Two ransomware strains target VMware’s ESXI hypervisor through stolen vCenter creds

Who allow their bare-metal hypervisor to connect directly to the internet without a firewall in between?

Also - who portforwards port 22 (or any VCenter port) directly to the Internet?

Mind boggles.

Put a firewall and VPN in between!

