Your ESX Environment May Be More Exposed Than You Think

Most organizations running VMware ESX and vCenter have foundational controls in place: patching, restricted administrative access, credential protections, segmentation, and backups. But those controls do not answer the most important operational question: can your...

Anubis: A Threat Profile

Aliases  Sphinx — original codename under which early ransomware samples and initial victims were recorded in late 2024, before formal rebranding  Anubis__media — operator persona used on the XSS underground forum  superSonic — operator persona used on the RAMP...

Stopping the Fairlife Playbook on ESXi

Reports indicate the attack that halted Fairlife’s US production targeted the Nutanix hypervisor, the one place in the technology stack with no runtime security. The same playbook works against VMware ESXi. Each attack stage below maps to a ZeroLock control that...

Stopping the Fairlife Playbook on ESXi

MITRE ATT&CK v17: New TTPs for ESXi ZeroLock was designed to deliver enterprise-grade hypervisor security without the operational friction that typically slows adoption. From rapid deployment to broad platform support, it integrates seamlessly into existing...

ESX Hardening vs. Behavioral Enforcement

MITRE ATT&CK v17: New TTPs for ESXi ZeroLock was designed to deliver enterprise-grade hypervisor security without the operational friction that typically slows adoption. From rapid deployment to broad platform support, it integrates seamlessly into existing...

INC Ransom: A Threat Profile

Aliases GOLD IONIC — Secureworks / Counter Threat Unit tracking name G1032 — MITRE ATT&CK group identifier   Profiling Threat Actor Type: Ransomware-as-a-Service (RaaS) operation with double extortion. Whether INC Ransom operates as a fully open affiliate...