Skip to content
P
非影
top
latest
vulnerabilities
research
tools
Topics
sources
search
search
🌓
中文
Curated security research, vulnerabilities, advisories and tools for practitioners.
Virtualization Security Resources
netspi.com
| blog |
#cloud
|
#virtualization
|
#vmware
|
#hyper-v
|
#resources
|
#hardening
|
#xen
Summary
A starter collection of virtualization security resources: hardening guides for Hyper-V, VMware vSphere, and Xen, plus references from DISA STIG, CSA, SANS, and CIS.
Published
2012-07-02 00:00
Collected
2026-09-20 06:10
original ↗
← Previous
5 Ways to Find Systems Running Domain Admin Processes
Next →
Passwords: Strength and Longevity vs. Uniqueness
Related coverage
blog
·
netspi.com
Pentesting the Cloud
After a dull conference, the author concludes cloud pentesting is fundamentally the same as traditional testing: virtualized or shared, the underlying technology and security controls hardly change.
blog
·
projectzero.google
Release of a Technical Report into Intel Trust Domain Extensions
Announcing a technical report on Intel Trust Domain Extensions, analyzing the confidential computing architecture's security model, implementation, and potential weaknesses.
blog
·
kali.org
Weekly Virtual Machines, with Build Scripts
Kali now builds its VMware and VirtualBox images automatically each week using published Kali-VM build scripts, offering fresher packages than release images plus generic multi-hypervisor builds.
blog
·
kali.org
VMware Fusion Kali USB Boot
How to boot a Kali live USB inside VMware Fusion on macOS: create a Debian 64-bit VM, attach the USB drive, and work around Fusion's hidden EFI boot options, with USB and EFI troubleshooting.
blog
·
projectzero.google
Pandavirtualization: Exploiting the Xen hypervisor
A Project Zero report on a Xen hypervisor escape: an attacker controlling a paravirtualized x86-64 guest kernel could break out and control physical memory, patched in April 2017.
vulnerability
·
theori.io
Compromising virtualization without attacking the hypervisor
CVE-2020-27675 (XSA-331): a DoS and potential out-of-bounds write in Linux's Xen paravirtualization driver — how virtualization platforms can be compromised without attacking the hypervisor directly.
back