Tag: backup
-
September updates break File History backup feature
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-file-history-backup-feature/
-
CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
CISA added CVE-2026-87886 to its KEV catalog after confirmed exploitation of an Acronis Backup flaw affecting Linux hosting environments. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-acronis-backup-flaw-exploited/
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
Backup-Experte Xopero Gitprotect setzt bei DACH-Expansion auf den Channel
Der Backup-Experte Xopero Gitprotect setzt bei seiner Expansion in DACH auf eine umfassende Channel- und Partnerstrategie. Im Zentrum des diesjährigen it-sa-Auftritts stehen neben der Vorstellung der neuen Produktversionen die Channelpartnerschaften. Daher tritt das Unternehmen gemeinsam mit seinen etablierten Partnern Trust2Protect sowie Schönbrunn TASC auf. Erstmals gezeigt wird die deutsche Version der Backup- und Disaster-Recovery-Lösung. Mit…
-
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions – Acronis Backup…
-
Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, targeted attacks against vulnerable deployments. This vulnerability is tracked as CVE-2026-87886 and is described as an insecure file permissions…
-
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/
-
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/acronis-backup-plugin-vulnerability-exploited-cve-2026-87886/
-
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
Weshalb guter Ransomware-Schutz für Backups nicht nur Daten schützt, sondern auch das Repository prüft
Unveränderliche Backups gelten als letzte Verteidigungslinie gegen Ransomware. Doch was passiert, wenn Angreifer nicht die Produktivsysteme, sondern das Backup-Repository selbst ins Visier nehmen? Kai Hambrecht von Grau Data geht dieser Frage auf den Grund. Übermäßige Admin-Rechte, Active-Directory-Anbindung, unzureichende Netzwerksegmentierung oder manipulierte Restore-Punkte können dazu führen, dass Backups im Ernstfall nicht mehr verfügbar oder wiederherstellbar sind.…
-
Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together
Originally published at Protecting Microsoft 365 and Google Workspace: Why Email Security and Backup Belong Together by Mike Anderson. Microsoft 365 and Google Workspace have become essential to how businesses communicate, collaborate, and operate. But as these platforms have become… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/protecting-microsoft-365-and-google-workspace-why-email-security-and-backup-belong-together/
-
Zeitalter der KI-Agenten erfordert neue Backup-Strategien
Autonome KI-Agenten verschieben die Grenzen klassischer Datensicherung: Weil sie mit gültigen Identitäten und hohen Schreibrechten agieren, können Fehlentscheidungen in Sekunden geschäftskritische Daten treffen. HYCU reagiert mit Transparenz über Agenten und Berechtigungen, engeren Wiederherstellungspunkten sowie einem vom SaaS-Betrieb unabhängigen Datenzugriff. Management Summary Neue Risikologik: KI-Agenten benötigen keinen Angriff, sondern können mit legitimen Tokens und Berechtigungen fehlerhafte……
-
Zeitalter der KI-Agenten erfordert neue Backup-Strategien
Autonome KI-Agenten verschieben die Grenzen klassischer Datensicherung: Weil sie mit gültigen Identitäten und hohen Schreibrechten agieren, können Fehlentscheidungen in Sekunden geschäftskritische Daten treffen. HYCU reagiert mit Transparenz über Agenten und Berechtigungen, engeren Wiederherstellungspunkten sowie einem vom SaaS-Betrieb unabhängigen Datenzugriff. Management Summary Neue Risikologik: KI-Agenten benötigen keinen Angriff, sondern können mit legitimen Tokens und Berechtigungen fehlerhafte……
-
Why immutable backups are critical for ransomware resilience
For most UK SMEs, the real cost of ransomware is not just the ransom demand. It is the interruption to trading, the pressure on staff, the loss of customer confidence, and the time spent trying to recover systems and data…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-immutable-backups-are-critical-for-ransomware-resilience/
-
Operational security architecture for long-term sustainability
For many UK SMEs, security starts as a set of separate fixes. A stronger password policy here, a backup tool there, and perhaps a firewall that was set up years ago and never fully revisited. That approach can work for… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/operational-security-architecture-for-long-term-sustainability-2/
-
Xopero erweitert <> und <> mit Image-basiertes Linux-Backup, FIPS-konforme Verschlüsselung und Active-Directory-Integration
Der Backup-Experte Xopero hat eine neue Version von <> und <> vorgestellt. Ab der Version 2.4.0 ermöglicht Xopero-ONE-vollständige, imagebasierte Backups von Linux-Systemen. Bei Windows-Umgebungen ist die Unterstützung der AES-Verschlüsselung gemäß den strengen US-FIPS-Standards das wichtigste neue Feature. Die Active-Directory-Integration via LDAP erleichtert nun die Aufgaben von Backup-Administratoren, unabhängig von den geschützten Workloads. Die Lösung […]…
-
Your Storage Was Hardened Once. It Isn’t Anymore.
