CVE-2023-34048
published 2023-10-25CVE-2023-34048: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-02-12
Exploited in the wild
EPSS
99.43%
99.9th percentile
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | 4.0 – 5.5 | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_cloud_foundation | — | — |
| vmware | vmware_vcenter_server | >= 7.0 < 7.0U3o | 7.0U3o |
| vmware | vmware_vcenter_server | >= 8.0 < 8.0U2 | 8.0U2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for python.exe or pythonw.exe loading a DLL named python20.dll — a strong indicator of DLL side-loading used by post-exploitation actors following CVE-2023-34048 compromise of vCenter. ↗
- →Detect FRP (Fast Reverse Proxy) samples containing the unique authentication token 'frpforzhangwei' or proxy names matching the pattern '10014-win-nic-32-v', '20012-linux-64-V', or '10013-linux-64-V'. ↗
- →Alert on certutil -encode being invoked against .rar archives in web server directories, a technique used to exfiltrate data via web shell output without file upload. ↗
- →Hunt for VirtualPita and VirtualPie backdoors deployed on ESXi hosts via maliciously crafted vSphere Installation Bundles (VIBs) — post-exploitation artifacts following CVE-2023-34048 exploitation by UNC3886. ↗
- →Restrict and monitor network access to vCenter Server management interfaces; CVE-2023-34048 is exploitable by any actor with network access via a specially crafted DCERPC packet, requiring no authentication. ↗
- →Detect creation of archive files (web.rar, web1.rar, web2.rar) under c:\inetpub\wwwroot as an indicator of staged exfiltration following initial access. ↗
- →Monitor for GodZilla and AntSword web shell deployment on Linux and Windows servers as initial post-exploitation indicators associated with actors leveraging CVE-2023-34048. ↗
- ·CVE-2023-34048 was exploited as a zero-day by UNC3886 since at least late 2021, well before public disclosure — environments should assume potential historic compromise even if patched promptly after disclosure. ↗
- ·No official workaround exists for CVE-2023-34048; the only mitigation is patching. Strict network perimeter controls on vSphere management interfaces are recommended as a compensating control. ↗
- ·Not every post-exploitation tool in the CL-UNK-1068 toolset was used in every intrusion; detection coverage should span the full toolkit rather than relying on any single indicator. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
VMware vCenter Server Out-of-Bounds Write Vulnerability
cisa·2024-01-22·CVSS 9.8
CVE-2023-34048 [CRITICAL] CWE-787 VMware vCenter Server Out-of-Bounds Write Vulnerability
Vulnerability: VMware vCenter Server Out-of-Bounds Write Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.vmware.com/security/advisories/VMSA-2023-0023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-34048
Remediation Due Date: 2024-02-12
VMware
VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
vendor_vmware·2023-10-25·CVSS 9.8
CVE-2023-34048 [CRITICAL] VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
VMSA-2023-0023: VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities (CVE-2023-34048, CVE-2023-34056)
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2023-34048, CVE-2023-34056
Affected products: VMware Cloud Foundation, VMware vCenter Server
GHSA
GHSA-87j2-5g9j-7jmv: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol
ghsa_unreviewed·2023-10-25
CVE-2023-34048 [CRITICAL] CWE-787 GHSA-87j2-5g9j-7jmv: vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol
vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.
VulnCheck
VMware vCenter Server Out-of-Bounds Write Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-34048 [CRITICAL] CWE-787 VMware vCenter Server Out-of-Bounds Write Vulnerability
VMware vCenter Server Out-of-Bounds Write Vulnerability
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Affected: VMware vCenter Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.vmware.com/security/advisories/VMSA-2023-0023.html; https://www.mandiant.com/resources/blog/chinese-vmware-exploitation-since-2021; https://www.rapid7.com/blog/post/2024/01/19/etr-critical-cves-in-outdated-versions-of-atlassian-confluence-and-vmware-vcenter-server/; https://censys.com/cve-2023-34048-vmware-vcenter/; https://www.cisa.gov/sites/default/files/feeds/known_expl
No detection rules found.
Nuclei
VMware vCenter Server - Out-of-Bounds Write
nuclei·CVSS 9.8
CVE-2023-34048 [CRITICAL] VMware vCenter Server - Out-of-Bounds Write
VMware vCenter Server - Out-of-Bounds Write
vCenter Server contains an out-of-bounds write caused by a vulnerability in the DCERPC protocol implementation. A malicious actor with network access can trigger remote code execution on vCenter Server.
