Two days ago, my Proxmox VE 7 installation, which was over four years old with the latest updates available up to EOL and only one user (root), was encrypted, and a ransom was demanded for decryption. I searched online for the ransom note and found someone complaining in Chinese about the same thing 1 day ago, which seems to be a wave of some kind of zero-day or RCE without authentication. All the logs were deleted by the attackers. There was an IP address sending requests to a specific endpoint in the last logs after they were deleted, but I'm not sure if it's the attacker's server. I can provide more details to the administrators if needed, but it seems there's some kind of exploit in the wild affecting all Proxmox VE 7 installations exposed to the internet, regardless of their configuration.





