Tag: security

Chinese Hackers Exploit VMware ESXi Zero-Day to Backdoor Virtual Machines

Security Advisory

Introduction Recently, a Chinese-sponsored hacking group, tracked as UNC3886 by cybersecurity firm Mandiant, has made headlines for exploiting a zero-day vulnerability in VMware ESXi to infiltrate Windows and Linux virtual machines (VMs) and steal sensitive data. In this blog post, we will delve into the details of the attack, the techniques employed by the hackers,…

Read more

Royal Ransomware Escalates: Targets Linux and VMware ESXi Environments

Security Advisory

The Royal ransomware group, believed to be composed of ex-Conti gang members, has intensified its operations since its emergence last year. The group has primarily targeted critical infrastructure and healthcare organizations and has recently extended its reach to Linux and VMware ESXi environments. Recent Developments: Palo Alto Networks’ Unit 42 division reported on May 9…

Read more

ESXiArgs Ransomware: Someone is encrypting an unpatched VMware ESXi 6.X servers that are open to the internet.

Security Advisory

Warnings are being issued by administrators, hosting providers, and the French Computer Emergency Response Team (CERT-FR) that attackers are actively targeting VMware ESXi servers that are vulnerable due to a two-year-old unpatched remote code execution flaw. The ultimate goal of these attackers is to install ransomware on these systems. The vulnerability tracked as CVE-2021-21974 is…

Read more

Recently, over 45,000 VMware ESXi systems reached their end of life.

Security Advisory

VMware ESXi 6.5 and ESXi 6.7 reached end-of-life on October 15, 2022, and will no longer receive technical support or security updates, putting the software at risk of vulnerabilities. The company examined data from 6,000 customers and discovered 79,000 VMware ESXi servers installed. 36.5% (28,835) of those servers are running version 6.7.0, which was released…

Read more

Prevention and Mitigation against Unsigned vSphere Installation Bundles (VIBs) in ESXi

Security Advisory

Researchers from cyber threat intelligence company Mandiant on Thursday 29th published information on two malware leveraging unsigned vSphere Installation Bundles (“VIBs”) to install backdoors VirtualPita and VirtualPie on compromised ESXi host. First I would like to point out that malicious actors MUST have administrative privileges on the ESXi host to perform an attack. Also, there…

Read more

VirtualPita, VirtualPie – new malware backdoors VMware ESXi servers to hijack virtual machines

Security Advisory

The malicious actors found the new method of taking over the control of VMware ESXi hypervisors to control vCenter servers and virtual machines for Windows and Linux while avoiding detection. Attackers are using malicious vSphere Installation Bundles (“VIBs”) to install multiple backdoors across ESXi hypervisors. The malware is hidden in VIB payloads. Researchers from Mandiant…

Read more

PowerShell to ensure TLS1.2 is enabled

PowerShell

Today I will show you how to ensure that TLS1.2 is enabled. I will write a short script to perform a check and remediate if ESXi hosts are still using legacy security protocols. Please like and share to spread the knowledge in the community. If you want to chat with me please use Twitter: @AngrySysOps…

Read more

Patching time! VMware released an update for vCenter Server and ESXi -> 7.0 Update 3f.

Security Advisory

vCenter server: NOTE: If your source system contains hosts of versions between ESXi 7.0 Update 2 and Update 3c, and Intel drivers, before upgrading to vCenter Server 7.0 Update 3f, see the What’s New section of the VMware vCenter Server 7.0 Update 3c Release Notes, because all content in the section is also applicable for vSphere 7.0 Update 3f. Also,…

Read more

Black Basta Ransomware is now actively targeting VMware ESXi servers – Protect your environment!

Security Advisory

What is Black Basta? Researchers from Uptycs reported that Linux version of Black Basta ransomware is now actively targeting ESXi servers, previously targeting Windows systems. Black Basta has been active since April 2022, like other ransomware operations, it implements a double-extortion attack model. Double-extortion scheme works in the way that first malicious actors extort victims…

Read more

New software package to upgrade VxRail appliance to 7.0.370 with vSphere 7.0 U3d.

VxRail

Product(s) Abstract Date Title VxRail Appliance Family,VxRail Appliance Series,VxRail Software Software package to upgrade VxRail appliance to 7.0.370 with vSphere 7.0 U3d. See the VxRail 7.0.x release notes (https://www.dell.com/support/manuals/en-us/vxrail-software/vxr_p_vxrail_release_notes_v7.0) for details. 2022-04-12 VxRail 7.0.370 Composite Upgrade Package for 4.5.x VxRail Appliance Family,VxRail Appliance Series,VxRail Software Software package to upgrade VxRail appliance to 7.0.370 with vSphere…

Read more