New Veeam Vulnerabilities Expose Backup Servers to RCE Attacks
Critical
Executive Summary
Veeam released security updates to patch multiple security flaws in its Backup & Replication software, including a critical remote code execution (RCE) vulnerability tracked as CVE-2025-59470. This vulnerability and others can allow attackers to perform RCE and other malicious activities; patches are available to remediate these issues.
Vulnerability Details
Affected Product: Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds
Identifier: CVE-2025-59470
CVSS Score: 9.0 (Critical)
Exploitation Status: No known active exploitation
Risk & Impact
Triage: Immediate patching is recommended for Veeam Backup & Replication version 13 users.
Attack Vector: A Backup or Tape Operator can achieve remote code execution as the postgres user by sending a malicious interval or order parameter.
Ease of Exploit: Requires Backup or Tape Operator credentials, making it High severity.
Action Plan
Immediate Action: Upgrade to Version 13.0.1.1071
Workaround: Follow Veeam's recommended Security Guidelines to reduce the opportunity for exploitability.
Detection: Monitor for suspicious activity related to Backup and Tape Operator roles and review user role assignments.
Relevant professional terms
Remote Code Execution (RCE)
A vulnerability that allows an attacker to execute arbitrary code on a target system.
CVSS Score
A numerical representation of the severity of a vulnerability, used to prioritize patching and mitigation efforts.
New D-Link Flaw in Legacy DSL Routers Actively Exploited
Critical
Executive Summary
A command injection vulnerability, identified as CVE-2026-0625, affects multiple D-Link DSL gateway routers that are no longer supported and is being actively exploited in the wild. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary shell commands.
Vulnerability Details
Affected Product: D-Link DSL routers including DSL-2640B (<= 1.07), DSL-2740R (< 1.17), DSL-2780B (<= 1.01.14), and DSL-526B (<= 2.01)
Identifier: CVE-2026-0625
CVSS Score: 9.3 (Critical)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Critical. Immediate action is required due to active exploitation.
Attack Vector: Remote, unauthenticated attackers can inject and execute arbitrary shell commands via the "dnscfg.cgi" endpoint due to improper sanitization of user-supplied DNS configuration parameters.
Ease of Exploit: Relatively low, as the vulnerability can be triggered remotely without authentication.
Action Plan
Immediate Action: Retire the affected devices and upgrade to actively supported devices with regular security updates. No patch will be released.
Workaround: There are no known workarounds. Discontinue use of the affected devices.
Detection: Monitor for suspicious activity and DNS modifications.
Relevant professional terms
Command Injection
An attack in which an attacker is able to execute arbitrary commands on a host operating system. This is typically achieved by exploiting vulnerabilities in an application that improperly handles user-supplied input.
Remote Code Execution (RCE)
The ability to execute arbitrary code on a remote device or system. This can allow an attacker to gain complete control over the compromised system.
The Crimson Collective claims to have stolen data from over one million Brightspeed customers, impacting their personal information. Brightspeed is currently investigating the alleged breach and claims made by the extortion group.
Attack Overview
Attack Path: The Crimson Collective compromised Brightspeed systems, gaining access to customer data.
Attacker: Crimson Collective.
Impact Assessment
Data Stolen: Customer data including names, email addresses, phone numbers, billing and service addresses, account status, and network details.
Strategic Takeaway
This breach highlights the persistent threat to telecommunications infrastructure and the sensitive data they hold, emphasizing the need for robust security measures.
Relevant professional terms
Data Exfiltration
The unauthorized transfer of data from a computer or other device.
Personally Identifiable Information (PII)
Any data that could potentially identify a specific individual.
GoBruteforcer is a botnet targeting internet-exposed services on Linux servers, including phpMyAdmin, MySQL, PostgreSQL, and FTP, by brute-forcing user passwords. Compromised hosts are then incorporated into the botnet for scanning and further attacks.
Key TTPs
Initial Access: Brute-forcing weak or default passwords on exposed services.
Execution: Deploys IRC bots and PHP web shells for remote command execution.
Defense Evasion: Uses UPX packer to evade detection.
Campaign Analysis
The botnet leverages AI-generated server deployment examples with weak defaults and targets legacy web stacks. This campaign has successfully compromised crypto and blockchain project databases.
