penfold Posted February 9, 2023 Posted February 9, 2023 Hope this doesn't impact anyone, but worth checking your version of ESXi https://www.bleepingcomputer.com/news/security/new-esxiargs-ransomware-version-prevents-vmware-esxi-recovery/
RLR Posted February 9, 2023 Posted February 9, 2023 This sounds a bit different to the one reported at the begining of the week as the fix was to disable SLP and/or update to a later version. This article suggests SLP was disabled but still got infected. Might have missed it but this article doesn't say what the cause is or how to fix it?
CHiLL Posted February 10, 2023 Posted February 10, 2023 "Internet-exposed VMware ESXi servers" - does that mean the hosts were accessible over the Internet (e.g, remote management), or that guest VMs were accessible (e.g, VPN server)?
Jcx500 Posted February 10, 2023 Posted February 10, 2023 "Internet-exposed VMware ESXi servers" - does that mean the hosts were accessible over the Internet (e.g, remote management), or that guest VMs were accessible (e.g, VPN server)? Most likely means exposed vcenter’s or standalone hosts. Still baffles me why people do this
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now