Security Feed
  1. Archives

Jan 08 2026 VMware ESXi zero-days likely exploited a year before disclosure

Source

Chinese-speaking threat actors used a compromised SonicWall VPN appliance to deliver a VMware ESXi exploit toolkit that seems to have been developed more than a year before the targeted vulnerabilities became publicly known. [...]

Posted by Bill Toulas on Thu 08 January 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Security Blog
  • Biz & IT
  • Microsoft
  • Security & Identity
  • AI
  • google
  • CryptoCurrency
  • Announcements
  • A Little Sunshine
  • Foundational (100)
  • Legal
  • privacy
  • Artificial Intelligence
  • Mobile
  • Apple
  • squid
  • Intermediate (200)
  • Advanced (300)
  • Technical How-to
  • hacking
  • The Coming Storm
  • Best Practices

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.