VMware vCenter is a technology platform tracked across 15 threat clusters and 26 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 23, 2026.
Hewlett Packard Enterprise (HPE) has addressed a critical vulnerability in its OneView software, identified as CVE-2025-37164, which allows attackers to execute arbitrary code remotely without authentication. This flaw…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
Hackers are increasingly targeting newly disclosed vulnerabilities in third-party software to access cloud environments, with the time frame for such attacks decreasing significantly. Google reports a notable decline in…
In June 2026, threat actors targeted Amazon EKS clusters by exploiting Kubernetes credentials or IAM roles to modify workloads and hijack compute resources. Attackers gained initial access through application-layer…
DragonForce, a new ransomware operation derived from Conti's leaked source code, has emerged with a cartel-like structure. The group retains Conti's core encryption and network-spreading capabilities while recruiting…
CISA has added the critical vulnerability CVE-2024-37079 affecting VMware vCenter Server to its Known Exploited Vulnerabilities catalog. Active exploitation of this vulnerability has been detected, impacting enterprise…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
CISA and NSA have issued an alert regarding BRICKSTORM malware that targets VMware ESXi and Windows systems. This malware poses a risk to organizations using these platforms, potentially leading to significant security…