BLOG POSTS
LockBit: A Threat Profile
Aliases ABCD ransomware LockBit 2.0 LockBit Black (3.0) LockBit Green LockBit 5.0 Get Threat Intel and Security Updates Delivered to Your Inbox. [gravityform id="12" title="false" description="false" ajax="true" tabindex="49"...
The 99% Solution: MFA for Hypervisor Security
Hypervisor attacks are accelerating, and the cost is catastrophic. Recent ESXi ransomware attacks have cost organizations hundreds of millions in recovery. In some cases, a single ESXi breach has led to costs exceeding $400 million. ...
Scattered Spider and the Finance Sector: Ransomware Tactics Banks Can’t Afford to Ignore
The financial sector is built on trust, speed, and constant availability. Despite publicly announcing their “retirement,” Scattered Spider has resurfaced with fresh intrusions into U.S. banks and financial services. Their latest ESXi...
Executive Briefing: Hypervisor Ransomware—The Hidden $400 Million Board-Level Exposure
Why The Board Should Act Now As hypervisor attacks surge and exposure widens, this once-overlooked layer now poses material risk to revenue, operations, and oversight. Ransomware on VMware ESXi has tripled YoY. Attackers have shifted to...
Scattered Spider: A Threat Profile
Aliases UNC3944 (Google Mandiant) The Com/The Community Octo Tempest (Microsoft) Oktapus (Group-IB) Muddled Libra (Palo Alto Unit 42) Scatter Swine (Okta) StarFraud Storm-0875 Profiling Demographics: Primarily young operators (assessed...
RansomHub Is Gone—But Their ESXi Ransomware Tactics Still Threaten Virtual Infrastructure
In 2024, one ransomware group surged to the forefront: RansomHub. Rapidly dominating the ransomware-as-a-service (RaaS) landscape, this formidable cybercriminal network successfully breached over 600 organizations worldwide, targeting...
Scattered Spider: The Group Behind Major ESXi Ransomware Attacks
A new wave of ransomware actors is rewriting the rulebook, and their sights are set on the foundation of enterprise infrastructure: VMware ESXi. Scattered Spider—also tracked as UNC3944, 0ktapus, and Muddled Libra among others—is one of...
From Retail Floors to Virtual Cores: ESXi Is the Next Attack Vector in Retail
In April 2025, Marks & Spencer—one of Britain’s most successful retailers—was crippled by a ransomware attack that didn’t just encrypt endpoints. It locked down VMware ESXi hypervisors, freezing core systems and bringing operations to...
The Oversight That Could Cost You: Why Basic Hypervisor Protection Fails
Modern hypervisors form the backbone of today's cloud and virtualization environments. By enabling multiple business functions to reside on a single physical server, they enhance efficiency and reduce administrative overhead. As...
ZeroLock® Mitigates 100% of ESXi TTPs
MITRE ATT&CK v17 introduces a dedicated ESXi platform, marking a major shift in cybersecurity priorities. The new ESXi matrix spans 12 attack stages — adapting 34 Linux TTPs, carrying over 30 more, and introducing 4 ESXi-specific...
MITRE ATT&CK v17: Spotlighting ESXi
In a landmark update, MITRE ATT&CK v17 introduces a dedicated ESXi platform to its framework, bringing hypervisor threats into the spotlight. This move validates what security teams have been seeing for years: attackers are targeting...
Why ESXi Security in Manufacturing Can’t Wait
Industry 4.0 is transforming manufacturing, making operations smarter, faster, and more efficient. But with increased connectivity comes increased risk. Hypervisor threats are evolving fast—especially for organizations relying on VMware...
MITRE ATT&CK v17 Is Coming: What Security Teams Should Watch For
MITRE ATT&CK v17 is set to launch on April 22, 2025. While full details haven’t been released, a recent X post from MITRE suggests that VMware ESXi may be a new focus area—an important signal as concerns around ESXi ransomware...
Virtual Patching: How to Protect VMware ESXi from Zero-Day Exploits
Broadcom recently patched three VMware zero-days (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226), suspected to be actively exploited. These vulnerabilities allow attackers with VM admin access to break out, execute code on the...
ESXi Ransomware: The Growing Threat to Virtualized Environments
Ransomware has reshaped the cybersecurity landscape, and a disturbing new trend is emerging: the targeting of VMware ESXi environments. As the core of countless organizations’ IT infrastructures, VMware ESXi has become a prime target for...
Protecting Networks at Scale: The Cyber Imperative for Managed Providers
Cybersecurity has become a critical concern across industries, but Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) are facing mounting pressure to secure not only their own operations, but also the vast...