Security News

Internet Society and IETF agreement ensures the continuity of critical work in creating open standards
2020-12-01 01:00

The Internet Society and the Internet Engineering Task Force announced a new long term strategic agreement that will ensure the continuity of the IETF's critical work in creating open standards that make the Internet work better. The Internet Society provided the organisational home for the IETF until 2018 when the IETF Administration LLC was formed to support its ongoing operations.

Drupal issues emergency fix for critical bug with known exploits
2020-11-27 12:31

Drupal has released emergency security updates to address a critical vulnerability with known exploits that could allow for arbitrary PHP code execution on some CMS versions. "These statistics are incomplete; only Drupal websites using the Update Status module are included in the data," Drupal says.

Critical MobileIron RCE Flaw Under Active Attack
2020-11-25 16:55

Separately, the Cybersecurity and Infrastructure Security Agency in October warned that APT groups are exploiting the MobileIron flaw in combination with the severe Microsoft Windows Netlogon/Zerologon vulnerability. The flaw, first reported to MobileIron by Orange Tsai from DEVCORE, could allow an attacker to execute remote exploits without authentication.

VMware urges sysadmins to apply workarounds after critical Workspace command execution vuln found
2020-11-24 19:04

VMware has published a series of workarounds for critical command injection vulnerabilities in its Workspace One Access, Access Connector, Identity Manager and Identity Manager Connector products. A command injection vuln could allow malicious people who have network access to the "Administrative configurator on port 8443" together with "a valid password for the configurator admin account" to execute commands with "Unrestricted privileges on the underlying operating system," said VMware.

UK urges orgs to patch critical MobileIron CVE-2020-15505 RCE bug
2020-11-24 14:31

The UK National Cyber Security Centre issued an alert yesterday, prompting all organizations to patch the critical CVE-2020-15505 remote code execution vulnerability in MobileIron mobile device management systems. NCSC is warning that they are aware of hacking groups actively using the MobileIron CVE-2020-1550 vulnerability to compromise the networks in the healthcare, local government, logistics, and legal sectors.

VMware Working on Patches for Critical Workspace ONE Access Vulnerability
2020-11-24 12:42

VMware on Monday published an advisory to inform users that it's working on patching a critical command injection vulnerability affecting Workspace ONE Access and some related components. VMware has not specified if technical details of the vulnerability have been disclosed or if it has been exploited in attacks.

VMware releases workarounds for another critical flaw (CVE-2020-4006)
2020-11-24 10:13

For the second time in less than a week, VMware is warning about a critical vulnerability. As some of these are components of the VMware Cloud Foundation and vRealize Suite Lifecycle Manager product suites, those are impacted as well.

Critical Unpatched VMware Flaw Affects Multiple Corporates Products
2020-11-23 23:08

VMware has released temporary workarounds to address a critical vulnerability in its products that could be exploited by an attacker to take control of an affected system. Tracked as CVE-2020-4006, the command injection vulnerability has a CVSS score of 9.1 out of 10 and impacts VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector.

Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending
2020-11-23 21:46

The U.S. Cybersecurity and Infrastructure Security Agency is warning of a zero-day bug affecting six VMware products including its Workspace One, Identity Manager and vRealize Suite Lifecycle Manager. The critical unpatched bug is a command injection vulnerability.

VMware discloses critical zero-day vulnerability in Workspace One
2020-11-23 14:53

VMware has released a workaround to address a critical zero-day in multiple VMware Workspace One components that allows attackers to execute commands on the host Linux and Windows operating systems using escalated privileges. The vulnerability tracked as CVE-2020-4006 is a command injection bug - with a 9.1/10 CVSSv3 severity rating - found in the administrative configurator of some releases of VMware Workspace ONE Access, Access Connector, Identity Manager, and Identity Manager Connector.