🚨🚨 紧急安全通知|URGENT SECURITY ALERT 🚨🚨
⚠️ Proxmox VE 用户请立即处理
近期出现旧版 Proxmox VE 环境遭入侵及勒索软件破坏的报告,可能导致虚拟机文件被加密、备份被删除。
目前尚未确认具体 CVE 或零日漏洞,但风险严重,请勿等待进一步通知!
🔴 请立即执行:
🔒 限制 22 和 8006 端口,仅允许 VPN 或可信 IP 访问
⬆️ PVE 7 或更旧版本:立即安排迁移至 PVE 9
⚠️ PVE 8:立即更新并尽快迁移至 PVE 9
🛡 PVE 9:安装全部更新并重启至最新内核
🔑 禁用 SSH 密码登录,并为管理账户启用 MFA
💾 确保备份独立、离线或不可被 PVE 主机删除,并立即测试恢复
如发现异常登录、未知 SSH 密钥、备份被删除、虚拟机文件被加密或异常对外扫描,请立即隔离管理网络并联系技术支持。
━━━━━━━━━━━━━━
⚠️ Immediate action required for Proxmox VE users
Recent reports indicate that legacy Proxmox VE environments have suffered intrusions and destructive ransomware attacks, potentially encrypting VM files and deleting accessible backups.
No specific CVE or zero-day has been confirmed. However, the risk is severe—do not wait for further notice!
🔴 Take action now:
🔒 Restrict ports 22 and 8006 to VPN or trusted IP addresses only
⬆️ PVE 7 or earlier: migrate urgently to PVE 9
⚠️ PVE 8: fully update now and migrate to PVE 9 as soon as possible
🛡 PVE 9: install all updates and reboot into the latest kernel
🔑 Disable SSH password authentication and enable MFA for administrators
💾 Maintain separate offline or immutable backups and test restoration immediately
If you detect unusual logins, unknown SSH keys, deleted backups, encrypted VM files, or abnormal outbound scanning, isolate the management network and contact technical support immediately.
⚠️ Proxmox VE 用户请立即处理
近期出现旧版 Proxmox VE 环境遭入侵及勒索软件破坏的报告,可能导致虚拟机文件被加密、备份被删除。
目前尚未确认具体 CVE 或零日漏洞,但风险严重,请勿等待进一步通知!
🔴 请立即执行:
🔒 限制 22 和 8006 端口,仅允许 VPN 或可信 IP 访问
⬆️ PVE 7 或更旧版本:立即安排迁移至 PVE 9
⚠️ PVE 8:立即更新并尽快迁移至 PVE 9
🛡 PVE 9:安装全部更新并重启至最新内核
🔑 禁用 SSH 密码登录,并为管理账户启用 MFA
💾 确保备份独立、离线或不可被 PVE 主机删除,并立即测试恢复
如发现异常登录、未知 SSH 密钥、备份被删除、虚拟机文件被加密或异常对外扫描,请立即隔离管理网络并联系技术支持。
━━━━━━━━━━━━━━
⚠️ Immediate action required for Proxmox VE users
Recent reports indicate that legacy Proxmox VE environments have suffered intrusions and destructive ransomware attacks, potentially encrypting VM files and deleting accessible backups.
No specific CVE or zero-day has been confirmed. However, the risk is severe—do not wait for further notice!
🔴 Take action now:
🔒 Restrict ports 22 and 8006 to VPN or trusted IP addresses only
⬆️ PVE 7 or earlier: migrate urgently to PVE 9
⚠️ PVE 8: fully update now and migrate to PVE 9 as soon as possible
🛡 PVE 9: install all updates and reboot into the latest kernel
🔑 Disable SSH password authentication and enable MFA for administrators
💾 Maintain separate offline or immutable backups and test restoration immediately
If you detect unusual logins, unknown SSH keys, deleted backups, encrypted VM files, or abnormal outbound scanning, isolate the management network and contact technical support immediately.