Cisco Finesse Exposes Vulnerabilities Allowing Attackers to Execute Stored XSS Attacks

Cisco Finesse Exposes Vulnerabilities Allowing Attackers to Execute Stored XSS Attacks

Cisco has disclosed two vulnerabilities in its Finesse web-based management interface which could allow remote attackers to conduct a stored cross-site scripting attack. The vulnerabilities, identified as CVE-2024-20404 and CVE-2024-20405, involve a remote file inclusion vulnerability and a server-side request forgery attack. These vulnerabilities have a security impact rating of Medium, as they provide limited … Read more

Ransomware attacks against VMware ESXi infrastructure are using a new method

Ransomware attacks against VMware ESXi infrastructure are using a new method

Sygnia cybersecurity experts have observed a rise in ransomware attacks targeting virtualized environments, particularly VMware ESXi infrastructure. Threat actors are exploiting vulnerabilities and misconfigurations in virtualization platforms to exfiltrate data before encrypting systems. Notorious ransomware groups such as LockBit and BlackMatter are using this attack vector. These attackers shut down virtual machines before encryption, making … Read more

IBM X-Force Report: Grandoreiro Malware Attacks Over 1,500 Banks Across 60 Countries

IBM X-Force Report: Grandoreiro Malware Attacks Over 1,500 Banks Across 60 Countries

IBM X-Force has released a new report highlighting the evolution of the Grandoreiro malware, a banking trojan that can now target over 1,500 global banks across 60 countries with enhanced features. Originally focused on Spanish-speaking countries, recent campaigns have expanded to Europe, Asia, and Africa. The malware has the ability to send phishing emails directly … Read more

Ransomware Attacks Exploit Vulnerabilities in VMware ESXi in an Alarming Pattern

Ransomware Attacks Exploit Vulnerabilities in VMware ESXi in an Alarming Pattern

Ransomware attacks targeting VMware ESXi infrastructure follow a set pattern, with threat actors gaining access through phishing attacks and known vulnerabilities, escalating privileges to compromise ESXi hosts or vCenter, and deploying ransomware. Organizations are advised to implement monitoring and logging, robust backup mechanisms, strong authentication measures, network restrictions, and hardening of the environment to mitigate … Read more

Attacks exploiting critical VMware vulnerabilities could lead to code execution and DOS attacks

Attacks exploiting critical VMware vulnerabilities could lead to code execution and DOS attacks

VMware has released patches for critical vulnerabilities affecting its ESXi, Workstation, Cloud Foundation, and Fusion products. These vulnerabilities could allow attackers to execute malicious code on host systems from virtual machines, posing a significant security risk. One of the critical vulnerabilities is an out-of-bounds read/write issue affecting storage controllers on VMware ESXi, Workstation, and Fusion. … Read more

HPE Aruba Devices at Risk from RCE Attacks due to Four Critical Vulnerabilities

HPE Aruba Devices at Risk from RCE Attacks due to Four Critical Vulnerabilities

HPE Aruba Networking has recently issued security updates to address critical vulnerabilities in ArubaOS that could potentially lead to remote code execution on affected systems. Among the 10 identified security flaws, four are classified as critical due to their severity. These include unauthenticated buffer overflow vulnerabilities in various services accessed via the PAPI protocol, posing … Read more

RansomHouse gang automates VMware ESXi attacks with new MrAgent tool

RansomHouse gang automates VMware ESXi attacks with new MrAgent tool

The RansomHouse ransomware operation has created a new tool named ‘MrAgent’ that automates the deployment of its data encrypter across multiple VMware ESXi hypervisors. RansomHouse is a ransomware-as-a-service (RaaS) operation that emerged in December 2021 and is using double extortion tactics. In May 2022, the operation set up a dedicated victim extortion page on the dark web. … Read more

VMware confirms critical vCenter flaw now exploited in attacks

VMware confirms critical vCenter flaw now exploited in attacks

VMware has confirmed that a critical vCenter Server remote code execution vulnerability patched in October is now under active exploitation. vCenter Server is a management platform for VMware vSphere environments that helps administrators manage ESX and ESXi servers and virtual machines (VMs). “VMware has confirmed that exploitation of CVE-2023-34048 has occurred in the wild,” the … Read more

Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks

Critical Vulnerability Alert: VMware Aria Operations Networks at Risk from Remote Attacks

Aug 30, 2023THNVulnerability / Network Security VMware has released software updates to correct two security vulnerabilities in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution. The most severe of the flaws is CVE-2023-34039 (CVSS score: 9.8), which relates to a case of authentication bypass arising as … Read more

Is Your Virtual Machine Safe from Cyber Attacks in Cloud Computing?

With the rise of cloud computing, virtual machines have become a popular way of running multiple instances of operating systems on a single physical machine. The convenience and flexibility of virtualization have made it an attractive option for businesses of all sizes. However, virtual machines come with their own set of security risks that must … Read more