Skip to main content
Cybersecurity

The Current

The Current #12 — Ransomware Went for the Layer Under Your Servers

Ransomware is now hitting the hypervisor underneath your servers, and the backups usually go with it — plus passkey-themed help-desk phishing and the EU Cyber Resilience Act's 24-hour reporting clock.

Charles Redding, Founder, DLegendDigital7 min read

Three items this time, and they share a shape: each one lives underneath the thing you actually monitor. The layer your servers run on. The phone call that happens before the login screen. The product vulnerability your supplier now has to tell you about. This cycle's blog post is about the first one.

Ransomware Is Going for the Floor Your Servers Stand On#

On July 29, Broadcom published a security advisory for VMware vCenter — the console that manages a company's virtual servers — with two bugs scoring 9.8 out of 10 and no workaround. By August 3 the first victim was talking to attacker infrastructure. By August 5, an incident-response firm had counted 343 compromised addresses on the way to 361, across 47 countries. The chain did not stop at the console: it went down into the ESXi hosts — the layer every virtual server actually runs on — created administrator accounts there, stopped the machines, and encrypted the storage underneath them.

The same week, a hosting provider called HostDZire confirmed several of its ESXi nodes in three countries were encrypted beyond recovery. It had no working backups of its own. Customers who kept a copy somewhere else rebuilt. Customers who did not lost everything.

That second story is the whole point. A snapshot is a photograph of the room, kept in the room. A backup server running as a virtual machine on the cluster it protects is a fire extinguisher stored in the building that is on fire. When the attacker owns the floor, both go with it.

What it changes for you: a backup only counts if it lives where the hypervisor cannot reach, under credentials the hypervisor and the domain do not control, and locked so that even an administrator cannot alter it for a set number of days. The blog post has the seven-item Monday list, including one restore test that assumes the hypervisor is gone.

The Fake Help Desk Now Calls Your Personal Phone About Your Passkey#

In July I wrote that the login screen had become the single most critical thing you run. Here is the update. On September 9 Microsoft published its analysis of a campaign, active since May, in which attackers phone or text employees on their personal numbers, claim to be the company's IT help desk, and warn that access will be cut off unless the employee "updates their passkey" right now. The link goes to a counterfeit Microsoft sign-in page. From there the attacker either captures the session or walks the victim through a device-code approval that hands over the account without a password ever being typed.

What happens next is the part to sit with: the first thing the attacker does is register their own second factor — a new phone number or authenticator app — so they can sign in later without the victim's help. Then comes hours or days of quiet downloading from SharePoint, OneDrive, and mailboxes through ordinary-looking API calls. Microsoft's own phrasing is that the activity "rarely appears suspicious when viewed through a single API call."

What it changes for you: the passkey is not the weakness — the enrollment step is, and it runs through people. Two decisions, both free: tell everyone in writing that IT will never call a personal phone to change a login method, and turn on an alert for any new authentication method being added to an account. The second one is the tripwire this campaign does not expect.

The EU's 24-Hour Product Reporting Clock Started on September 11#

The Cyber Resilience Act is the EU law that makes manufacturers responsible for the security of "products with digital elements" — hardware and software that connects to anything. Most of it lands in December 2027. But the reporting piece went live on September 11, 2026, and it applies to products already on the EU market, not just new ones.

If you make such a product and learn of a vulnerability being actively exploited, or of a severe incident in it, you now owe an early warning within 24 hours, a fuller notification within 72, and a final report within 14 days of a fix (one month for incidents) — all through ENISA's new Single Reporting Platform, which opened the same day. The fine ceiling is 15 million euros or 2.5% of worldwide turnover. There is no EU-establishment exemption; a US software company with EU customers is in scope.

If you buy such products, the law just changed your vendors' behavior: they now have a legal reason to tell you about exploited bugs quickly, and a legal exposure if they sit on them.

What it changes for you: if you sell software or connected hardware into Europe, you need one named person and one written path from "we learned of exploitation" to "the 24-hour warning is filed." If you only buy, add a line to your next vendor review asking how they will notify you under the CRA.

One Level Deeper: Tier Zero Is a List You Write, Not a Product You Buy#

The blog post ends by predicting the hypervisor will be treated as a "tier-zero" system — the small set of things that, if lost, take everything else with them. Most companies have the list wrong.

