TLDR: Trump’s Trash Reich Gestapo-wannabes at Homeland Security are afraid of Chinese competition.
>About Cybersecurity and Infrastructure Security Agency
>The Cybersecurity and Infrastructure Security Agency (CISA), a component of the U.S. Department of Homeland Security (DHS), is tasked with cybersecurity and infrastructure protection across all government levels. Created in 2018 via the Cybersecurity and Infrastructure Security Agency Act of 2018, CISA’s main goal is to improve the security of critical national infrastructure from cyber threats and other dangers. Its duties encompass cybersecurity coordination, critical infrastructure protection, cyber incident response, risk management, and resilience. Furthermore, CISA manages National Special Security Events, protects the census, and aids U.S. responses to public health crises. Headquartered in Arlington, Virginia, the agency anticipates relocating to a larger facility in 2025.Less
[https://www.cisa.gov/](https://www.cisa.gov/)
thieh on
Who still uses VMware after broadcom jacked up the price by 300% and sued the counterparty during license fee negotiations?
Ultimatecookie57 on
Another zero day getting actively exploited before patches drop. If you’re running VMware servers exposed to the internet, this is your wakeup call to segment that network yesterday. These state-sponsored groups don’t just scan they sit and wait.
Shaggyfries on
CISA didn’t get cut by doge?😂
AppleTree98 on
From the article- DAMN
„…CISA says it analyzed eight Brickstorm malware samples.
These samples were discovered on networks belonging to victim organizations, where the attackers specifically targeted VMware vSphere servers to create hidden rogue virtual machines to evade detection and steal cloned virtual machine snapshots for further credential theft.“
ilevelconcrete on
It’s so crazy that anything tangentially related to a country of a billion and a half people gets it labeled “Chinese”, but if you dare to insinuate that Americans who willingly volunteered to join their military might have some share of blame for its many crimes, you get a million annoying replies that are like “ummm wow, most people in the army don’t even get to kill innocent brown people, they just do innocent tasks like loading the bombs onto the planes but go off”
Muted_Delivery4655 on
I’m assuming Horizon is also included in this?
Mr_Enemabag-Jones on
Sooooo lateral movement from a DMZ server to your vCenter.
This is not a VMware issue. This is a piss poor architecture and flat network issue.
Your vSphere management plane should only be accessible from known jump servers using proper privilege access management.
9 Kommentare
TLDR: Trump’s Trash Reich Gestapo-wannabes at Homeland Security are afraid of Chinese competition.
>About Cybersecurity and Infrastructure Security Agency
>The Cybersecurity and Infrastructure Security Agency (CISA), a component of the U.S. Department of Homeland Security (DHS), is tasked with cybersecurity and infrastructure protection across all government levels. Created in 2018 via the Cybersecurity and Infrastructure Security Agency Act of 2018, CISA’s main goal is to improve the security of critical national infrastructure from cyber threats and other dangers. Its duties encompass cybersecurity coordination, critical infrastructure protection, cyber incident response, risk management, and resilience. Furthermore, CISA manages National Special Security Events, protects the census, and aids U.S. responses to public health crises. Headquartered in Arlington, Virginia, the agency anticipates relocating to a larger facility in 2025.Less
[https://www.cisa.gov/](https://www.cisa.gov/)
Who still uses VMware after broadcom jacked up the price by 300% and sued the counterparty during license fee negotiations?
Another zero day getting actively exploited before patches drop. If you’re running VMware servers exposed to the internet, this is your wakeup call to segment that network yesterday. These state-sponsored groups don’t just scan they sit and wait.
CISA didn’t get cut by doge?😂
From the article- DAMN
„…CISA says it analyzed eight Brickstorm malware samples.
These samples were discovered on networks belonging to victim organizations, where the attackers specifically targeted VMware vSphere servers to create hidden rogue virtual machines to evade detection and steal cloned virtual machine snapshots for further credential theft.“
It’s so crazy that anything tangentially related to a country of a billion and a half people gets it labeled “Chinese”, but if you dare to insinuate that Americans who willingly volunteered to join their military might have some share of blame for its many crimes, you get a million annoying replies that are like “ummm wow, most people in the army don’t even get to kill innocent brown people, they just do innocent tasks like loading the bombs onto the planes but go off”
I’m assuming Horizon is also included in this?
Sooooo lateral movement from a DMZ server to your vCenter.
This is not a VMware issue. This is a piss poor architecture and flat network issue.
Your vSphere management plane should only be accessible from known jump servers using proper privilege access management.
If only CISA could do something about it!!! [Oh yeah wait… fuck Elon.](https://www.axios.com/2025/06/03/cisa-staff-layoffs-resignations-trump-cuts)