China-linked Cybercriminals Exploit VMware ESXi Vulnerabilities
First seen 9 Jan 2026, 15:51 UTC
•
•33
Export
Article Content
Browse articles
Chinese-linked cybercriminals utilized a VMware ESXi hypervisor escape kit to target the ESXi hypervisor. Researchers from Huntress reported that the toolkit was in development as early as February 2024 and was used in an intrusion observed in December 2025. The attack involved sophisticated techniques to break out of virtual machines.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Cisco SD-WAN Zero-Day Exploited by Threat Actor Since 2023
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
Escalating Cyber Warfare Threats Amid Geopolitical Tensions
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks