The Frag ransomware is exploiting a critical flaw in Veeam Backup & Replication software known as CVE-2024-40711 to deploy malware, according to cybersecurity researchers at Sophos. Despite Veeam having released fixes for multiple vulnerabilities in September 2024, attacker are still using compromised VPN gateways to access systems and exploit this flaw. STAC 5881, a cyber threat actor, has been identified as exploiting this vulnerability to deploy Frag ransomware on compromised networks.
Microsoft Patch Tuesday security updates for November 2024 fix two actively exploited zero-days
Microsoft’s Patch Tuesday security update for November 2024 rectified 89 vulnerabilities across numerous software offerings, including Windows, Office Components, and Azure. Two of these were