• News/
  • https://www.theregister.com/2025/11/14/cisa_akira_ransomware/

CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV

The Register
·
Connor Jones
·
Published Nov 14, 2025
·
Updated

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance to organizations on the Akira ransomware operation, which poses an imminent threat to critical sectors. In an updated advisory produced with the FBI and European law enforcement partners, it said Akira has expanded its capabilities and is now targeting Nutanix AHV virtual machines, an evolution from its previous attacks against VMware ESXi and Hyper-V. The agencies spotted attacks against Nutanix hypervisors in June, but did not specify the affected organizations, and added that the data informing the advisory is as recent as November 2025. Critical national infrastructure (CNI) organizations were urged to be on high alert for a new breed of attacks coming from the Russian ransomware outfit as it looks to further its criminal revenues, currently pegged at $244.17 million. Nutanix's hypervisors are among the market leaders and are typically used in sectors such as healthcare, finance, and government. While Akira is typically known for targeting small and medium businesses, its members have also laid claim to attacks on larger organizations. The advisory stated that the group has previously displayed "a notable preference for organizations in the manufacturing, educational institutions, information technology, healthcare and public health, financial services, and food and agriculture sectors." Akira affiliates are gaining initial access to targets' networks via bugs in VPN products, but the a...

Read full article

Affected Software

1 affected component
Nutanix Ahv
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the imminent threat posed by the Akira ransomware, particularly its impact on Nutanix AHV systems.

2

What security implications are discussed?

The article highlights the potential for devastating attacks on critical sectors due to the Akira ransomware operation.

3

What products or software are affected?

Nutanix AHV is specifically mentioned as a product vulnerable to the Akira ransomware.

4

What guidance has CISA issued regarding Akira ransomware?

CISA has provided updated guidance urging organizations to enhance their cybersecurity measures to protect against Akira ransomware attacks.

5

Who is advising organizations about the Akira ransomware threat?

The advisory is issued by the US Cybersecurity and Infrastructure Security Agency (CISA).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203