"Chinese Hackers Exploit VMware Zero-Day Flaw for 2 Years, Targeting Critical vCenter Vulnerabilities"

TL;DR Summary
A China-linked cyber espionage group, UNC3886, has been exploiting a critical zero-day vulnerability (CVE-2023-34048) in VMware vCenter Server since late 2021, allowing them to gain privileged access, deploy malware, and execute arbitrary commands. This group has a history of leveraging zero-day vulnerabilities and has also targeted Fortinet appliances. VMware vCenter Server users are advised to update to the latest version to mitigate potential threats, as the group continues to exploit vulnerabilities in virtualization and firewall technologies.
- Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years The Hacker News
- VMware confirms critical vCenter flaw now exploited in attacks BleepingComputer
- Russians invade Microsoft exec mail while China jabs at VMware vCenter Server The Register
- Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 Mandiant
- Chinese hackers exploit VMware bug as zero-day for two years BleepingComputer
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
2 min
vs 3 min read
Condensed
81%
405 → 76 words
Want the full story? Read the original article
Read on The Hacker News