Ask people what their tier-zero systems are and you get the identity provider and maybe the domain controllers. This month's items add two more that almost nobody lists: the hypervisor management console, and the help-desk process for changing a login method. The second is not software at all. It is a phone call and a checklist, and it is on the list because an attacker who can talk their way through it owns the account as surely as one who steals the password.

Here is the exercise. Write down every system or process that can silently change who can access what or whether anything can be restored. That is your real tier zero. Then check each entry against three rules: its own credentials (not the domain's), its own patch clock (days, not the monthly cycle), and its own recovery path that does not depend on anything else on the list. Most companies will find one entry that fails all three. That entry is the one August was about.

How This Impacts Your Organization#

The principle doesn't change with company size: the things underneath what you monitor — the virtualization layer, the enrollment call, the supplier's disclosure duty — are where this month's risk moved. What changes is which of those you own, how much slack you have when one gives way, and where your leverage sits.

Large Enterprises (1,000+ employees)

Your risk is organizational: virtualization, identity, backup, help desk, and product security are five teams, and every item this month crosses at least two of them. Your leverage is that you can name owners and write the rules down. This quarter, produce the tier-zero list above as a single document with one owner per entry, get a single-digit-day patch commitment for the management plane written into the platform team's service levels, and, if you sell into the EU, appoint the CRA reporting owner now — the 24-hour clock does not wait for an org chart.

Mid-Size Organizations (100–999 employees)

You feel this fastest because one or two people own all of it, and the same administrator account usually reaches all of it. The overcorrection to avoid: buying a second hypervisor, a second identity platform, or a compliance program in response. Three moves, no platform team: move the backup server off the production cluster and give it its own local login with its own multi-factor method; tell staff in writing that IT never calls personal phones about passkeys, and alert on new authentication methods; if you make software sold in Europe, write the one-page CRA reporting path this month.

Small & Growing Organizations (under 100 employees)

Honest counsel: if your servers are in the cloud, the hypervisor item is your provider's problem — but the provider's backup is still not your backup, so keep one copy of what matters somewhere the provider cannot touch. The help-desk item reaches you in full, because a five-person company with no IT department is exactly who believes a caller claiming to be IT; one sentence to the whole team fixes most of it. The CRA reaches you only if you sell connected products into the EU; if you do, it reaches you at full strength. Nothing here requires a purchase.

  1. Ransomware Is Going for the Floor Your Servers Stand On (companion blog post) — dlegenddigital.com/blog
  2. Broadcom VMSA-2026-0006 — support.broadcom.com
  3. Rapid7: critical vCenter vulnerabilities CVE-2026-59309 / CVE-2026-59310 — rapid7.com
  4. CISA adds four Known Exploited Vulnerabilities (Aug 18) — cisa.gov
  5. VMware syslog path traversal to ESXi ransomware (QUIRSO report) — cybersecuritynews.com
  6. HostDZire ransomware attack causes complete data loss — securityonline.info
  7. Microsoft: passkey-themed social engineering leads to identity and cloud compromise — microsoft.com/security/blog
  8. Attackers use passkey phishing to hijack Microsoft cloud accounts — thehackernews.com
  9. EU Cyber Resilience Act reporting obligations from 11 September 2026 — goodwinlaw.com
  10. ENISA Single Reporting Platform FAQ — enisa.europa.eu

Three items, one habit: the things that hurt this month were not the systems people watch. They were the layer underneath, the call before the login, and the disclosure duty upstream. Write the list. Check the three rules. Fix the one that fails.

On the blog this cycle: Ransomware Is Going for the Floor Your Servers Stand On — and Your Backups Are Standing There Too — what happened in August, why endpoint protection saw nothing, and what a backup has to be to survive it.

Hit reply and tell me what you're wrestling with — I read every one.

— Charles Redding, Founder, DLegendDigital

Paired long-form

Ransomware Is Going for the Floor Your Servers Stand On — and Your Backups Are Standing There Too

In August 2026 a VMware vCenter bug went from advisory to mass exploitation in five days, and the end of the chain was ransomware on the layer every server runs on. One hosting provider lost every customer's data because its backups lived there too. Here's what a backup has to be to survive that.

Read the full article

The Current

Get the next one before anyone else.

Twice a month. ~5 min read. No spam, no upsells buried in footnotes.

Free. Unsubscribe any time.

More issues

Full archive →