CISA Cybersecurity Alerts

Update 1 to CISA Alert AA22-138B – Threat actors chaining unpatched VMware vulnerabilities for full system control.


Listen Later

Malicious cyber actors are exploiting multiple critical vulnerabilities in VMware products. Successful exploitation permits malicious actors to trigger a server-side template injection that may result in remote code execution or escalation of privileges to root level access. CISA has updated this alert with additional indicators of compromise, detection signatures, and threat actor TTPs from trusted third parties to assist administrators with detecting and responding to this activity.

AA22-138B Alert, Technical Details, and Mitigations

AA22-138B.stix

Emergency Directive 22-03 Mitigate VMware Vulnerabilities

VMware Security Advisory VMSA-2022-0011

VMware Security Advisory VMSA-2022-0014

Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at [email protected] or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or [email protected].

Learn more about your ad choices. Visit megaphone.fm/adchoices

...more
View all episodesView all episodes
Download on the App Store

CISA Cybersecurity AlertsBy N2K Networks

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

12 ratings


More shows like CISA Cybersecurity Alerts

View all
CyberWire Daily by N2K Networks

CyberWire Daily

1,023 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,049 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

181 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

92 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners