Researchers from cyber threat intelligence company Mandiant on Thursday 29th published information on two malware leveraging unsigned vSphere Installation Bundles (“VIBs”) to install backdoors VirtualPita and VirtualPie on compromised ESXi host. First I would like to point out that malicious actors MUST have administrative privileges on the ESXi host to perform an attack. Also, there…
Read moreCategory: Security Advisory
VirtualPita, VirtualPie – new malware backdoors VMware ESXi servers to hijack virtual machines
The malicious actors found the new method of taking over the control of VMware ESXi hypervisors to control vCenter servers and virtual machines for Windows and Linux while avoiding detection. Attackers are using malicious vSphere Installation Bundles (“VIBs”) to install multiple backdoors across ESXi hypervisors. The malware is hidden in VIB payloads. Researchers from Mandiant…
Read moreLet’s determine expired SSL certificates in vCenter and ESXi 6.x and 7.x
Once you have an issue with signing in to your environment or some services cannot start, the more likely root cause is the SSL cert expiration. vCenter has a number of certificates and in this article, I will show you how to determine which certificate expired. The first certificate to check is Sign-on Token Signing…
Read moreVMware tools need to be patched!
VMware has released a security update to address a vulnerability in Tools. A remote attacker could likely exploit the vulnerability to take control of an affected system. VMware Tools was impacted by a local privilege escalation vulnerability. Updates are available to remediate this vulnerability in affected VMware products. VMware Tools contains a local privilege escalation vulnerability. VMware has evaluated the…
Read moreVMware fixed Security Token Service (STS) error with new patch – VMware vCenter Server 7.0 Update 3g
As we reported in this article, there was a bug in VMware vCenter Server 7.0 Update 3f, causing installation hung on 93%. An issue with STS in environments joined to an Active Directory domain that currently uses, or has used in the past, Integrated Windows Authentication (IWA) as an Identity Source, might prevent patching and…
Read morePatching time! VMware released an update for vCenter Server and ESXi -> 7.0 Update 3f.
vCenter server: NOTE: If your source system contains hosts of versions between ESXi 7.0 Update 2 and Update 3c, and Intel drivers, before upgrading to vCenter Server 7.0 Update 3f, see the What’s New section of the VMware vCenter Server 7.0 Update 3c Release Notes, because all content in the section is also applicable for vSphere 7.0 Update 3f. Also,…
Read moreNew ransomware is targeting Windows and Linux VMware ESXi servers – RedAlert/N13V
The ransomware was discovered by MalwareHunterTeam, who tweeted images of the malicious actor’s data leak webpage. The ransomware was called RedAlert as it has this name in the ransom note left for the victims, however, the criminals call their operation N13V, as we can see from the screenshots provided by the BleepingComputer website. We know…
Read moreBlack Basta Ransomware is now actively targeting VMware ESXi servers – Protect your environment!
What is Black Basta? Researchers from Uptycs reported that Linux version of Black Basta ransomware is now actively targeting ESXi servers, previously targeting Windows systems. Black Basta has been active since April 2022, like other ransomware operations, it implements a double-extortion attack model. Double-extortion scheme works in the way that first malicious actors extort victims…
Read moreCritical Severity – VMSA-2022-0014 – VMware Workspace ONE Access, Identity Manager and vRealize Automation
VMware published CRITICAL Severity VMSA-2022-0014. A critical vulnerabilities (CVE-2022-22972 and CVE-2022-22973) were discovered for: VMware Workspace ONE Access (Access) 20.10.0.1, 20.10.0.0, 21.08.0.1, 21.08.0.0 VMware Identity Manager (vIDM) 3.3.6, 3.3.5, 3.3.4, 3.3.3 VMware vRealize Automation (vRA) 7.6 The angle of the attack is a malicious actor with network access to the UI may be able to obtain administrative…
Read moreVMware vCenter Server 7.0 Update 3e is now available!
VMware released a new update for vCenter Server 7.0 -> vCenter Server 7.0 Update 3e ISO Build 19717403. This maintenance update delivers new features and fixes for VMware vSphere with Tanzu. For VMware vSphere with Tanzu updates, see VMware vSphere with Tanzu Release Notes. Download Filename VMware-vCenter-Server-Appliance-7.0.3.00600-19717403-patch-FP.iso Build 19717403 Download Size 8272.2 MB md5sum 3d4d977acd6072ff61db4a36909702e5 sha256checksum 6d67067d565fd530a6d047b079efff9019bdf28c63d04a904c43bcdf202d5c5d One…
Read more