Tag: vmware
-
VMware ESXi and Workstation Vulnerabilities Allow Host-Level Code Execution
Broadcom disclosed four critical vulnerabilities in VMware’s virtualization suite on July 15, 2025, enabling attackers to escape virtual machines and execute code directly on host systems. The flaws, discovered through the Pwn2Own competition, affect ESXi, Workstation, Fusion, and VMware Tools across enterprise and desktop environments. Vulnerability Overview CVE ID Component Vulnerability Type CVSS Score Impact…
-
Ransomware Threat Grows as Attackers Move Into VMware and Linux
Linux has been the reliable backbone of business infrastructure for many years; it powers 96% of the top million web servers worldwide and more than 80% of workloads in public clouds. Its reputation for reliability and inherent security has long shielded it from the intense scrutiny faced by Windows environments. However, this era of relative…
-
Telefónica Germany offloads VMware support to Spinnaker due to high renewal costs
‘Our offer from Broadcom was five times higher than we expected’ First seen on theregister.com Jump to article: www.theregister.com/2025/07/11/telefnica_germany_shifts_vmware_support/
-
VMware’s rivals ramp up their efforts to create alternative stacks
Red Hat and Open Nebula deliver big updates, as Edera tools for Xen with Rust First seen on theregister.com Jump to article: www.theregister.com/2025/07/07/vmware_rivals_ramp_virtualization_efforts/
-
Schutz vor Ransomware, Migration von VMware zu Hyper-V und Backup für Microsoft 365 – Flexible Datensicherung mit Zmanda: Hybridlösungen für Unternehmen
First seen on security-insider.de Jump to article: www.security-insider.de/flexible-datensicherung-mit-zmanda-hybridloesungen-fuer-unternehmen-a-b8f6645bff5b3e471e09cc0d74cee6a2/
-
VMware must support crucial Dutch govt agency as it migrates off the platform, judge rules
Court says State arm cannot be left without maintenance, patches and upgrades because of Broadcom’s new licensing model First seen on theregister.com Jump to article: www.theregister.com/2025/06/30/dutch_agency_wins_right_to/
-
HPE OneView for VMware vCenter Vulnerability Allows Elevated Access
Hewlett Packard Enterprise (HPE) has issued a critical security bulletin warning customers of a significant vulnerability in its OneView for VMware vCenter (OV4VC) software. The flaw, tracked as CVE-2025-37101, could allow attackers with only read-only privileges to escalate their access and perform administrative actions, putting enterprise IT environments at risk. Vulnerability Overview The vulnerability, detailed…
-
Lerneffekte aus der aktuell effektivsten Ransomware Qilin
Qilin zählt inzwischen zu den aktivsten und wirkungsvollsten Ransomware-Operationen weltweit. Die Schadsoftware verbreitet sich zunehmend über etablierte Cybercrime-Netzwerke und spielt eine zentrale Rolle in aktuellen Bedrohungsmodellen. Die ersten Versionen wurden 2022 unter dem Namen “Agent” veröffentlicht und später vollständig in Rust neu entwickelt. Ab Ende 2023 gewann die Gruppe durch gezielte Angriffe auf VMware-ESXi-Systeme an…
-
Broadcom’s answer to VMware pricing outrage: You’re using it wrong
Tags: vmwareVCF bundle is worth it if you make the most of every part, says CTO First seen on theregister.com Jump to article: www.theregister.com/2025/06/20/vmware_price_hikes_excuse/
-
Spring Framework Flaw Enables Remote File Disclosure via “Content”‘Disposition” Header
A medium-severity reflected file download (RFD) vulnerability (CVE-2025-41234) in VMware’s Spring Framework has been patched, affecting multiple versions of the widely used Java framework. The flaw enables attackers to execute malicious code by exploiting improperly configured Content-Disposition headers in a web application. Technical Breakdown The vulnerability arises when applications use Spring’s org.springframework.http.ContentDisposition class to set…
-
Broadcom Cuts VMware Partner Ranks, Analysts Call It Ruthless but Strategic
Tags: vmwareFirst seen on scworld.com Jump to article: www.scworld.com/news/broadcom-cuts-vmware-partner-ranks-analysts-call-it-ruthless-but-strategic
-
Broadcom sends VMware to record revenue, margins, as most big customers sign for private cloud bundles
Chip biz surging too as CEO Hock Tan predicts optical GPU interconnects are a year or two away First seen on theregister.com Jump to article: www.theregister.com/2025/06/06/broadcom_q2_2025/
-
VMware NSX XSS Vulnerability Exposes Systems to Malicious Code Injection
Broadcom has issued a high-severity security advisory (VMSA-2025-0012) for VMware NSX, addressing three newly discovered stored Cross-Site Scripting (XSS) vulnerabilities: CVE-2025-22243, CVE-2025-22244, and CVE-2025-22245. These vulnerabilities impact the NSX Manager UI, gateway firewall, and router port components, exposing organizations to potential code injection attacks if left unpatched. The vulnerabilities, all stemming from improper input validation,…
-
Broadcom Streamlines Reseller Program to Strengthen VMware Delivery
Tags: vmwareFirst seen on scworld.com Jump to article: www.scworld.com/news/broadcom-streamlines-reseller-program-to-strengthen-vmware-delivery
-
VMware drops the lowest tier of its partner program except in Europe
Wants channel to be all in on private cloud as more details emerge on VCF 9 licensing and hardware First seen on theregister.com Jump to article: www.theregister.com/2025/06/01/vmware_channel_changes/
-
Hoher Schweregrad – Mehrere Sicherheitslücken in VMware Cloud Foundation
First seen on security-insider.de Jump to article: www.security-insider.de/broadcom-vmware-cloud-foundation-sicherheitsluecken-update-a-74d4b9d2be0b6be082b8c23a54089986/
-
VMware price hikes? Between 800 and 1,500%, claim Euro customers
Tags: vmwareReport slates end of perpetual licenses, death of monthly pay-as-you-go model, and ‘punitive’ changes by Broadcom First seen on theregister.com Jump to article: www.theregister.com/2025/05/22/euro_cloud_body_ecco_says_broadcom_licensing_unfair/
-
Dell creates one private cloud to rule them all and in the datacenter bind them
Mix Master Mike will spin up Nutanix, VMware, Red Hat on the same beastly cluster First seen on theregister.com Jump to article: www.theregister.com/2025/05/20/dell_private_cloud/
-
DragonForce mischt die Ransomware-Szene auf und legt sich mit der Konkurrenz an
Die Sicherheitsforscher von Sophos beobachten die Aktivitäten der Gruppe schon seit geraumer Zeit. DragonForce greift gezielt klassische IT-Infrastrukturen ebenso wie virtualisierte Umgebungen (z.”¯B. VMware ESXi) an. Die Angreifer setzen auf den Diebstahl von Zugangsdaten, missbrauchen Active Directory und schleusen sensible Daten aus den Systemen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/dragonforce-mischt-die-ransomware-szene-auf-und-legt-sich-mit-der-konkurrenz-an/a40893/
-
Trojanized RVTools push Bumblebee malware in SEO poisoning campaign
The official website for the RVTools VMware management tool was taken offline in what appears to be a supply chain attack that distributed a trojanized installer to drop the Bumblebee malware loader on users’ machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trojanized-rvtools-push-bumblebee-malware-in-seo-poisoning-campaign/
-
Trust becomes an attack vector in the new campaign using trojanized KeePass
Tags: access, api, attack, authentication, backup, breach, ceo, control, credentials, defense, edr, identity, open-source, password, ransomware, risk, service, software, veeam, vmware, zero-trustIdentity is the new perimeter: Once KeeLoader stole vault credentials-often including domain admin, vSphere, and backup service accountattackers moved fast. Using SSH, RDP, and SMB protocols, they quietly seized control of jump servers, escalated privileges, disabled multifactor authentication, and pushed ransomware payloads directly to VMware ESXi hypervisors.Jason Soroko of Sectigo called it a “textbook identity…
-
Critical VMware ESXi vCenter Flaw Allows Remote Execution of Arbitrary Commands
VMware by Broadcom has released critical security updates to address multiple severe vulnerabilities affecting its virtualization products, with evidence suggesting active exploitation in the wild. The vulnerabilities, tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, affect VMware ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform products. With CVSS scores ranging from 7.1 to 9.3, these flaws…
-
Hacking contest exposes VMware security
In what has been described as a historical first, hackers in Berlin have been able to demo successful attacks on the ESXi hypervisor First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366624198/Hacking-contest-exposes-VMware-security
-
Bumblebee Malware Takes Flight via Trojanized VMware Utility
An employee inadvertently downloaded a malicious version of the legitimate RVTools utility, which launched an investigation into an attempted supply chain attack aimed at delivering the recently revived initial-access loader. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/bumblebee-malware-trojanized-vmware-utility
-
RVTools hit in supply chain attack to deliver Bumblebee malware
The official website for the RVTools VMware management tool was taken offline in what appears to be a supply chain attack where hackers replaced a DLL in the distributed installer to drop the Bumblebee malware loader on users’ machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rvtools-hit-in-supply-chain-attack-to-deliver-bumblebee-malware/
-
Ethical hackers exploited zero-day vulnerabilities against popular OS, browsers, VMs and AI frameworks
Virtual machine and container escapes: Virtualization sits at the core of public cloud infrastructure and private data centers, allowing companies to run their workloads and applications inside isolated containers or virtual servers. Any flaw that allows escaping from the confines of a virtual machine or a Linux container poses a risk not only to the…

