logo

Russians invade Microsoft exec mail while China jabs at VMware vCenter Server

ID: 78e9e70b-85cf-58e6-ab5e-4e8ef7a872fd

STIX ID: report--78e9e70b-85cf-58e6-ab5e-4e8ef7a872fd

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-01-20

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Mandiant and VMware confirm that the critical CVE-2023-34048 out-of-bounds write in VMware vCenter Server (CVSS 9.8) has been actively exploited since late 2021 by UNC3886 — a China-nexus espionage group — enabling remote code execution and backdoor deployments across a small number of victims; separately, CISA issued an emergency directive after widespread exploitation of Ivanti Connect Secure zero-days (with ~1,700 devices reported compromised) likely involving China-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.