VMware plays down risk of source code leak
Virtualisation giant confirms authenticity of leaked ESX source code.

Virtualisation giant VMware has confirmed that part of the source code for its ESX hypervisor has been leaked online, but insists it poses little risk to its customers.
The leak consists of a single file from the VMware ESX source code and is understood to have been posted on text sharing website Pastebin by known hacktivist Hardcore Charlie on 8 April.
In a post on the software vendor's website, Iain Mulholland, director of VMware's security response centre, said the code could date back to 2003 or 2004.
He also revealed that the firm became aware of the leak several days ago and acknowledged that more code could be leaked in future.
"The fact the source code may have been publicly shared does not necessarily mean that there is any increased risk to VMware customers," said Mulholland.
"We take customer security seriously and have engaged internal and external resources, including our VMware security response centre to thoroughly investigate," he added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
RSAC Conference 2025: The front line of cyber innovation
ITPro Podcast Ransomware, quantum computing, and an unsurprising focus on AI were highlights of this year's event
-
Anthropic CEO Dario Amodei thinks we're burying our heads in the sand on AI job losses
News With AI set to hit entry-level jobs especially, some industry execs say clear warning signs are being ignored
-
Broadcom issues urgent alert over three VMware zero-days
News The firm says it has information to suggest all three are being exploited in the wild
-
Threat actors are exploiting a VMware ESXi bug which could be “catastrophic” for affected firms
News The VMware ESXi hypervisor has become a favorite target in the digital extortion community, according to researchers
-
Everything you need to know about the VMware vCenter Server vulnerability
News A critical flaw in the VMware vCenter Server management software has been exploited in the wild by a Chinese hacking group since late 2021
-
VMware Aria: CISA warns customers to immediately patch products
News The disclosure marks the third critical vulnerability in as many months for VMware
-
VMware’s ESXi security issues spur new ransomware gang into action
News The popularity of ESXi combined with a lack of security tools makes it an “attractive target” for threat actors
-
Warning issued over ransomware attacks targeting VMware ESXi servers globally
News Businesses have been urged to patch the two-year-old vulnerability amidst heightened ransomware threats
-
Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers
News Cheerscrypt malware could cause severe disruption to companies using the virtualisation software
-
US security agency issues emergency alert over vulnerable VMware products
News A string of actively exploited critical vulnerabilities across five popular VMware products has been described as an "unacceptable risk" to government systems