Scworld
Chinese-speaking actors exploit VMware ESXi zero-days via SonicWall VPN breach
First seen 9 Jan 2026, 20:34 UTC
•
•33.2
Export
Article Content
Browse articles
Chinese-speaking threat actors conducted attacks using a VMware ESXi exploit toolkit that leveraged three zero-day vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226. The initial access was gained through a compromised SonicWall VPN, allowing attackers to pivot to domain controllers and execute the exploit chain. These vulnerabilities were disclosed in March 2025, but the attacks occurred last month.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
SonicWall Patches Actively Exploited Zero-Day Vulnerability CVE-2025-40602
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
Surge in Brute-Force Attacks Targeting SonicWall and Fortinet Devices
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766