Veeam Backup Servers Need Patching, Plus 3 Stories
A critical Veeam backup vulnerability turns an account with the low-privilege Backup Viewer role into remote code execution on the backup server. That is not the same as an attacker walking in without a password, but it is a much larger jump in authority than the role name suggests. More importantly, the target is the system a business expects to save it when other systems fail.
A Backup Viewer Can Become Control of the Veeam Server
Veeam says CVE-2025-64393 affects Veeam Backup & Replication version 12.3.2.4854 and every earlier version 12 build. Version 13 is not affected. The flaw has a 9.4 severity score and is fixed in version 12.3.2 P4, build 12.3.2.4934.
The mechanism is insecure deserialization in the Mount Service. Serialization packages software objects and their data so another process can store or transmit them. Deserialization rebuilds those objects on the receiving side. If a service accepts a crafted object and rebuilds it without treating the contents as hostile, the object can make the program execute instructions the developer never intended. In this case, a Backup Viewer can send untrusted data that becomes code running on the backup server. The Cyber Security Agency of Singapore says that code can run with Windows SYSTEM privileges.
Why does that matter more than another server bug? Because the backup system is part of the recovery control plane. Remote code execution does not prove an attacker erased or altered any backups. It does put the attacker on the server that coordinates backup and restoration work, which is close enough that nobody should be relaxed about it.
Organizations on Veeam version 12 should install 12.3.2 P4 now or move to unaffected version 13. Then check who has the Backup Viewer role, remove accounts that no longer need it, and review authentication and server logs for unexpected use. A patch closes the software flaw. It does not tell you whether a stolen account was used before the patch arrived.
This is also a good time to verify that at least one backup copy is immutable or otherwise outside the reach of the live environment and the normal backup administration path. The useful question is not only “Do we have backups?” It is “Can the same compromised identity erase the live system and the recovery copies?” We have covered another serious Veeam flaw recently, but this is a separate vulnerability with a separate update. Patch fatigue does not make the new bug optional. It mostly makes the job harder.
Backups & recovery
Backups are comforting right up until you need one. Raymond Tec helps small businesses build practical backup and recovery plans — including the decidedly unglamorous part where we make sure the thing can actually be restored.
Flock’s Job Cuts Do Not Shrink Its Surveillance Network
Flock Safety plans to cut about 18 percent of its workforce, or roughly 270 jobs, according to Reuters reporting based on people familiar with the plan. Flock declined to comment, so the cuts remain source-based reporting rather than a public company announcement. The story matters because the company is facing growing opposition to its automated license-plate readers while still operating a very large network.
Reuters says about 120,000 Flock cameras operate across 49 states, serving more than 4,800 law-enforcement agencies and nearly 1,000 businesses. A single camera records a license plate, time, and location. Connect enough of those observations and the system can reconstruct where a vehicle has been. The privacy question is therefore not limited to whether a camera correctly reads one plate. It includes who can search the network, how long records remain available, which agencies or companies can receive them, and whether the original customer knows about the sharing.
Florida banned automated plate readers from state highways in September, a Virginia lawsuit argues that widespread deployment amounts to warrantless surveillance, and Home Depot investors have called for a review of surveillance vendors after reports involving immigration enforcement. We covered the earlier state pushback against Flock. The layoffs add business pressure, but they do not automatically change the cameras, contracts, or data practices.
If a business, apartment complex, neighborhood association, or local government uses these systems, the practical work is contractual: document the purpose, restrict searches, set retention limits, log access, and identify every sharing path. There is no personal privacy toggle that makes a plate unreadable on a public road. Accountability has to exist on the side collecting and querying the data.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
The FBI Seized Hacking Domains, but Victims Still Need to Look
The Justice Department and FBI seized seven internet domains used with two tools attributed to actors associated with China-based Integrity Technology Group. The Justice Department says Microscan searched networks for vulnerabilities, sometimes hiding its origin behind a botnet of compromised Internet of Things devices. FishHub supported spear-phishing attacks and delivered malware that could create file lists, search for documents, compress them, and send them to attacker-controlled servers.
The action is useful. Taking control of command-and-control and delivery domains can break parts of an attack system without waiting to arrest every operator. It is not a remote cleaning service. A computer that was already compromised, a password that was already stolen, or persistence installed under another name can survive the disappearance of the original domain.
That is why the accompanying joint CISA, FBI, NSA, and international advisory matters more to defenders than the seizure banner. It provides indicators and techniques organizations can use to search logs and systems for current or historical access. The actors combined automated scanning, password attacks, phishing, and hands-on exploitation. There is no single magic product to buy in response.
Organizations with internet-facing services should compare their logs with the advisory, patch exposed applications, require multifactor authentication where supported, and examine unusual email or remote-access activity. Small businesses should ask their IT provider whether the advisory applies to anything they manage. Home users can do the less glamorous version: install router firmware updates and replace internet-connected devices that no longer receive them. A cheap abandoned router is still a computer somebody else may decide to use.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
AI Memory Demand Is Reaching the iPhone Price Tag
Apple has reportedly reduced October component orders for the iPhone 18 Pro and Pro Max by at least 15 percent after higher prices and expensive memory contributed to softer demand. Reuters attributes the report to Nikkei Asia and says it could not independently verify it. Apple did not immediately comment. That uncertainty belongs near the top, not in the fine print.
The confirmed price change is easier to see. The Pro models now start at $1,199 and $1,299, each $100 above the previous generation. Reuters reports that AI data centers are consuming advanced chip-making capacity and memory, contributing to shortages and higher costs across phones and computers. Apple had already raised some MacBook and iPad prices in June for the same reason.
We tracked this pressure in September when AI demand began pushing memory prices into ordinary devices. The new development is not that one expensive iPhone had a slow month. It is that suppliers and buyers are now making decisions around the higher cost structure.
There is no reason to panic-buy a phone. For households and small businesses, the sensible response is to keep working devices longer, compare storage tiers carefully, and budget replacements based on need rather than launch season. The AI infrastructure bill does not stay inside a data center. Some of it arrives at the checkout counter.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources and Further Reading
- Veeam: Vulnerabilities resolved in Backup & Replication 12.3.2 P4
- Cyber Security Agency of Singapore: Critical Veeam vulnerability
- Reuters: Flock Safety plans job cuts amid surveillance backlash
- U.S. Justice Department: Microscan and FishHub domain seizures
- CISA and partners: Integrity Technology Group advisory AA26-281A
- Associated Press: FBI disrupts tools used by China-linked hackers
- Reuters: Apple reportedly cuts iPhone 18 Pro component orders
Photo by Kevin Ache on Unsplash.
