APT Actively targeting unpatched VMWare Horizon, exploiting Log4j

Share This Post

An Iranian APT is actively targeting unpatched VMWare Horizon systems to exploit Log4j vulnerabilities. The APT is destructive and these attacks often lead to full Ransomware deployment in the victim’s environment.

See the full Sentinel One synopsis here:

https://www.sentinelone.com/labs/log4j2-in-the-wild-iranian-aligned-threat-actor-tunnelvision-actively-exploiting-vmware-horizon/



Reach out to our incident response team for help

More To Explore

Information Security News – 5/4/2026

Phishing Campaign Abuses Event Invitations to Target U.S. Firms  Article Link: https://cyberpress.org/fake-invites-target-firms/  PyPI Package With 1.1M Monthly Downloads Hacked to Push Infostealer  Article Link: https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/ 

Information Security News – 4/27/2026

Microsoft Releases Emergency Patches for Critical ASP.NET Flaw Article Link: https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-security-updates-for-critical-aspnet-flaw/ Vercel Confirms Security Breach After Customer Accounts Were Compromised Article Link: https://cyberpress.org/vercel-confirms-security-breach-after-customer-accounts-were-compromised/ ‘Zealot’ Shows

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.