Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Chinese hackers exploiting vmware zero-day from October 2024
    Security

    Chinese hackers exploiting vmware zero-day from October 2024

    PineapplesUpdateBy PineapplesUpdateSeptember 30, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Chinese hackers exploiting vmware zero-day from October 2024
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Chinese hackers exploiting vmware zero-day from October 2024

    Broadcom has packed the vulnerability to increase a high-severity privilege in its VMWARE ARIA operation and VMware tools software, which has been exploited in zero-day attacks since October 2024.

    While American technology giants did not tag this security bug (Cve-2025-41244) As is exploited in the wild, it Thanks NVISO Danger Researcher Maxime Thiebaut To report bug in May.

    However, yesterday, the European Cyber ​​Security Company revealed that the vulnerability was first exploited in the wild initial initial in mid-October 2024 and the attacks were linked to the UNC5174 Chinese state-proposed danger actor.

    “To misuse this vulnerability, an unpublished local attacker can staging a malicious binary within any of the widely matched regular expression paths. A simple common place, which is abused in the wild by UNC5174, is /TMP /httpd,” Thiebaut explained,

    “To ensure that the malicious binary is raised by the discovery of VMWARE service, the binary should be run by unexpected user (ie, showing in the tree of the process) and opening at least (random) listening sockets.”

    NVISO also issued a proof-of-concept exploitation, showing how attackers can exploit CVE-2025-41244 defects so that weak VMWARE ARIA operations (in credential-based mode) and vmware tools (in credensible-level mode) to increase specialized vm to get special hon less Route-level code can be obtained.

    A spokesperson of Broadcom did not immediately provide comments on the contact by Bleepingcomputer today.

    Who is UnC5174?

    Google Mandient Security Analyst, who believes that UnC5174 is a contractor for the Chinese State Security Ministry (MSS), has seen the actor with danger Selling access to US defense contractors’ networkAfter the UK government institutions, and Asian institutions, F5-IP CVE-2023-46747 remote code execution vulnerabilities at the end of 2023.

    In February 2024, it also exploited Cve-2024-1709 ConnectWise Schenconnect Flaw To dissolve hundreds of we and Canadian institutions.

    Earlier this year, in May, UNC5174 was also linked to the in-walled exploitation of the CVE-2025-31324 informal file uploading defects that enable the attackers to achieve remote code execution on the weaker networks visual music servers.

    Other Chinese danger actors (eg, Chaya_004, UNC5221, and CL-STA-0048) also joined this wave of attacks, 580 SAP Netwever examples include backdoring, including a significant infrastructure in the United Kingdom and the United States.

    On Monday, Broadcom also packed two high-seriousness VMware NSX weaknesses mentioned by the US National Security Agency (NSA).

    In March, the company actively exploited three other actively exploitation of the Microsoft Danger Reported by the Microsoft Danger (CVE-2025-222224, CVE-2025-22225, and CVE-2025-22226).


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    Chinese exploiting hackers October Vmware zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBook your exhibition table until 2025 is disrupted. Tekkachchan
    Next Article Amazon event 2025 Live: Alexa, Ring, Blink Arch, Fire TV, Kindle, Peacock
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How a simple link allowed hackers to bypass Copilot’s security guardrails – and what Microsoft did about it

    January 19, 2026
    Startups

    How Microsoft’s new security agent helps businesses stay one step ahead of AI-enabled hackers

    November 21, 2025
    Startups

    A new Chinese AI model claims to outperform GPT-5 and Sonnet 4.5 – and it’s free

    November 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.