HomeCII/OTChinese Cybercriminal Misused ESXi Zero-Day for Stealing Data from Guest VMs

Chinese Cybercriminal Misused ESXi Zero-Day for Stealing Data from Guest VMs

Published on

spot_img

A Chinese cyber-espionage group has been exploiting a zero-day authentication bypass flaw in VMware ESXi hosts to execute privileged commands on guest virtual machines, according to researchers. The vulnerability was discovered by Mandiant, while investigating the activities of UNC3886, a Chinese threat actor that was previously found to have been targeting VMware ESXi hosts. The bug, present in VMware Tools which is designed for enhanced management of guest operating systems, allows attackers to exploit a compromised ESXi host to transfer files to and from Windows, Linux, and vCenter guest virtual machines, without the need for guest credentials and without default logging. VMware has since released a patch for the flaw. While Mandiant found no evidence of UNC3886 utilising any zero-day vulnerability to break into the ESXi environment, they did highlight the threat actor’s ability to flexibly switch up attacker paths and tactics.

Source link

Latest articles

Italian Authorities Dismantle CINEMAGOAL App That Enabled Unauthorized Access to Streaming Platforms

Italian Authorities Dismantle Major Piracy Operation with the Arrest of 70 Individuals Italian law enforcement...

Security Experts Warn That MFA Alone Is Insufficient to Stop Threat Actors

Emergence of Professional Attack Models: An Exploration of the Kali365 Service In the evolving landscape...

7-Eleven Data Breach Affects Franchisee Information

7-Eleven Confirms Data Breach Impacting Franchisees In a troubling announcement, 7-Eleven has confirmed that it...

Project Glasswing Uncovers 10,000 Vulnerabilities, According to Anthropic

Anthropic Launches Project Glasswing to Address AI-Driven Vulnerabilities in Software Anthropic has recently inaugurated Project...

More like this

Italian Authorities Dismantle CINEMAGOAL App That Enabled Unauthorized Access to Streaming Platforms

Italian Authorities Dismantle Major Piracy Operation with the Arrest of 70 Individuals Italian law enforcement...

Security Experts Warn That MFA Alone Is Insufficient to Stop Threat Actors

Emergence of Professional Attack Models: An Exploration of the Kali365 Service In the evolving landscape...

7-Eleven Data Breach Affects Franchisee Information

7-Eleven Confirms Data Breach Impacting Franchisees In a troubling announcement, 7-Eleven has confirmed that it...