Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years
ID: 0ad18790-e1fc-58c2-b298-a2b65bc8aac2
STIX ID: report--0ad18790-e1fc-58c2-b298-a2b65bc8aac2
Feed Name: The Hacker News
UNC3886, a China-linked advanced threat actor, has been attributed with weaponizing VMware vCenter Server zero-day CVE-2023-34048 (CVSS 9.8) to obtain privileged access, enumerate ESXi hosts, retrieve vpxuser credentials, and deploy VIRTUALPITA/VIRTUALPIE implants to compromised hosts and guest VMs; the actor also previously exploited Fortinet CVE-2022-41328 to deploy THINCRUST and CASTLETAP. Mandiant reported these activities, VMware acknowledged in-the-wild exploitation and released patches — organizations using vCenter and affected Fortinet products are advised to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
