The BlackByte ransomware group is actively exploiting a vulnerability in VMware ESXi, identified as CVE-2024-37085, to escalate privileges and compromise systems. This attack involves using vulnerable drivers to disable security measures, making it particularly dangerous. The group has been observed blending traditional tradecraft with newly disclosed vulnerabilities to support ongoing attacks. This marks a departure from their established methods, as noted by Talos Security.
CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet: https://t.co/pXQvZcn57a by darkreading #infosec #cybersecurity #technology #news
BlackByte Targets ESXi Bug With Ransomware to Access Virtual Assets: https://t.co/2Ko3EWB8M4 by darkreading #infosec #cybersecurity #technology #news
The BlackByte #ransomware group was observed exploiting a recent authentication bypass vulnerability in @VMware ESXi, a technique that departs from the group’s established tradecraft, according to @TalosSecurity. #cybersecurity #infosec #ITsecurity https://t.co/PvXJERhX1I