Security News > 2024 > July > Microsoft: Ransomware gangs exploit VMware ESXi auth bypass in attacks

Microsoft warned today that ransomware gangs are actively exploiting a VMware ESXi authentication bypass vulnerability in attacks.
Ransomware groups have focused on creating lockers dedicated to encrypting ESXi VMs rather than targeting specific ESXi vulnerabilities that would provide them a quicker way of acquiring and maintaining access to a victim's hypervisors.
The Play ransomware group is the latest such operation to start deploying an ESXi Linux locker in their attacks.
"The number of Microsoft Incident Response engagements that involved the targeting and impacting ESXi hypervisors have more than doubled in the last three years," Microsoft warned.
New Play ransomware Linux version targets VMware ESXi VMs. SEXi ransomware rebrands to APT INC, continues VMware ESXi attacks.
Linux version of RansomHub ransomware targets VMware ESXi VMs. Keytronic confirms data breach after ransomware gang leaks stolen files.
News URL
Related news
- Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own (source)
- US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks (source)
- New "Bring Your Own Installer" EDR bypass used in ransomware attack (source)
- Fake KeePass password manager leads to ESXi ransomware attack (source)
- PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks (source)
- Microsoft: Windows CLFS zero-day exploited by ransomware gang (source)
- PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware (source)
- Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’ (source)
- Sensata Technologies hit by ransomware attack impacting operations (source)
- Hackers exploit WordPress plugin auth bypass hours after disclosure (source)