Attackers are scanning VMware vCenter after critical vulnerabilities were disclosed, with DefusedCyber’s honeypots recording increased vCenter fingerprinting activity. The activity includes requests to the /sdk/ endpoint using RetrieveServiceContent and exploration of the /websso single sign-on path. The requests do not prove compromise but show that attackers are identifying exposed systems before launching more direct attacks. […]
Read the original article: