On Monday, July 29, Microsoft published an extensive threat intelligence blog on observed exploitation of CVE-2024-37085, an Active Directory integration authentication bypass vulnerability affecting Broadcom VMware ESXi hypervisors.
The vulnerability, according to Redmond, was identified in zero-day attacks and has evidently been used by at least half a dozen ransomware operations to obtain full administrative permissions on domain-joined ESXi hypervisors (which, in turn, enables attackers to encrypt downstream file systems).
Read more…
Source: Rapid7
Related:
- Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction
August 14, 2026
Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side. Luckily, the vulnerability was discovered by white hat hackers, ...
- Patch Tuesday: Update now to fix 421 flaws, including three zero-days
August 12, 2026
Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: ...
- The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know
August 11, 2026
CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...
- UK MoD says no data leaked to China via drone vulnerability
August 10, 2026
Britain’s Ministry of Defence said on Monday that there is no evidence that military data was compromised after a cyber vulnerability was discovered in Royal Navy drones. The issue was identified during routine cybersecurity testing, the ministry said, adding that it continues to conduct security checks across its equipment and systems. Read more… Source: EUROACTIV Sign up for the ...
- Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
August 7, 2026
Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand ...
- Buggy microcontrollers making up some of the world’s most important servers can be easily backdoored
August 6, 2026
Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular enterprise servers. BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide ...
