UNC3886: Use of VMCI Sockets for Persistence
UNC3886 is a threat group documented by Mandiant that used VMware VMCI sockets for persistence between compromised ESXi hosts and guest VMs.…
UNC3886 is a threat group documented by Mandiant that used VMware VMCI sockets for persistence between compromised ESXi hosts and guest VMs.…
VMware VMCI is a virtual communication interface that allows traffic to pass through the virtualization layer, bypassing network adapters. SLEEPWALKER uses VMCI…
VCF Fleet is a centralized management capability in VMware Cloud Foundation. Attackers used User-Agent strings like 'GoodMoodle-VCFleet/1.0' to masquerade malicious activity as…
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent…
VMware vCenter Server and vCenter Server Appliance were targeted in a ransomware campaign exploiting CVE-2026-59310 and CVE-2026-59309. The attacks involved deployment of…
VMware vCenter vulnerability (CVE-2026-59310) allows RCE and was exploited by China-nexus APT.
Broadcom has released security updates addressing multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion, including three critical-severity flaws. The most severe…
Broadcom's VMware vCenter path traversal flaw (CVE-2026-59310) was exploited by a China-nexus APT, leading to ransomware deployment.