VMware ESXi ransomware outbreak hits Florida state court system, U.S., EU universities

Share post:

A global ransomware outbreak has intercepted servers affiliated to Florida’s Supreme Court and several universities in the United States and Central Europe after attackers exploited a 2-year-old vulnerability in widely used software made by California-based cloud computing giant VMWare.

According to Ransomwhere, a user generated platform that records digital extortion attempts and online ransom payments and whose figures are drawn from internet scans, these organizations are among more than 3,800 victims of a rapidly spreading digital extortion campaign that locked up thousands of servers in Europe over the weekend.

Ransomwhere stated that only four of those victims have paid ransoms so far. It is also unclear how much the ransomware, which encrypts computers and demands a payment, has disrupted operations at the victim organizations.

As the victim organizations left the vulnerable software exposed directly to the public internet, cybercriminals were able to break in more easily. The Cybersecurity and Infrastructure Security Agency (CISA) of the United States has released a recovery script in an attempt to mitigate the damage caused by the attacks, which may have been carried out by a gang known as ESXiArgs.

French and Italian government agencies have also issued warnings about the attacks late last week and over the weekend.

The sources for this piece include an article in Reuters.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways