Sources
Loading...
Additional media
Loading...
The BlackByte ransomware group is actively exploiting a vulnerability in VMware ESXi, identified as CVE-2024-37085, to escalate privileges and compromise systems. This attack involves using vulnerable drivers to disable security measures, making it particularly dangerous. The group has been observed blending traditional tradecraft with newly disclosed vulnerabilities to support ongoing attacks. This marks a departure from their established methods, as noted by Talos Security.