Template:
id: CVE-2023-34048
info:
name: VMware vCenter Server - Out-of-Bounds Write
author: ritikchaddha
severity: critical
description: |
vCenter Server contains an out-of-bounds write caused by a vulnerability in the DCERPC protocol implementation. A malicious actor with network access can trigger remote code execution on vCenter Server.
impact: |
Unauthenticated attackers with network access can exploit the out-of-bounds write vulnerability in the DCERPC protocol to execute arbitrary code on vCenter Server, potentially compromising the ent
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Unit42
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
blogs_unit42·2026-03-06
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
## An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
Tom Fakterman
Published: March 6, 2026
Malware
Threat Research
CL-UNK-1068
DLL Sideloading
Fast Reverse Proxy
ScanPortPlus
Xnote
## Executive Summary
Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications.
Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined.
We assess with high confidence that the atta
Unit42
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
blogs_unit42·2026-03-06
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
## Executive Summary
Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications.
Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined.
We assess with high confidence that the attackers behind CL-UNK-1068 are a Chinese threat actor. This assessment is based on the origin of their tools, linguistic artifacts in configuration files, and their consistent, longstanding targeting of critical infrastructure in
Bleepingcomputer
Chinese cyberspies breach Singapore's four largest telcos
blogs_bleepingcomputer·2026-02-09
Chinese cyberspies breach Singapore's four largest telcos
## Chinese cyberspies breach Singapore's four largest telcos
## Bill Toulas
The Chinese threat actor tracked as UNC3886 breached Singapore’s four largest telecommunication service providers, Singtel, StarHub, M1, and Simba, at least once last year.
The hackers also gained limited access to critical systems but did not pivot deep enough to disrupt services.
In response to the intrusions, which were disclosed in July 2025, Singapore deployed ‘Operation Cyber Guardian’ to limit the adversary's activity on the telco's networks, but very few details were shared at the time.
"Over the past months, our investigations have indicated that UNC3886 had launched a deliberate, targeted, and well-planned campaign against Singapore’s telecommunications sector," Singapore's Cyber Security Agency (CSA
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Trendmicro
Revisiting UNC3886 Tactics to Defend Against Present Risk
blogs_trendmicro·2025-07-28
Revisiting UNC3886 Tactics to Defend Against Present Risk
APT & Targeted Attacks
# Revisiting UNC3886 Tactics to Defend Against Present Risk
We examine the past tactics used by UNC3886 to gain insight on how to best strengthen defenses against the ongoing and emerging threats of this APT group.
By: Cj Arsley Mateo, Ieriz Nicolle Gonzalez, Jacob Santos, Paul John Bardon, Angelo Junio, Rayven Cervantes
2025/07/28
Read time: ( words)
Save to Folio
## Key Takeaways
- UNC3886 is an APT group that has historically targeted critical infrastructure, including telecommunications, government, technology, and defense, with a recent attack against Singapore.
- The group is known for rapidly exploiting zero-day and high-impact vulnerabilities in network and virtualization devices such as VMware vCenter/ESXi, Fortinet FortiOS, and Juniper Junos OS.
- UN
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Bleepingcomputer
Broadcom fixes three VMware zero-days exploited in attacks
blogs_bleepingcomputer·2025-03-04·CVSS 9.8
CVE-2025-22224 [CRITICAL] Broadcom fixes three VMware zero-days exploited in attacks
## Broadcom fixes three VMware zero-days exploited in attacks
## Sergiu Gatlan
"This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'."
Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host.
CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is descri
Bleepingcomputer
Critical RCE bug in VMware vCenter Server now exploited in attacks
blogs_bleepingcomputer·2024-11-18·CVSS 9.8
CVE-2024-38812 [CRITICAL] Critical RCE bug in VMware vCenter Server now exploited in attacks
## Critical RCE bug in VMware vCenter Server now exploited in attacks
## Sergiu Gatlan
Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw.
TZL security researchers reported the RCE vulnerability ( CVE-2024-38812 ) during China's 2024 Matrix Cup hacking contest. It is caused by a heap overflow weakness in the vCenter's DCE/RPC protocol implementation and affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
The other vCenter Server flaw now exploited in the wild (reported by the same researchers) is a privilege escalation flaw tracked as CVE-2024-38813 that enables attackers to escalate privileges to root with a specially crafted network packet.
