Nutanix Move 6.3, shipped July 29, 2026, moves VMs from ESXi to AHV by repointing array metadata instead of copying vDisk data. Teams that drop the copy step also lose the validation checkpoint it used to force, and they still carry identity and dependency risk.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives25
- Confidence40
Gambit Security says the ransomware crew used a commercial coding agent for hands-on post-compromise work between 8 April and 21 May, alongside a new Linux encryptor that force-kills running guests before it touches ESXi datastores.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence78
- Adoption60
- Hype gap+22
- Incentives58
- Confidence70
CVE-2026-59310 gave a suspected APT crew persistence on vCenter systems in August. CISA has now flagged the same directory traversal as abused by ransomware operators. Broadcom patched it on July 29.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence65
Kaspersky's responders found no encrypted files and no malware on disk across the Windows estate of a Middle East manufacturer in April 2026. The impact arrived through one Group Policy Object linked at the domain root.
Reality
- Evidence62
- Adoption35
- Hype gap+12
- Incentives72
- Confidence58
GBHackers reports Aurora operators handing vulnerability analysis and payload delivery to Cursor agents against ESXi hypervisors, and Anthropic's September 2026 assessment describes the same delegation running for months inside state-linked campaigns.
Reality
- Evidence24
- Adoption42
- Hype gap+38
- Incentives55
- Confidence30
The RaaS operation appeared on August 5 with build management for four operating systems, Tox-gated affiliate vetting and two Italian victims, and the encryptor those affiliates are uploading still awaits public analysis.
Publishers:andreafortuna.org
Reality
- Evidence30
- Adoption32
- Hype gap+18
- Incentives68
- Confidence40
Guest memory statistics reach a Proxmox host over the virtio balloon device, so a VM set to balloon: 0 shows its whole allocation as consumed while Task Manager inside reports 30 to 50 percent. Enabling it need not cost you a fixed allocation.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives38
- Confidence55
Nine agencies across four countries refreshed the #StopRansomware Akira advisory on Nov. 13 with indicators current to November 2025 and a three-item action list.
Reality
- Evidence79
- Adoption66
- Hype gap+4
- Incentives24
- Confidence71
Check Point Research says a nonce bug in every public VECT build leaves files above 131,072 bytes unrecoverable, by the attacker as well. That turns extortion into destruction.
Publishers:research.checkpoint.com
Reality
- Evidence74
- Adoption22
- Hype gap+12
- Incentives62
- Confidence58
Coveware says four bytes of the per-file public key get overwritten on the stack, so no private key exists for anything Nitrogen encrypted on ESXi. Not even the attacker can undo it.
Publishers:coveware.com
Reality
- Evidence66
- Adoption24
- Hype gap+14
- Incentives58
- Confidence55