Targeting & Infrastructure
Target Profile: Internet-exposed Linux servers running phpMyAdmin, MySQL, PostgreSQL, and FTP services.
Infrastructure: Utilizes compromised servers as scanning and brute-forcing nodes, controlled via IRC bots and web shells.
Actionable Intelligence
IPs:5.253.84.159
Domains:fi.warmachine.su
Relevant Terms
Botnet: A network of computers infected with malware that are controlled by a single attacker.
Brute-Force Attack: A method of gaining access to a system by trying numerous username and password combinations.
The Kimwolf botnet, an Android-based malware variant of Aisuru, has infected over two million devices by exploiting vulnerabilities within residential proxy networks. This botnet targets devices on internal networks, turning them into conduits for malicious traffic and DDoS attacks.
Execution: Installing malware through scanning infrastructure using residential proxies.
Defense Evasion: Using DNS over TLS (DoT) to hide communication and EtherHiding to resist takedowns.
Campaign Analysis
Kimwolf's rapid growth is attributed to targeting vulnerable devices through residential proxy networks, with many devices pre-infected. The botnet is used for DDoS attacks, selling residential proxy bandwidth, and app installs, highlighting the risks of unsecured proxy networks.
Targeting & Infrastructure
Target Profile: Unofficial Android TV boxes and streaming devices with exposed ADB services, primarily in Vietnam, Brazil, India, and Saudi Arabia.
Infrastructure: Over two million infected devices, utilizing residential proxies, with a significant portion linked to IPIDEA.
Actionable Intelligence
IPs: 85.234.91.247 (C2 Node).
Infected Devices: Over 2 million Android devices acting as residential proxy nodes.
Relevant Terms
Botnet: A network of computers infected with malware that can be controlled remotely to perform tasks such as DDoS attacks.
Residential Proxy: A proxy service that uses IP addresses from residential internet service providers to mask the user's actual IP address.
Taiwan Faces Escalating Cyberattacks on Energy Sector
Executive Summary
Taiwan's National Security Bureau (NSB) reported a tenfold increase in cyberattacks targeting the country's energy sector in 2025, signaling a significant escalation in China's cyber activity. These attacks are often synchronized with military activities, indicating a coordinated effort to undermine Taiwan's critical infrastructure.
Key Findings
Cyberattacks on Taiwan's energy sector increased by 1,000% in 2025 compared to the previous year.
Overall cyber incidents linked to China grew by 6%, with an average of 2.63 million attacks per day.
Emergency rescue and hospitals sectors experienced a 54% increase in cyberattacks.
The Bottom Line
The dramatic rise in cyberattacks against Taiwan's energy sector, coupled with coordinated timing alongside military activities, suggests a deliberate strategy to destabilize critical infrastructure. This poses a significant threat to national security and economic stability, requiring enhanced cybersecurity measures and international cooperation to counter these evolving hybrid warfare tactics. The focus on industrial control systems and software upgrade monitoring highlights the need for robust vulnerability management and supply chain security practices.
Relevant Terms
National Security Bureau (NSB): The principal intelligence agency of Taiwan, responsible for coordinating national security intelligence efforts and counterintelligence operations.
Energy Sector: Encompasses companies involved in the production and distribution of energy, including fossil fuels and renewables, critical for powering the economy.
The founder of pcTattletale, Bryan Fleming, pleaded guilty to federal charges related to computer hacking and advertising surveillance software. The guilty plea marks the first successful U.S. federal prosecution of a stalkerware operator in over a decade.
The Scheme
TTP 1: Developed and marketed stalkerware, pcTattletale, for monitoring computers and phones.
TTP 2: Promoted the software for spying on spouses and domestic partners.
TTP 3: Collected and stored screenshots and private data from victims' devices.
The Players
Facilitators Arrested:Bryan Fleming
The Consequence
Outcome: Bryan Fleming pleaded guilty to computer hacking and advertising surveillance software.
Strategic Takeaway
The successful prosecution signals increased legal consequences for developing and marketing stalkerware.
Relevant Terms
Stalkerware: Software designed to secretly monitor individuals without their knowledge or consent.
Data Breach: A security incident where sensitive, protected, or confidential data is copied, transmitted, viewed, stolen, or used by an individual unauthorized to do so.