"U
Bleepingcomputer
VMware fixes bad patch for critical vCenter Server RCE flaw
blogs_bleepingcomputer·2024-10-22·CVSS 9.8
CVE-2024-38812 [CRITICAL] VMware fixes bad patch for critical vCenter Server RCE flaw
## VMware fixes bad patch for critical vCenter Server RCE flaw
## Bill Toulas
VMware has released another security update for CVE-2024-38812, a critical VMware vCenter Server remote code execution vulnerability that was not correctly fixed in the first patch from September 2024.
The flaw is rated critical (CVSS v3.1 score: 9.8) and stems from a heap overflow weakness in vCenter's DCE/RPC protocol implementation, impacting the vCenter Server and any products incorporating it, such as vSphere and Cloud Foundation.
The flaw does not require user interaction for exploitation, as remote code execution is triggered when a specially crafted network packet is received.
The vulnerability was discovered and used by TZL security researchers during China's 2024 Matrix Cup hacking contest. The res
Bleepingcomputer
Broadcom fixes critical RCE bug in VMware vCenter Server
blogs_bleepingcomputer·2024-09-17·CVSS 9.8
CVE-2024-38812 [CRITICAL] Broadcom fixes critical RCE bug in VMware vCenter Server
## Broadcom fixes critical RCE bug in VMware vCenter Server
## Sergiu Gatlan
Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet.
vCenter Server is the central management hub for VMware's vSphere suite, helping administrators manage and monitor virtualized infrastructure.
The vulnerability ( CVE-2024-38812 ), reported by TZL security researchers during China's 2024 Matrix Cup hacking contest, is caused by a heap overflow weakness in vCenter's DCE/RPC protocol implementation. It also affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
Unauthenticated attackers can exploit it remotely in low-complexity attacks that don't require user int
Bleepingcomputer
VMware urges admins to remove deprecated, vulnerable auth plug-in
blogs_bleepingcomputer·2024-02-20·CVSS 9.6
[CRITICAL] VMware urges admins to remove deprecated, vulnerable auth plug-in
## VMware urges admins to remove deprecated, vulnerable auth plug-in
## Sergiu Gatlan
VMware urged admins today to remove a discontinued authentication plugin exposed to authentication relay and session hijack attacks in Windows domain environments via two security vulnerabilities left unpatched.
The vulnerable VMware Enhanced Authentication Plug-in (EAP) enables seamless login to vSphere's management interfaces via integrated Windows Authentication and Windows-based smart card functionality on Windows client systems.
VMware announced EAP's deprecation almost three years ago, in March 2021, with the release of vCenter Server 7.0 Update 2.
Tracked as CVE-2024-22245 (9.6/10 CVSSv3 base score) and CVE-2024-22250 (7.8/10), the two security flaws patched today can be used by malicious atta
Bleepingcomputer
Chinese hackers exploit VMware bug as zero-day for two years
blogs_bleepingcomputer·2024-01-19·CVSS 3.9
CVE-2023-34048 [LOW] Chinese hackers exploit VMware bug as zero-day for two years
## Chinese hackers exploit VMware bug as zero-day for two years
## Sergiu Gatlan
A Chinese hacking group has been exploiting a critical vCenter Server vulnerability (CVE-2023-34048) as a zero-day since at least late 2021.
The flaw was patched in October , with VMware confirming this Wednesday that it's aware of CVE-2023-34048 in-the-wild exploitation, although it didn't share any other details on the attacks.
However, as security firm Mandiant revealed today, the vulnerability was used by the UNC3886 Chinese cyber espionage group as part of a previously reported campaign , exposed in June 2023.
The cyberspies used it to breach their targets' vCenter servers and compromised credentials to deploy VirtualPita and VirtualPie backdoors on ESXi hosts via maliciously crafted vSphere Installa
Bleepingcomputer
VMware confirms critical vCenter flaw now exploited in attacks
blogs_bleepingcomputer·2024-01-19·CVSS 9.8
CVE-2023-34048 [CRITICAL] VMware confirms critical vCenter flaw now exploited in attacks
## VMware confirms critical vCenter flaw now exploited in attacks
## Sergiu Gatlan
VMware has confirmed that a critical vCenter Server remote code execution vulnerability patched in October is now under active exploitation.
vCenter Server is a management platform for VMware vSphere environments that helps administrators manage ESX and ESXi servers and virtual machines (VMs).
