Large scale cyberattack in Europe via VMWare ESXi

  • 8 February 2023
  • 1 reply
  • 15 views

  • Anonymous
  • 0 replies

https://www.techradar.com/news/widespread-cyberattack-hits-servers-across-europe

Looks like this is a bad one, and it’s not a new vulnerability.  Patch your stuff!

Anyone here been hit by this one?


1 reply

Looks like it’s getting worse:

https://www.bleepingcomputer.com/news/security/new-esxiargs-ransomware-version-prevents-vmware-esxi-recovery/

There was a recovery script that was working, but it doesn’t work for the latest version of ESXiArgs:

https://github.com/cisagov/ESXiArgs-Recover/blob/main/recover.sh

Bleeping Computer has a dedicated thread if you want to stay up to date on the latest:

https://www.bleepingcomputer.com/forums/t/782193/esxi-ransomware-help-and-support-topic-esxiargs-args-extension/

And finally here’s the vulnerability entry from VMWare:

https://www.vmware.com/security/advisories/VMSA-2021-0002.html

Reply