Security News > 2024 > July > Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks

Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks
2024-07-29 17:06

Microsoft warned today that ransomware gangs are actively exploiting a VMware ESXi authentication bypass vulnerability in attacks.

Ransomware groups have focused on creating lockers dedicated to encrypting ESXi VMs rather than targeting specific ESXi vulnerabilities that would provide them a quicker way of acquiring and maintaining access to a victim's hypervisors.

The Play ransomware group is the latest such operation to start deploying an ESXi Linux locker in their attacks.

"The number of Microsoft Incident Response engagements that involved the targeting and impacting ESXi hypervisors have more than doubled in the last three years," Microsoft warned.

New Play ransomware Linux version targets VMware ESXi VMs. SEXi ransomware rebrands to APT INC, continues VMware ESXi attacks.

Linux version of RansomHub ransomware targets VMware ESXi VMs. Keytronic confirms data breach after ransomware gang leaks stolen files.


News URL

https://www.bleepingcomputer.com/news/microsoft/microsoft-ransomware-gangs-exploit-vmware-esxi-auth-bypass-in-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 186 83 402 200 103 788