What is the Attack?Threat actors are exploiting an authentication bypass vulnerability in ESXi hypervisors, known as CVE-2024-37085, to gain full administrative permissions on domain-joined ESXi hypervisors. This flaw allows threat actors to encrypt critical ESXi servers in ransomware attacks. On Monday, July 29, Microsoft published a threat intelligence blog on observed exploitation of CVE-2024-37085. According to the blog, Akira and Black Basta ransomware deployments were found on the impacted servers. The vulnerability has also been added to CISA’s Known Exploited Catalog (KEV) list on July 31, 2024.What is the recommended Mitigation?Please go through the vendor provided update to address the security vulnerability. Support Content Notification – Support Portal – Broadcom support portalWhat FortiGuard Coverage is available?FortiGuard Labs recommends users to apply the patches released by the vendor immediately to secure their systems.FortiGuard Intrusion Prevention Service (IPS) protection is currently being investigated to defend against exploitation of CVE-2024-37085.The FortiGuard Incident Response team can be engaged to help with any suspected compromise.To learn more about the Akira and BlackBasta Ransomware, read the Outbreak Reports posted by FortiGuard Labs. Black Basta Ransomware | Outbreak Alert | FortiGuard LabsAkira Ransomware | Outbreak Alert | FortiGuard Labs
More Stories
rust-zincati-0.0.30-1.fc40
FEDORA-2025-43bcbb0795 Packages in this update: rust-zincati-0.0.30-1.fc40 Update description: New upstream release v0.0.30 see: https://github.com/coreos/zincati/releases/tag/v0.0.30 Read More
rust-zincati-0.0.30-1.fc41
FEDORA-2025-cc269f80fa Packages in this update: rust-zincati-0.0.30-1.fc41 Update description: New upstream release v0.0.30 see: https://github.com/coreos/zincati/releases/tag/v0.0.30 Backport polkit rules patch for CVE-2025-27512...
rust-zincati-0.0.30-1.fc42
FEDORA-2025-19fabb2ca6 Packages in this update: rust-zincati-0.0.30-1.fc42 Update description: New upstream release v0.0.30 see: https://github.com/coreos/zincati/releases/tag/v0.0.30 Read More
bluez-5.80-1.fc42 iwd-3.4-1.fc42 libell-0.74-1.fc42
FEDORA-2025-35347bf9f0 Packages in this update: bluez-5.80-1.fc42 iwd-3.4-1.fc42 libell-0.74-1.fc42 Update description: bluez 5.80: Fix issue with handling address type for all...
dotnet9.0-9.0.104-1.fc40
FEDORA-2025-78dcffbaa1 Packages in this update: dotnet9.0-9.0.104-1.fc40 Update description: This is the monthly update for .NET 9 for March 2025. Release...
dotnet9.0-9.0.104-1.fc41
FEDORA-2025-2edd9dc83b Packages in this update: dotnet9.0-9.0.104-1.fc41 Update description: This is the monthly update for .NET 9 for March 2025. Release...