Security News

VMware fixes authentication bypass in data center security software
2021-04-01 16:58

VMware has addressed a critical vulnerability in the VMware Carbon Black Cloud Workload appliance that could allow attackers to bypass authentication after exploiting vulnerable servers. VMware Carbon Black Cloud Workload is a Linux data center security software designed to protect workloads running in virtualized environments.

VMware vROps Flaws Can Provide 'Unlimited Opportunities' in Attacks on Companies
2021-04-01 11:45

A couple of serious vulnerabilities patched recently by VMware in its vRealize Operations product can pose a significant risk to organizations, according to a researcher involved in the discovery of the security bugs. The vROps IT operations management product, specifically the vRealize Operations Manager API, is affected by a server-side request forgery vulnerability tracked as CVE-2021-21975, and an arbitrary file write issue tracked as CVE-2021-21983.

VMware patches critical vRealize Operations flaws that could lead to RCE
2021-04-01 10:16

Two vulnerabilities recently patched by VMware in its vRealize Operations platform can be chained together to achieve unauthenticated remote code execution on the underlying operating system, Positive Technologies researchers have found. There is no PoC currently available and no mention of the vulnerabilities being exploited in the wild.

VMware Cloud enables orgs to accelerate app modernization across the data center, edge and cloud
2021-04-01 02:15

VMware Cloud is a distributed, multi-cloud platform that enables organizations to accelerate application modernization across the data center, edge, and any cloud. VMware Cloud Universal is ideal for customers committed to a hybrid cloud architecture; that have extended or variable cloud migration timelines; that have cloud bursting requirements; or desire an OPEX model for on-premises infrastructure.

VMware fixes bug allowing attackers to steal admin credentials
2021-03-30 18:01

VMware has published security updates to address a high severity vulnerability in vRealize Operations that could allow attackers to steal admin credentials after exploiting vulnerable servers. vRealize Operations is an AI-powered and "Self-driving" IT operations management for private, hybrid, and multi-cloud environments, available as an on-premises or SaaS solution.

VMware makes the complexity of managing clouds invisible
2021-03-17 02:00

VMware announced innovations across its cloud management portfolio spanning CloudHealth by VMware and VMware vRealize Cloud Management on-premises and software as a service offerings. "VMware makes this complexity of managing clouds invisible. By providing consistent costing, security, governance, operations and service automation across clouds, VMware enables customers to achieve higher application and business agility."

VMware unveils portfolio updates to help customers modernize apps and infrastructure
2021-03-10 01:15

VMware announced portfolio updates to help customers modernize their applications and infrastructure. The new releases of vSphere 7 and vSAN 7 will help IT teams support new and existing applications with infrastructure that is developer and AI-ready; scales without compromise; boosts infrastructure and data security; and simplifies operations.

VMware releases fix for severe View Planner RCE vulnerability
2021-03-04 17:09

VMware has addressed a high severity unauthenticated RCE vulnerability in VMware View Planner, allowing attackers to abuse servers running unpatched software for remote code execution. The vulnerability was discovered and reported to VMware by Positive Technologies web application security expert Mikhail Klyuchnikov.

Armor Anywhere and VMware Carbon Black extend protection to detect and stop advanced threats
2021-03-04 01:45

Armor announced new endpoint detection and response capabilities delivered with VMware Carbon Black. Armor Anywhere, a trusted cloud security platform, will utilize VMware Carbon Black Cloud Enterprise EDR to extend threat detection and response to end user devices.

VMware Patches Remote Code Execution Vulnerability in View Planner
2021-03-03 15:23

VMware this week announced the availability of a security patch for VMware View Planner, to address a vulnerability leading to remote code execution. With the release of View Planner 4.6 Security Patch 1 on March 2, VMware fixes CVE-2021-21978, an issue that could allow an attacker to execute code remotely.