Blackpoint’s Adversary Pursuit Group (APG) is currently tracking recently published vulnerabilities impacting Veeam Backup & Replication (VBR), exploitation of which may disrupt backup file restoration and integrity post-ransomware attack.
While there is no known exploitation at time of this writing – including within Blackpoint Active SOC-monitored environments – the APG’s threat actor tracking has identified several major threat groups with histories of exploiting VBR vulnerabilities, including Akira, Cuba, and FIN7.