Virtualizor does have issues currently but this was not related to that as my system was not attached to it. Our PVE 8.1 install didnt get hit by this only 7.3-11.
Wish I had more logs to share but had to wipe the machine quickly and get it...
Hi,
the "true" news to stop speculating : https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
And the post never mention proxmox as "hacked or compromised"…
Best regards,
Earlier, when the OP posted, the only mention was "Can confirm we're not using Proxmox", "i'm more aware of the proxmox one, anyone's having any information?", "it's also a weak product so not an extremely big revenue like vmWare, Hyper-V or even...
Hi,
how can you be sure that there is a "unauthenticated RCE" touching PVE7/8 systems ?
All the systems mentionned was affected by :
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-860952...
I was hit with this same attack the night of the 28th luckily had backups i setup less than 24 hrs prior to happening. Seems they went around just scanning for vulnerable hosts exposed to the public. I had 2 hosts exposed to the public one 7.3-6...
Hi,
how can you be sure that there is a "unauthenticated RCE" touching PVE7/8 systems ?
All the systems mentionned was affected by :
https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-860952...
I was hit with this same attack the night of the 28th luckily had backups i setup less than 24 hrs prior to happening. Seems they went around just scanning for vulnerable hosts exposed to the public. I had 2 hosts exposed to the public one 7.3-6...
Hi,
What are you talking about ? Neither hetzner was breached and/or proxmox host in hetzner network was affected by the BGP Hijack.
The big problem that "virtualizor" has is that "[...]product update clients did not yet cryptographically...
1) Some people have their proxmox hosts connected to virtualizor
2) virtualizor was hacked with a feasible method of deploying ransomware https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
3) The point of this thread is to find out...
1) Some people have their proxmox hosts connected to virtualizor
2) virtualizor was hacked with a feasible method of deploying ransomware https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
3) The point of this thread is to find out...
Ich sehe ( und das als bekennender KI-Luddit!) auch nicht so das Problem. Im Grunde sagt Debian, dass „aber die ki sagt, das passt so“ keine erlaubte Ausrede ist Bullshit abzuliefern ;)
OpenBSD hatte ja das Vergnügen mit einen Vibecoder, der...
This is highly unlikely. Any Software has bugs and in System stuff like the Kernel every bug is an security issue. Since right now every week ai-assisted Security research discover previously unknown bugs it‘s just not realistic to assume that a...
Hi,
What are you talking about ? Neither hetzner was breached and/or proxmox host in hetzner network was affected by the BGP Hijack.
The big problem that "virtualizor" has is that "[...]product update clients did not yet cryptographically...
Da brauchst nicht all zu weit zu gehen, hier ein schönes Beispiel für..
https://forum.proxmox.com/threads/wasserdichtes-system-f%C3%BCr-kleine-multi-teant-anwendung.185556/
Ehrlich gesagt ändert das bei Debian doch wenig, mit dem DCO lag die Verantwortung schon immer beim Einreicher. Ungeprüft zusammenkopierten Kram gab's auch vorher schon, halt von Stack Overflow statt vom LLM. Was real schützt ist der Review- und...
So because one vendor sucks every other sucks too? Interessting „Logic“ which confirms my strong belief that most developers and admins ( myself included ) shouldn‘t get ssh Not Root Access on Servers. In that regard immutable, Auto-updated...
Yes - even though this isnt proxmox itself im sure it would be helpful to find the method of the breach, for instance, im sure if hetzner were breached and proxmox hosts cryptolocked, many people who run proxmox on hetzner would come here as well
Did you read the mentioned thread on lowendtalk? What is there to actually panic about? In what way did they mention Proxmox? Did they simply say "Can confirm not running Proxmox"? Please don't exacerbate LLM mistakes posted by others.
This is highly unlikely. Any Software has bugs and in System stuff like the Kernel every bug is an security issue. Since right now every week ai-assisted Security research discover previously unknown bugs it‘s just not realistic to assume that a...