CyberSecurity news
@cyble.com
//
ImgSrc: cyble.com
References :
- : Weekly IT Vulnerability Report: Cyble Urges Fixes for Ivanti, Microsoft Dark Web Exploits
- Alerts: CISA Adds Three Known Exploited Vulnerabilities to Catalog
- www.ivanti.com: October 2024 Security Update - Ivanti
- cyble.com: Critical Vulnerability in Veeam Products Exploited by Ransomware Gangs
- forums.veeam.com: Veeam Security Bulletin September 2024
- Sophos X-Ops: Veeam Vulnerability (CVE-2024-40711) exploited by Ransomware Groups
- nvd.nist.gov: CVE-2024-40711 - Veeam Backup & Replication Remote Code Execution
- search.odin.io: Cyble Odin's search engine results for vulnerable Veeam instances exposed online.
- securityaffairs.com: U.S. CISA adds Veeam Backup and Replication flaw to its Known Exploited Vulnerabilities catalog
- malware.news: An article analyzing the similarities between BlackCat and Cicada3301, raising concerns about a potential return of the ransomware group.
- securityintelligence.com: A Security Intelligence article exploring the connection between BlackCat and Cicada3301.
- : While he says that code itself isn’t just a rehash of BlackCat, “the malware group has either seen the code base or are using the same developers.
- securityintelligence.com: It was the first piece of ransomware written in Rust. Choosing Rust let BlackCat engineers add customized features and implement measures that prevented malware analysis.
Classification:
- HashTags: #ivanti #csavulnerability #cybersecurity
- Company: Ivanti
- Target: Ivanti CSA users
- Product: Ivanti CSA
- Feature: Device management
- Type: Vulnerability
- Severity: Critical