Security News

PoC Exploit Released for Critical VMware Aria's SSH Auth Bypass Vulnerability
2023-09-03 04:42

Proof-of-concept exploit code has been made available for a recently disclosed and patched critical flaw impacting VMware Aria Operations for Networks. "A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI," VMware said earlier this week.

Exploit released for critical VMware SSH auth bypass vulnerability
2023-09-01 20:21

Proof-of-concept exploit code has been released for a critical SSH authentication bypass vulnerability in VMware's Aria Operations for Networks analysis tool.Today, VMware confirmed that CVE-2023-34039 exploit code has been published online, two days after disclosing the critical security bug.

Lazarus hackers deploy fake VMware PyPI packages in VMConnect attacks
2023-08-31 18:47

North Korean state-sponsored hackers have uploaded malicious packages to the PyPI repository, camouflaging one of them as a VMware vSphere connector module named vConnector. The packages were uploaded at the beginning of August, with one named VMConnect targeting IT professionals seeking virtualization tools.

VMware Aria vulnerable to critical SSH authentication bypass flaw
2023-08-30 16:19

VMware Aria Operations for Networks is vulnerable to a critical severity authentication bypass flaw that could allow remote attackers to bypass SSH authentication and access private endpoints. VMware Aria is a suite for managing and monitoring virtualized environments and hybrid clouds, enabling IT automation, log management, analytics generation, network visibility, security and capacity planning, and full-scope operations management.

VMware fixes critical vulnerability in Aria Operations for Networks (CVE-2023-34039)
2023-08-30 10:59

VMware has patched one critical and one high-severity vulnerability in Aria Operations for Networks, its popular enterprise network monitoring tool. It could allow an attacker with network access to Aria Operations for Networks to bypass SSH authentication to gain access to the Aria Operations for Networks command-line interface.

Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks
2023-08-30 06:57

VMware has released software updates to correct two security vulnerabilities in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution."A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI," the company said in an advisory.

VMware Explore 2023: Keynote Highlights
2023-08-22 17:00

Explore enterprise applications and infrastructure, AI, tools for the remote workforce, machine learning, and more from VMware Explore 2023. VMware made several announcements related to new cloud, edge and machine learning services on August 22 at VMware Explore held in Las Vegas.

Monti ransomware targets VMware ESXi servers with new Linux locker
2023-08-14 16:12

The Monti ransomware gang has returned, after a two-month break from publishing victims on their data leak site, using a new Linux locker to target VMware ESXi servers, legal, and government organizations. Researchers at Trend Micro analyzing the new encryption tool from Monti found that it has "Significant deviations from its other Linux-based predecessors."

Dell Compellent hardcoded key exposes VMware vCenter admin creds
2023-08-10 14:38

An unfixed hardcoded encryption key flaw in Dell's Compellent Integration Tools for VMware (CITV) allows attackers to decrypt stored vCenter admin credentials and retrieve the cleartext password. [...]

The Week in Ransomware - August 4th 2023 - Targeting VMware ESXi
2023-08-04 23:12

Ransomware gangs continue to prioritize targeting VMware ESXi servers, with almost every active ransomware gang creating custom Linux encryptors for this purpose. Hospitals run by Prospect Medical Holdings were also impacted this week by a ransomware attack on the parent company.