MITRE shared new lessons from its own cyberattack in a blog post Wednesday, describing how China state-sponsored threat actor UNC5221 used rogue virtual machines (VMs) to evade detection and establish persistence in its VMware environment. MITRE’s Networked Experimentation, Research, and Virtualization Environment (NERVE) was compromised in January with the threat actors leveraging two Ivanti Connect Secure zero-days for initial access.
Source: SC Magazine