Russians invade Microsoft exec mail while China jabs at VMware vCenter Server
ID: 78e9e70b-85cf-58e6-ab5e-4e8ef7a872fd
STIX ID: report--78e9e70b-85cf-58e6-ab5e-4e8ef7a872fd
Feed Name: The Register (Security)
Mandiant and VMware confirm that the critical CVE-2023-34048 out-of-bounds write in VMware vCenter Server (CVSS 9.8) has been actively exploited since late 2021 by UNC3886 — a China-nexus espionage group — enabling remote code execution and backdoor deployments across a small number of victims; separately, CISA issued an emergency directive after widespread exploitation of Ivanti Connect Secure zero-days (with ~1,700 devices reported compromised) likely involving China-linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
