complete system compromise.
Multiple Vulnerabilities in Veeam Backup & Replication
2 rules 1 TTP 2 CVEsMultiple vulnerabilities in Veeam Backup & Replication prior to version 13.0.2.29 allow an attacker to cause privilege escalation and compromise data integrity.
Windows Service Installed via an Unusual Client for Privilege Escalation
2 rules 1 TTPIdentifies the creation of a Windows service by an unusual client process, which can be leveraged to escalate privileges from administrator to SYSTEM by exploiting misconfigurations or vulnerabilities in the service creation process.
Persistence via Windows Installer (Msiexec)
3 rules 3 TTPsAdversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.
Potential Veeam Credential Access via SQL Commands
2 rules 5 TTPsAttackers can leverage sqlcmd.exe or PowerShell commands like Invoke-Sqlcmd to access Veeam credentials stored in MSSQL databases, potentially targeting backups for destructive operations such as ransomware attacks.
Veeam Backup Library Loaded by Unusual Process
2 rules 3 TTPsDetects potential credential decryption operations by PowerShell or unsigned processes using the Veeam.Backup.Common.dll library, indicating potential credential access attempts to target backups as part of destructive operations.
Third-party Backup Files Deleted via Unexpected Process
2 rules 2 TTPsThis detection identifies the deletion of backup files by processes outside of the backup suite, specifically targeting Veritas and Veeam backups, which may indicate an attempt to prevent recovery from ransomware.
Detecting Remote Windows Service Installation for Lateral Movement
2 rules 3 TTPsThis rule detects a network logon followed by Windows service creation with the same LogonId on a Windows host, which could indicate lateral movement or persistence by adversaries.
Remote Execution of Windows Services via RPC
2 rules 2 TTPsDetection of remote execution of Windows services over RPC by correlating `services.exe` network connections and spawned child processes, potentially indicating lateral movement.