Ransomware Gangs Exploit ESXi Bug for Instant, Mass Encryption of VMs
ID: cea9efe5-a5ac-5671-b55d-2f8c7ea2e8bf
STIX ID: report--cea9efe5-a5ac-5671-b55d-2f8c7ea2e8bf
Feed Name: Dark Reading
Threat Score
Multiple ransomware groups have been exploiting VMware ESXi vulnerability CVE-2024-37085 — which grants full ESXi administrative access to any AD domain group named "ESX Admins" — to quickly escalate privileges and deploy ransomware (e.g., Black Basta, Akira) across virtualized environments; Broadcom has released a patch and organizations are urged to apply it and improve hypervisor hygiene and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
