You're just too late for Proxmox to spend time and money on this. PVE 8.4.21 is just about EoL and out of support (and it did get several updates beyond 8.4.0). PVE 9 did get a lot of CVE fixes via the Linux kernel and Debian recently that might...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
Hi,
the "true" news to stop speculating : https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
And the post never mention proxmox as "hacked or compromised"…
Best regards,
Hi,
hum 8.4 was out on the 9 april 2025, so it's affected by all the PSA (which affect PVE8) after this post : https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/#post-764654
Which on recent PSA allows an...
Were compromised hosts here using Virtualizor API/SSH connection?
https://forum.proxmox.com/threads/forum-thread-with-a-message-saying-%E2%80%9Cproxmox-is-compromised%E2%80%9D.186086/
Could be a coincidence, or related to the fact that we have a sh**tload of occurrences in Brasil because of outdated version and bad sysadmins on small providers, that rely exclusively on next next finish installations and the mindset of using...
You're just too late for Proxmox to spend time and money on this. PVE 8.4.21 is just about EoL and out of support (and it did get several updates beyond 8.4.0). PVE 9 did get a lot of CVE fixes via the Linux kernel and Debian recently that might...
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
You're absolutely right, and I accept the failure on my side.
Just to clarify, this is informational, not a complaint. I'm sharing it so you're aware that this actually happened in our environment and can take it into account.
Hello PMG Admins,
I've been running PMG for a while, and the one thing that always bugged me was managing the spam quarantine from my phone. The admin interface works fine, but it's not built for a small screen - and there are days I need to...
Could be a coincidence, or related to the fact that we have a sh**tload of occurrences in Brasil because of outdated version and bad sysadmins on small providers, that rely exclusively on next next finish installations and the mindset of using...
Could be a coincidence, or related to the fact that we have a sh**tload of occurrences in Brasil because of outdated version and bad sysadmins on small providers, that rely exclusively on next next finish installations and the mindset of using...
Unfortunately, the report I received was out of my hand. Isn't from any of my customers/colleagues, don't have access to the environment, and also don't know how they got in. Just telling that I saw a 8.4.0 getting owned.
I disagree. I think it's more toxic to have EOL systems (like PVE7) on the Internet. It makes the world for all a worse place. I also think it's toxic to register accounts to cry about about an "Proxmox security issue" which quite obviouvsly...
Having read that post (& translating the Chinese!) & all comments, I believe it is a scam. Read it carefully.
I don't think so. I've already stated above:
Systems without current system updates can be hacked, nothing is "new" or "urgent" on this. And PVE7 and PVE8 won't get any security updates any more so it's somehow expected that they get owned. Even if you don't connect them directly to the...
The PBS is added as trusted storage on the PVE cluster.
When i run the command with :8007 i says "error" cant find path.
When I remove the :8007, it asks for the password, as if the PBS user was not added on the PVE cluster.
I then enter the...
I still think a more productive way to look at this would be to see if there's any possible/remaining logs, to see what could've exactly caused this, and then list exact affected versions?
So far reading between the posts here and the other...