Articles tagged "VMware"

Found 18 articles

A cyber espionage group linked to China, known as Fire Ant, has broadened its operations to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. This escalation follows a previous focus on VMware hypervisors. The group aims to steal credentials and disable security logs, which could severely compromise the integrity of high-value networks. Sygnia, the incident response firm that investigated the incidents, emphasizes the significance of these vulnerabilities given the critical role these systems play in network management and authentication. Organizations using these technologies should be vigilant and take immediate steps to secure their infrastructures.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild, adding them to its Known Exploited Vulnerabilities (KEV) catalog. Among these is CVE-2026-65400, a serious authentication flaw in Apple macOS that could allow unauthorized access. Other vulnerabilities affect Microsoft SharePoint, VMware vCenter, and Microsoft IKE, all of which pose significant risks to organizations using these platforms. With a CVSS score of 9.8 for CVE-2026-65400, it’s crucial for users and companies to act quickly to mitigate these risks. The exploitation of these vulnerabilities could lead to severe data breaches or unauthorized access, making it essential for affected parties to stay informed and apply necessary updates and patches.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically targeting flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE. One notable vulnerability, CVE-2026-33824, relates to the Windows Internet Key Exchange (IKE) Service Extensions and poses a risk of remote code execution. These vulnerabilities could allow attackers to exploit systems running the affected software, potentially leading to unauthorized access or data breaches. It's crucial for users and organizations utilizing these platforms to take immediate action to mitigate the risks associated with these vulnerabilities. Keeping software updated and applying any available patches is essential to protect against potential exploitation.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being targeted by cybercriminals. The vulnerabilities include a double free flaw in Microsoft Internet Key Exchange (CVE-2026-33824), a weak authentication issue in Microsoft SharePoint (CVE-2026-55040), a path traversal vulnerability in Broadcom's VMware vCenter (CVE-2026-59310), and an improper authentication vulnerability in Apple macOS (CVE-2026-65400). These vulnerabilities pose significant risks, especially for federal agencies, which are required to prioritize their remediation under Binding Operational Directive 26-04. Although this directive specifically targets federal agencies, CISA encourages all organizations to adopt similar practices to enhance their security posture against these threats.

Read Original

Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.

Read Original

A serious vulnerability in VMware's vCenter software has been identified, tracked as CVE-2026-59310. This directory traversal flaw allows remote attackers to execute arbitrary code on affected systems, posing a significant risk to users. Organizations that rely on vCenter for managing virtualized environments should prioritize addressing this issue. The potential for exploitation means that attackers could gain control over systems, leading to data breaches or other malicious activities. It's crucial for companies to apply any available patches or updates to safeguard their infrastructure.

Read Original
Actively Exploited

A new vulnerability in VMware vCenter has been identified and is currently being exploited by an unspecified advanced persistent threat (APT) group. This group has targeted 361 unique IP addresses across 47 countries, indicating a widespread impact. The flaw poses significant risks to organizations using VMware vCenter, as it could allow attackers to gain unauthorized access and control over critical systems. Given the number of affected systems, companies using VMware products need to assess their exposure and take immediate action to secure their environments. The urgency of addressing this vulnerability cannot be overstated, as ongoing attacks are already in progress.

Read Original

Recent research from QUIRSO reveals that attackers are exploiting a severe vulnerability in Broadcom's VMware vCenter, identified as CVE-2026-59310, which has a CVSS score of 9.8. This directory-traversal flaw allows malicious users with network access to execute arbitrary code on the server, creating a significant risk for organizations using this software. The vulnerability is particularly concerning because it enables persistent remote access, potentially compromising sensitive systems. VMware has issued patches to address this flaw, but organizations must act quickly to implement them to protect against active exploitation. This incident serves as a reminder of the importance of timely updates in cybersecurity management.

Read Original

CrowdStrike has identified a new technique used by attackers to obfuscate shell commands on VMware ESX systems. This method complicates detection efforts by security tools, making it easier for malicious actors to execute unauthorized commands without being noticed. The research highlights the risks associated with virtualized environments, which are increasingly targeted by cybercriminals. Users and organizations running VMware ESX should be particularly vigilant and ensure they have adequate monitoring in place to catch any suspicious activity. The findings serve as a reminder of the evolving tactics used by attackers and the need for continuous improvement in security protocols.

Read Original

Broadcom has issued security updates to fix several vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Among these, three flaws are deemed critical, with CVE-2026-59309 being the most severe, rated at 9.8 on the CVSS scale. This particular flaw allows attackers with network access to VMware vCenter to bypass authentication, potentially leading to unauthorized access. Other vulnerabilities could enable code execution and VM escape, which poses significant risks for virtualized environments. Organizations using these VMware products should prioritize applying the updates to safeguard against potential exploits.

Read Original

Broadcom has addressed a serious vulnerability in VMware ESXi that could allow attackers to execute code on a host machine from a compromised virtual machine. This flaw, identified as CVE-2026-47876, has a high severity rating of 9.3 on the CVSS scale, indicating a significant risk. Alongside this critical issue, Broadcom released patches for four other vulnerabilities affecting VMware's ESXi, vCenter, Workstation, and Fusion products, three of which are also classified as critical. Companies using these systems should prioritize applying the patches to safeguard their environments, as the potential for exploitation could lead to severe data breaches or system compromises.

Read Original

VMware has patched five vulnerabilities across its products, including VMware ESXi, vCenter, Workstation, and Fusion. Among these, a critical VM escape vulnerability was identified, which could allow attackers to break out of a virtual machine and execute code on the host system. This poses a serious risk to users operating these virtual environments, as it could lead to unauthorized access to sensitive data and systems. Organizations using these VMware products should prioritize applying the latest updates to secure their infrastructure. The vulnerabilities were addressed in a recent update, emphasizing the need for regular patch management in virtualized environments.

Read Original

Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.

Read Original

VMware has patched seven serious vulnerabilities in its Avi Load Balancer that could allow attackers to bypass authentication, execute remote code, escalate privileges, and traverse directories. These vulnerabilities pose a significant risk to organizations relying on this load balancing technology, as they could lead to unauthorized access and control over systems. Users of VMware Avi Load Balancer should prioritize applying the latest patches to safeguard their environments. The severity of these vulnerabilities highlights the ongoing need for vigilance in cybersecurity practices, especially for widely used infrastructure components.

Read Original
Actively Exploited

CISA has reported that ransomware gangs are now exploiting a serious vulnerability in VMware ESXi, which allows attackers to escape sandboxes and gain unauthorized access to systems. This vulnerability, which had previously been used in zero-day attacks, poses a significant risk to organizations using affected VMware products. Companies relying on VMware ESXi for virtualization need to be particularly vigilant, as attackers are actively targeting this flaw. The exploitation of such vulnerabilities can lead to severe data breaches and financial losses. Organizations should prioritize patching their systems to mitigate this risk and protect sensitive data from potential ransomware attacks.

Read Original
Page 1 of 2Next