Veeam is a technology platform tracked across 14 threat clusters and 22 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity July 22, 2026.
Veeam reported a critical Remote Code Execution (RCE) vulnerability in its backup and replication software, identified as CVE-2025-59470, with a CVSS score of 9.0. The vulnerability highlights risks associated with…
Veeam Software has released a critical security update for its Backup & Replication platform to address multiple vulnerabilities, including three severe remote code execution (RCE) flaws. These vulnerabilities, tracked…
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
A vulnerability in the Veeam Updater component (CVE-2026-56844) allows local users to escalate privileges and gain root access to the operating system. This high-risk flaw affects the Veeam Backup & Replication server…
On May 4, 2026, a leak of internal communications from The Gentlemen Ransomware-as-a-Service (RaaS) operation surfaced on underground forums. The leak, which included chats and backend data from November 2025 to April…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
Veeam Software disclosed four critical vulnerabilities in Veeam Backup & Replication v13 that could allow attackers to gain root-level access and execute code on backup systems. The most severe flaw, CVE-2025-55125, was…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. They leveraged three critical vulnerabilities…
The Gentlemen ransomware operation has affected at least 17 countries across the Americas, Asia-Pacific, and the Middle East, targeting sectors such as manufacturing, healthcare, construction, and insurance. This…