// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

VMware

DISCLOSED 2024-05-22 · UNPATCHED CVE

A state-sponsored threat actor compromised MITRE's NERVE network via Ivanti zero-days, then abused VMware VPXUSER privileged account to create rogue VMs directly on ESXi hypervisors, evading vCenter detection. The actor deployed BRICKSTORM backdoor and BEEFLUSH web shell for persistence and C2. This technique bypasses centralized management visibility, allowing stealthy operations.

The record

What we know

Disclosed
2024-05-22
Attack vector
Unpatched Cve
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the VMware disclosure. It updates if new public reporting emerges. All tracked breaches →

VMware just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →