Critical Authentication Bypass Flaw in VMware Cloud Director Appliance

November 14, 2023 at 04:21PM VMware has released an urgent patch to fix a serious authentication bypass bug in its Cloud Director Appliance product. The vulnerability, known as CVE-2023-34060, has a severity score of 9.8 out of 10 and can be exploited by attackers with network access. The issue affects instances where the appliance has … Read more

Critical Atlassian Confluence bug exploited in Cerber ransomware attacks

November 6, 2023 at 12:40PM Attackers are exploiting a critical security flaw in Atlassian Confluence to encrypt files with Cerber ransomware. The flaw, tracked as CVE-2023-22518, received a severity rating of 9.1/10 and affects all versions of Confluence Data Center and Confluence Server software. Although there are currently no reports of active exploitation, Atlassian has … Read more

Alert: PoC Exploits Released for Citrix and VMware Vulnerabilities

October 25, 2023 at 02:36AM Virtualization services provider VMware has alerted customers to a proof-of-concept exploit for a recently patched security flaw in Aria Operations for Logs. The vulnerability, tracked as CVE-2023-34051, allows for authentication bypass and remote code execution. A PoC for the vulnerability has been made available, prompting VMware to revise its advisory. … Read more

VMware warns admins of public exploit for vRealize RCE flaw

October 24, 2023 at 10:56AM VMware has alerted customers to the availability of proof-of-concept exploit code for an authentication bypass flaw in vRealize Log Insight (now VMware Aria Operations for Logs). Tracked as CVE-2023-34051, the vulnerability allows unauthenticated attackers to remotely execute code with root permissions. Researchers have released a technical analysis, a proof-of-concept exploit, … Read more