"VMware has confirmed that exploitation of CVE-2023-34048 has occurred in the wild," the company said in an update added to the original advisory this week.
The vulnerability was reported by Trend Micro vulnerability researcher Grigory Dorodnov and is caused by an out-of-bounds write weakness in vCenter's DCE/RPC protocol implementation.
Attackers can exploit it remotely in low-complexity attacks with high confid
Bleepingcomputer
VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
blogs_bleepingcomputer·2023-12-01·CVSS 3.9
CVE-2023-34060 [LOW] VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
## VMware fixes critical Cloud Director auth bypass unpatched for 2 weeks
## Sergiu Gatlan
VMware has fixed a critical authentication bypass vulnerability in Cloud Director appliance deployments, a bug that was left unpatched for over two weeks since it was disclosed on November 14th.
Cloud Director is a VMware platform that enables admins to manage data centers spread across multiple locations as Virtual Data Centers (VDC).
The auth bypass security flaw (CVE-2023-34060) only impacts appliances running VCD Appliance 10.5 that were previously upgraded from an older release. However, VMware says it doesn't affect fresh VCD Appliance 10.5 installs, Linux deployments, and other appliances.
Remote attackers can remotely exploit the CVE-2023-34060 bug in low-complexity attacks that don't re
Bleepingcomputer
VMware discloses critical VCD Appliance auth bypass with no patch
blogs_bleepingcomputer·2023-11-14·CVSS 9.8
[CRITICAL] VMware discloses critical VCD Appliance auth bypass with no patch
## VMware discloses critical VCD Appliance auth bypass with no patch
## Sergiu Gatlan
VMware disclosed a critical and unpatched authentication bypass vulnerability affecting Cloud Director appliance deployments.
Cloud Director enables VMware admins to manage their organizations' cloud services as part of Virtual Data Centers (VDC).
The auth bypass security flaw only affects appliances running VCD Appliance 10.5 that were previously upgraded from an older release. The company also added that CVE-2023-34060 does not impact fresh VCD Appliance 10.5 installs, Linux deployments, and other appliances.
Unauthenticated attackers can remotely exploit the bug in low-complexity attacks that don't require user interaction.
"On an upgraded version of VMware Cloud Director Appliance 10.5, a malici
Bleepingcomputer
VMware fixes critical code execution flaw in vCenter Server
blogs_bleepingcomputer·2023-10-25·CVSS 9.8
CVE-2023-34048 [CRITICAL] VMware fixes critical code execution flaw in vCenter Server
## VMware fixes critical code execution flaw in vCenter Server
## Sergiu Gatlan
VMware issued security updates to fix a critical vCenter Server vulnerability that can be exploited to gain remote code execution attacks on vulnerable servers.
vCenter Server is the central management hub for VMware's vSphere suite, and it helps administrators manage and monitor virtualized infrastructure.
The vulnerability ( CVE-2023-34048 ) was reported by Grigory Dorodnov of Trend Micro's Zero Day Initiative and is due to an out-of-bounds write weakness in vCenter's DCE/RPC protocol implementation.
Unauthenticated attackers can exploit it remotely in low-complexity attacks that don't require user interaction. The company says it has no evidence that the CVE-2023-34048 RCE bug is currently used in attac
Crowdstrike
Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Threat Intel
UNC3886 (UNC3886)
threat_intel
UNC3886 (UNC3886)
# Threat Actor Profile: UNC3886
ATT&CK ID: G1048
Also known as: UNC3886
Suspected origin: China
## Overview
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.(Citation: Mandiant Fortinet Zero Day)(Citation: Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023)
## Campaigns
- **RedPenguin** (C0056) [2024-07-01T04:00:00.000Z to 2025-03-01T05:00:00.000Z]
The RedPenguin project was launched by Juniper in July 2024 to inv
https://www.vmware.com/security/advisories/VMSA-2023-0023.htmlhttps://www.vicarius.io/vsociety/posts/understanding-cve-2023-34048-a-zero-day-out-of-bound-write-in-vcenter-serverhttps://www.vmware.com/security/advisories/VMSA-2023-0023.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-34048
2023-10-25
Published
2024-01-22
Added to CISA KEV
Exploited in the wild