Tag: vmware
-
Critical VMware RCE flaw now exploited by ransomware gangs
Tags: attack, cisa, cybersecurity, exploit, flaw, infrastructure, ransomware, rce, remote-code-execution, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Security Affairs newsletter Round 593 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U.S. and European Schools Broadcom Patches Critical VMware Workstation and Fusion…
-
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.”A First seen on…
-
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.”A First seen on…
-
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as…
-
VMware enhances AI security with AgentMinder and vDefend updates
First seen on scworld.com Jump to article: www.scworld.com/brief/vmware-enhances-ai-security-with-agentminder-and-vdefend-updates-1
-
VMware Cloud Foundation adds top AI models to private cloud platform
First seen on scworld.com Jump to article: www.scworld.com/brief/vmware-cloud-foundation-adds-top-ai-models-to-private-cloud-platform
-
VMware’s new AgentMinder puts guardrails around autonomous AI agents
First seen on scworld.com Jump to article: www.scworld.com/news/vmware-enhances-ai-security-with-agentminder-and-vdefend-updates
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads
Broadcom has announced the VMware AI Factory, a software-defined private AI platform designed to accelerate the transition from bare-metal servers to production-ready AI models. This platform enhances governance, infrastructure automation, and workload isolation. Unveiled during VMware Explore 2026, the VMware AI Factory serves as the foundation for VMware’s Private AI Cloud. It combines VMware Cloud…
-
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments. The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Tags: apple, cisa, cve, cybersecurity, exploit, flaw, infrastructure, Internet, kev, macOS, microsoft, remote-code-execution, service, vcenter, vmware, vulnerability, windowsU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution…
-
CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, hacker, infrastructure, kev, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, tracked as CVE-2026-59310, is a path traversal flaw that enables arbitrary code execution in affected vCenter deployments. VMware vCenter Path Traversal Flaw CVE-2026-59310 impacts the VMware vCenter Syslog Server…
-
Unter anderem vCenter, ESX, Workstation und Fusion – VMware patcht fünf Schwachstellen in acht Produkten
First seen on security-insider.de Jump to article: www.security-insider.de/vmware-kritische-vcenter-luecken-auth-bypass-rce-a-97695fcf2175fd68953b1e7a76957623/
-
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
Tags: cve, cyber, data-breach, exploit, infrastructure, rce, remote-code-execution, vcenter, vmware, vulnerabilityA critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a launch point for broad virtual-infrastructure compromise. Incident responders at QUIRSO linked the activity to exploitation of CVE-2026-59310, while identifying a separate, possibly unrelated track involving CVE-2026-59309. CVE-2026-59310 is a directory-traversal vulnerability in the…
-
China-Nexus Threat Actor Targeting Critical VMware Flaw
A China-nexus bad actor is likely behind the rapid exploitation of a critical flaw in VMware’s vCenter management software that has spread across 361 victim IP addresses in almost four dozen countries. Exploitation of the vulnerability tracked as CVE-2026-59310 started five days after VMware owner Broadcom first disclosed the security flaw July 29,.. First seen…
-
Remote VMware migrations need a site-by-site plan
Tags: vmwareFirst seen on scworld.com Jump to article: www.scworld.com/perspective/remote-vmware-migrations-need-a-site-by-site-plan
-
Broadcom adds multi-tenant security and API protection to VMware, opens MSP opportunities
First seen on scworld.com Jump to article: www.scworld.com/news/broadcom-adds-multi-tenant-security-and-api-protection-to-vmware-opens-msp-opportunities
-
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
-
VMware Licensing Changes and Their Impact on Infrastructure Modernization
Explore how VMware licensing changes are influencing infrastructure modernization, cloud strategy, and AI readiness, and what enterprises should evaluate next. First seen on hackread.com Jump to article: hackread.com/vmware-licensing-changes-infrastructure-modernization/
-
Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader
Two closely related espionage campaigns targeting Cambodian government organizations that abuse a legitimate VMware-signed binary to sideload a custom loader dubbed NIGHTFORGE, which in turn deploys a Havoc Demon implant in memory. TRU attributes both operations to a previously unreported cluster it calls Khmer Shadow, based on targeting, lure construction and shared infrastructure; the activity…
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts
VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially allowing attackers to inject malicious scripts and compromise administrative environments. The issues, tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, were published under advisory VMSA-2026-0004 on June 8, 2026, and carry a combined CVSS v3 base score of 8.0, indicating…
-
VMware Cloud Foundation 9.1 gives partners a bigger private cloud services play
First seen on scworld.com Jump to article: www.scworld.com/news/vmware-cloud-foundation-9-1-gives-partners-a-bigger-private-cloud-services-play
-
Gentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi Systems
The Gentlemen ransomware operation has rapidly emerged as one of the most active and scalable cybercrime threats since its public appearance in the second half of 2025. The Gentlemen stands out for its ability to target a wide range of enterprise systems, including Windows, Linux, NAS, BSD, and VMware ESXi environments. This lineage suggests the…

