<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: VMware Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving VMware.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor</title><link>https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html</link><guid isPermaLink="false">cst-2674</guid><description>A China-linked threat actor has redeployed Daxin, a kernel-mode rootkit inactive for over four years, in a Taiwan manufacturing company alongside a new backdoor named Stupig. Daxin was previously documented by Symantec in March 2022 as a tool used in targeted attacks.</description><pubDate>Thu, 16 Jul 2026 11:17:23 GMT</pubDate></item><item><title>Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws</title><link>https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html</link><guid isPermaLink="false">cst-2594</guid><description>Mozilla released Firefox updates to patch two critical vulnerabilities in the JavaScript/WebAssembly and DOM/Navigation components with known public exploit code. Chrome, Adobe, and VMware also issued updates for multiple critical security flaws, though details on those vendors' patches are not provided in this incomplete summary.</description><pubDate>Wed, 15 Jul 2026 13:18:53 GMT</pubDate></item><item><title>7 Severe Vulnerabilities Patched in VMware Avi Load Balancer</title><link>https://securityweek.com/7-severe-vulnerabilities-patched-in-vmware-avi-load-balancer</link><guid isPermaLink="false">cst-2498</guid><description>VMware patched seven severe vulnerabilities in Avi Load Balancer that could enable authentication bypass, remote code execution, privilege escalation, and directory traversal. The specific CVE numbers, affected versions, and remediation details were not provided in the available information.</description><pubDate>Tue, 14 Jul 2026 13:55:41 GMT</pubDate></item><item><title>Pwn2Own Berlin 2026: Day Three Results and Master of Pw</title><link>https://thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn</link><guid isPermaLink="false">cst-392</guid><description>Pwn2Own Berlin 2026 concluded on Day Three with security researchers demonstrating 47 unique zero-day vulnerabilities across the three-day competition. DEVCORE won the Master of Pwn title with 50.5 points and $505,000, followed by STARLabs SG and Out Of Bounds, with a total of $1,298,250 awarded for all disclosed vulnerabilities.</description><pubDate>Sat, 16 May 2026 10:38:50 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>vSphere and BRICKSTORM Malware: A Defender's Guide</title><link>https://cloud.google.com/blog/topics/threat-intelligence/vsphere-brickstorm-defender-guide</link><guid isPermaLink="false">cst-317</guid><description>Google Threat Intelligence Group published research on BRICKSTORM malware targeting VMware vSphere environments, with a focus on hardening strategies to defend virtualized infrastructure. Threat actors exploit weak security architecture, identity design, and limited visibility at the virtualization control plane to establish persistence beneath the guest operating system where traditional security tools are ineffective. Mandiant released a vCenter Hardening Script to help organizations enforce security configurations at the Photon Linux layer and transform the virtualization layer into a hardened environment.</description><pubDate>Thu, 02 Apr 2026 14:00:00 GMT</pubDate></item><item><title>Announcing Pwn2Own Berlin for 2026</title><link>https://thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026</link><guid isPermaLink="false">cst-397</guid><description>Pwn2Own Berlin 2026 will take place May 14-16 with over $1 million in prizes across 31 targets in 10 categories, including newly expanded artificial intelligence categories and increased rewards for Firecracker vulnerabilities. AWS has joined as a co-sponsor, and the competition returns to OffensiveCon after a successful 2025 inaugural event. Registration closes May 7, and the winner will be crowned Master of Pwn with prizes including ZDI reward points, a trophy, and a jacket.</description><pubDate>Thu, 12 Mar 2026 16:25:15 GMT</pubDate></item><item><title>ESXi Exploitation in the Wild</title><link>https://huntress.com/blog/esxi-vm-escape-exploit</link><guid isPermaLink="false">cst-768</guid><description>Huntress has documented an active multi-stage attack that exploits vulnerabilities to escape guest virtual machines and compromise VMware ESXi hypervisors, leveraging VSOCK communication channels to conceal the exploitation chain. The attack involves potential zero-day exploits that allow attackers to move from guest systems to the underlying hypervisor infrastructure.</description><pubDate>Wed, 07 Jan 2026 14:00:00 GMT</pubDate></item><item><title>BERT Ransomware's First Moves: Kill the VMs, Kill the Backups</title><link>https://halcyon.ai/blog/bert-ransomwares-first-moves-kill-the-vms-kill-the-backups</link><guid isPermaLink="false">cst-2064</guid><description>BERT ransomware's initial attacks focus on compromising ESXi hosts to simultaneously disable multiple virtual machines and backup systems, amplifying the impact across an organization's infrastructure. This attack pattern exploits the centralized nature of virtualization environments to maximize damage and operational disruption from a single point of compromise.</description><pubDate>Tue, 08 Jul 2025 15:49:59 GMT</pubDate></item><item><title>Ransomware attacks targeting VMware ESXi servers: everything you need to know</title><link>https://wiz.io/blog/ransomware-attacks-targeting-vmware-esxi-servers-everything-you-need-to-know</link><guid isPermaLink="false">cst-1751</guid><description>Recent attacks are exploiting CVE-2021-21974, a known vulnerability in VMware ESXi servers, to deploy ransomware. Security teams are being urged to apply patches and monitor for signs of compromise on affected systems.</description><pubDate>Tue, 07 Feb 2023 12:26:52 GMT</pubDate></item><item><title>Wiz introduces VMware vSphere support to provide a unified hybrid cloud security platform</title><link>https://wiz.io/blog/wiz-introduces-vmware-vsphere-support-to-provide-a-unified-hybrid-cloud-security</link><guid isPermaLink="false">cst-1780</guid><description>Wiz has added VMware vSphere integration to its cloud security platform, enabling coverage of both on-premises and cloud environments. The integration is agent-less, allowing unified security monitoring across hybrid infrastructure without requiring additional software deployment.</description><pubDate>Mon, 07 Nov 2022 13:56:14 GMT</pubDate></item><item><title>Threat Recap: Huntress Managed EDR Trial by Fire | Huntress</title><link>https://huntress.com/blog/threat-recap-process-insights-trial-by-fire</link><guid isPermaLink="false">cst-1153</guid><description>Huntress Managed EDR detected and helped respond to follow-on attacks targeting VMware Horizon servers in real time. The case study demonstrates how the platform identified and mitigated post-compromise activity on affected systems.</description><pubDate>Tue, 25 Jan 2022 00:00:00 GMT</pubDate></item><item><title>VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress</title><link>https://huntress.com/blog/cybersecurity-advisory-vmware-horizon-servers-actively-being-hit-with-cobalt-strike</link><guid isPermaLink="false">cst-1156</guid><description>Huntress has identified active attacks targeting VMware Horizon servers with Cobalt Strike malware. The attackers are leveraging the remote access capabilities of Horizon to deliver post-exploitation tools and maintain persistence.</description><pubDate>Sat, 15 Jan 2022 00:00:00 GMT</pubDate></item></channel></rss>