Hello,
it come a security message that Virtualizor Compromised with a bgp attack . The post also mentions Proxmox, also that it was hacked or compromised. If this is false, Proxmox should take immediate action to prevent the spread of fake news...
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...
I have a compromised Proxmox 7 system, and they left me with those files shown in the screenshots and the same message that appears on the Chinese website... it's clearly a scam... although they encrypted the LVM unit located at /var/lib/vz
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.
I don't think so. I've already stated above:
Which version of Proxmox VE are you on? I suspect not a recent one, as the pause and hibernate buttons have been added to the right click menu some time ago.
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.
I don't think so. I've already stated above:
The usual use of the zero-day term is for vulnerabilities that are being exploited while there is no fix yet (for a supported/current version). That is something the administrator cannot do much about. This vulnerability is probably already fixed...
Not sure what you mean by "Everything". So far you only reported your own single host being attacked.
Are you (by chance) connected to arjitc, the other reporter of this attack. (Interestingly both these users only joined today, for the purpose...
Only to you, unless you are claiming that it affects an up-to-date version of PVE.
PVE 7 is based on Debian 11, PVE 8 on Debian 12. So they would be affected by that bug unless they were updated since the bug was fixed.
In any case, I don't think this is a 0day vulnerability, because on this is happen due to out date servers and bad servers administration, to say the least.
Many of this vulnerabilities are well-know documented, such as kernel and ssh...