Configuration drift: the silent creator of security risk in storage and backup systems. Every storage and backup environment drifts. Firmware updates reset settings back to their defaults. Temporary changes made during an outage never get reverted. A vendor account created… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-storage-was-hardened-once-it-isnt-anymore/
-
Imaging und Klonen mit nativem ARM64-Support – Hasleo Backup Suite Free für Windows
First seen on security-insider.de Jump to article: www.security-insider.de/hasleo-backup-suite-free-fuer-windows-a-cf62f57f0130f32d5a797f348cdd2b80/
-
Plugin-Schwachstelle betrifft mehr als 3 Millionen WordPress-Seiten
Eine Schwachstelle im Plugin All-in-One WP Migration and Backup gefährdet nach Angaben des WordPress-Sicherheitsunternehmens Defiant mehr als 3 Millionen Websites. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/wordpress-schwachstelle
-
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
Tags: backup, cve, cyber, exploit, flaw, injection, remote-code-execution, sql, vulnerability, wordpressA high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of…
-
Lücke in Backup-Tool gefährdet Millionen von Websites
In einem WordPress-Plug-in mit über 5 Millionen Installationen klafft eine gefährliche Sicherheitslücke. Admins sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/wordpress-luecke-in-backup-tool-gefaehrdet-millionen-von-websites-2609-212585.html
-
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
-
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery/
-
AWS S3 Bucket Security: Find the Secrets Hiding Outside Git
S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/aws-s3-bucket-security-find-the-secrets-hiding-outside-git/
-
CNCF-Projekt erstellt Backups, migriert Cluster und legt Daten im Objektspeicher ab – Velero sichert Kubernetes-Ressourcen und Volumes
First seen on security-insider.de Jump to article: www.security-insider.de/velero-kubernetes-backup-restore-persistent-volumes-a-d1417d84a53c3af9f3f58234487fc742/
-
Rethinking Threat Intelligence: New Tactics for the Age of AI
Joe Hladik, head of Rubrik Zero Labs, sat down with the CEO and founder of the Techstrong Group, Alan Shimel, at Black Hat 2026 to talk about how Zero Labs is taking novel approaches to threat intelligence. One emerging source of threat intelligence, Hladik said, has historically been overlooked in threat detection: backup data. “When..…
-
Backup, Recovery, Cyber-Resilienz und Storage-Optimierung – Pink Elephant stärkt neue TDN-Einheit ‘Data Resilience Services”
First seen on security-insider.de Jump to article: www.security-insider.de/pink-elephant-staerkt-neue-tdn-einheit-data-resilience-services-a-0a50766c05258d5246c7a2bacc0ab1ab/
-
Data protection through encryption and secure channels for UK SMEs
Key takeaways Start with the data that would hurt most if exposed, then apply encryption where it reduces the biggest business risk. Protect both stored data and data in transit, because laptops, backups, websites, and system connections all carry different risks. Encryption only works properly when keys, passwords, certificates, and access rights are managed carefully….…

