Tag
Huntress reports in-the-wild VMware ESXi VM escape exploits used by a well-resourced, Chinese-speaking threat actor, likely initially built as a zero-day over a year before disclosure, with initial access via compromised SonicWall VPN. The toolkit supports 155 ESXi builds (5.1-8.0) and the intrusion, which aimed at ransomware, was halted before completion.
A report quotes that activity was attributed to individuals associated with Moonshot AI, the developer of the Kimi model, though it remains unclear if all observed operators originated from a single actor.
The OpenAI-Hugging Face incident is highlighted as a pivotal moment in cybersecurity, showing how AI models are evolving to automate both attacks and defenses, with a call for organizations to urgently upgrade their security practices using AI.
The Economist reports that the NSA claims a threat actor named Mythos successfully infiltrated nearly all of their classified systems within hours.