Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • ETH Back Below $2,000, BTC Down 6% to Start the Weekend – Market Updates Bitcoin News bitcoin news
  • Bitcoin Price Could Rally Again If It Stays Above This Key Support bitcoin news
  • GRT, LINK Rally to Multi-Week Highs on Friday – Market Updates Bitcoin News bitcoin news
  • Polygon (MATIC) Price Falls Short Of Reaching Full Potential Despite Recent Developments bitcoin news
  • Argentinian Exchange Ripio Presents Crypto Educational Textbook and Web3 Metaverse Wallet – Bitcoin News bitcoin news
  • Tim Draper Bullish on Bitcoin Due to Its Inflation Hedge Traits – Bitcoin News bitcoin news
  • Hello XD Ransomware Installing Backdoor on Targeted Windows and Linux Systems cyber security news
  • Bitcoin Price Remains In Range, Why The Bulls Need To Take Control bitcoin news

VMware Releases Patches for New Vulnerabilities Affecting Multiple Products

Posted on May 19, 2022 By root


VMware Vulnerabilities

VMware has issued patches to contain two security flaws impacting Workspace ONE Access, Identity Manager, and vRealize Automation that could be exploited to backdoor enterprise networks.

The first of the two flaws, tracked as CVE-2022-22972 (CVSS score: 9.8), concerns an authentication bypass that could enable an actor with network access to the UI to gain administrative access without prior authentication.

CVE-2022-22973 (CVSS score: 7.8), the other bug, is a case of local privilege escalation that could enable an attacker with local access to elevate privileges to the “root” user on vulnerable virtual appliances.

“It is extremely important that you quickly take steps to patch or mitigate these issues in on-premises deployments,” VMware said.

The disclosure follows a warning from the U.S. Cybersecurity and Infrastructure Agency (CISA) that advanced persistent threat (APT) groups are exploiting CVE-2022-22954 and CVE-2022-22960 — two other VMware flaws that were fixed early last month — separately and in combination.

“An unauthenticated actor with network access to the web interface leveraged CVE-2022-22954 to execute an arbitrary shell command as a VMware user,” it said. “The actor then exploited CVE-2022-22960 to escalate the user’s privileges to root. With root access, the actor could wipe logs, escalate permissions, and move laterally to other systems.”

On top of that, the cybersecurity authority noted that threat actors have deployed post-exploitation tools such as the Dingo J-spy web shell in at least three different organizations.

IT security company Barracuda Networks, in an independent report, said it has observed consistent probing attempts in the wild for CVE-2022-22954 and CVE-2022-22960 soon after the shortcomings became public knowledge on April 6.

More than three-fourths of the attacker IPs, about 76%, are said to have originated from the U.S., followed by the U.K. (6%), Russia (6%), Australia (5%), India (2%), Denmark (1%), and France (1%).

Some of the exploitation attempts recorded by the company involve botnet operators, with the threat actors leveraging the flaws to deploy variants of the Mirai distributed denial-of-service (DDoS) malware.

The issues have also prompted CISA to issue an emergency directive urging federal civilian executive branch (FCEB) agencies to apply the updates by 5 p.m. EDT on May 23 or disconnect the devices from their networks.

CyberSecurity

“CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products,” the agency said.

The patches arrive a little over a month after the company rolled out an update to resolve a critical security flaw in its Cloud Director product (CVE-2022-22966) that could be weaponized to launch remote code execution attacks.

CISA warns of active exploitation of F5 BIG-IP CVE-2022-1388

It’s not just VMware that’s under fire. The agency has also released a follow-up advisory with regards to the active exploitation of CVE-2022-1388 (CVSS score: 9.8), a recently disclosed remote code execution flaw affecting BIG-IP devices.

CISA said it expects to “see widespread exploitation of unpatched F5 BIG-IP devices (mostly with publicly exposed management ports or self IPs) in both government and private sector networks.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Jamiroquai to Bring ‘Virtual Insanity’ to The Sandbox Blockchain Metaverse – Metaverse Bitcoin News
Next Post: Bitcoin Argentina NGO to Take Crypto Education to Schools – Bitcoin News

Related Posts

  • Russian Hackers Exploiting Microsoft Follina Vulnerability Against Ukraine cyber security news
  • SideWinder Hackers Launched Over a 1,000 Cyber Attacks Over the Past 2 Years cyber security news
  • Chinese “Override Panda” Hackers Resurface With New Espionage Attacks cyber security news
  • LockBit Ransomware Abuses Windows Defender to Deploy Cobalt Strike Payload cyber security news
  • New Air-Gap Attack Uses SATA Cable as an Antenna to Transfer Radio Signals — The Hacker News cyber security news
  • Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • India Freezes Peter Thiel-Backed Vauld’s Crypto and Bank Assets Worth $46 Million – Regulation Bitcoin News
  • Ethereum Price Broke Past $1,800 Despite Higher Demand At Lower Levels
  • Philippines Will Stop Accepting Crypto License Applications for 3 Years, Regulator Says – Regulation Bitcoin News
  • GAIMIN’s Early Access Event Opens Its Platform and Monetization App to Gamers – Press release Bitcoin News
  • Cardano Price Sits Pretty At $0.5, Why A Breakout Is On The Horizon

Recent Comments

No comments to show.
  • Ternoa, First NFT-Centric Blockchain, Releases Mainnet Setting to Disrupt NFT Economy – Press release Bitcoin News bitcoin news
  • Economist Peter Schiff Explains Why He Expects Bitcoin to Crash as Recession Deepens — Warns ‘Don’t Buy This Dip’ – Bitcoin News bitcoin news
  • Crypto Needs Enhanced Regulatory and Law Enforcement Frameworks – Regulation Bitcoin News bitcoin news
  • Bitcoin Cash to Include Bigger Integers and Native Introspection in Upcoming Upgrade – Bitcoin News bitcoin news
  • Bitcoin Price Could Rally Again If It Stays Above This Key Support bitcoin news
  • SideWinder Hackers Launched Over a 1,000 Cyber Attacks Over the Past 2 Years cyber security news
  • US Regulator Charges South African MTI and Its Operator With $1.7 Billion Fraud Involving Bitcoin – Regulation Bitcoin News bitcoin news
  • Over 110,000 Traders Rekt As Crypto Market Sees $120B Shaved Off bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme