Theregister
Chinese Cybercriminals Exploit ESXi Zero-Days Before Public Disclosure
First seen 9 Jan 2026, 17:57 UTC
•
•33.3
Export
Article Content
Browse articles
Chinese-linked cybercriminals utilized a VMware ESXi hypervisor escape toolkit over a year prior to the public disclosure of the vulnerabilities. Researchers at Huntress identified an intrusion in December 2025, revealing that the toolkit's development began as early as February 2024. This sophisticated attack targeted the ESXi hypervisor by breaking out of virtual machines.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Cisco SD-WAN Zero-Day Exploited by Threat Actor Since 2023
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
Escalating Cyber Warfare Threats Amid Geopolitical Tensions
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks