logo

Scans for VMWare Hybrid Cloud Extension (HCX) API (Log4j - not brute forcing), (Wed, Mar 12th)

ID: 16499f07-d7f7-527d-922f-4392e71cf1bf

STIX ID: report--16499f07-d7f7-527d-922f-4392e71cf1bf

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2025-03-12

Date Updated: 2026-04-19

...
...

The report describes active scanning and exploitation attempts against the VMware HCX /hybridity/api/sessions endpoint where attackers submit Log4j JNDI payloads in the username field to trigger remote lookups (OAST), indicating exploitation of the Log4j vulnerability rather than credential brute-forcing; it includes a complete malicious request sample and the originating IP observed in logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.