VMWARE

CISA recommends VMware, F5 patches. Liquidity mining fraud. Strapi issues patched. TDI clarifies data incident.

CISA | May 20, 2022

CISA_recommends_VMware
VMware yesterday addressed issues in several of its products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. That these are more significant than the ordinary run of patches may be seen by the way the US Cybersecurity and Infrastructure Security Agency (CISA) has discussed them. Alert (AA22-138B), "Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control" warns that "malicious cyber actors, likely advanced persistent threat (APT) actors, are exploiting CVE-2022-22954 and CVE-2022-22960 separately and in combination." The Alert adds, "CISA expects malicious cyber actors to quickly develop a capability to exploit newly released vulnerabilities CVE-2022-22972 and CVE-2022-22973 in the same impacted VMware products. In response, CISA has released, Emergency Directive (ED) 22-03 Mitigate VMware Vulnerabilities, which requires emergency action from Federal Civilian Executive Branch agencies to either immediately implement the updates in VMware Security Advisory VMSA-2022-0014 or remove the affected software from their network until the updates can be applied." US Federal civilian agencies have until next Monday to identify and remediate the issues, and they're required to report completion no later than Tuesday.

Fraudulent liquidity mining.
Sophos describes the way the threat of fraudulent liquidity mining is shaping up in decentralized finance systems. "Legitimate liquidity mining exists to make it possible for decentralized finance (DeFi) networks to automatically process digital currency trades," Sophos explains, and criminals are using social engineering to abuse such systems to defraud cryptocurrency investors of their holdings.

More loosely regulated than conventional cryptocurrency exchanges, which use market makers and seek to ensure that sufficient reserves are on hand to back trades, DeFi exchanges use Automated Market Makers (AMMs). Sophos explains that "Smart contracts built into the DeFi network have to rapidly determine the relative value of the currencies being exchanged and execute the trade. Since there is no centralized pool of crypto for these distributed exchanges to pull from to complete trades, they rely on crowdsourcing to provide the pool of cryptocurrency capital required to complete a trade—a liquidity pool." Liquidity pool tokens, ("LP tokens") are used to represent the portion of the liquidity pool an investor contributed. But unethical DeFi operators can cancel the tokens (or simply not create a pool to back them in the first place), and this, Sophos observes, offers "ample opportunity for digital Ponzi schemes, fraudulent tokens, and flat-out theft."

CMS vulnerabilities disclosed and patched.
The Synopsys Cybersecurity Research Center (CyRC) has identified two vulnerabilities in Strapi. Strapi is an open-source headless content management system (CMS) Javascript software that enables developers to quickly design and build content-rich APIs. Both vulnerabilities involve authenticated users with access to the Strapi admin panel having access to private and sensitive data, such as email and password reset tokens. The first vulnerability allows for the authenticated user to view private and sensitive data for other admin panel users that have a relationship with content accessible to the authenticated user. The second vulnerability allows for the authenticated user to view private and sensitive data for API users if content types accessible to the authenticated user contains relationships to API users. The vulnerabilities are fixed in newer, updated versions of Strapi, and Synopsys has commended Strapi for its quick response to the discovery.

Texas Department of Insurance clarifies facts surrounding its data incident.
The Texas Department of Insurance (TDI) has sent around a fact sheet that clarifies a data incident the agency sustained earlier this year: "In January 2022, TDI found the issue was due to a programming code error that allowed internet access to a protected area of the application. TDI promptly disconnected the web application from the internet. After correcting the programming code, TDI placed the web application back online. The forensic investigation could not conclusively rule out that certain information on the web application was accessed outside of TDI. This does not mean all the information was viewed by people outside TDI. Because we couldn't rule out access, we took steps to notify those who may have been affected." While data could have been accessed by unauthorized personnel, TDI has investigated and found that, "There is no evidence to date that there was a misuse of information."

Spotlight

Find out how KVM and container virtualization differs and how each can be used to create a flexible virtualization solution for any business environment.

Spotlight

Find out how KVM and container virtualization differs and how each can be used to create a flexible virtualization solution for any business environment.

Related News

VIRTUAL DESKTOP TOOLS

Repairify and Autel Announce Exclusive North American Agreement

Repairify | March 03, 2023

Repairify, LLC portfolio company of Kinderhook Industries, and Autel U.S., a wholly-owned subsidiary of Autel Intelligent Technology, have announced an exclusive long-term collaboration agreement to bring Repairify's patented global OEM remote solutions for diagnostics, calibrations, and programming through Autel's remote-capable products across North America. Repairify's industry-leading patented remote diagnostic, calibration, and programming solutions will be added as a new service option to an upgraded version of Autel's Remote Expert platform as per agreement. Customers can choose between Repairify's OEM-certified and warrantied remote solutions and those of the independent, experience-verified Remote Experts already serving the platform, thanks to the platform's shared management by Repairify and Autel. Launched in 2022, Autel's Remote Expert offers on-site aftermarket scanning and remote access to OEM tools backed by trained experts. Autel MaxiSYS Ultra, Ultra EV, MS919, MS909, and MS909 EV diagnostic tablets support Autel's Remote Expert service. In addition, there will be an extension of Remote Expert to Autel's ADAS calibration systems. "We are excited to enter into this collaboration with Repairify. Autel developed the Remote Expert platform to provide our users remote access to specialized and experienced module programmers and diagnosticians. We are very proud that its success drew the attention of a company of such quality and industry success as Repairify. We are confident that this partnership will benefit both companies and, most importantly, be of immense value to our users," said Chloe Hung, CEO, Autel U.S. (Source –CISION PR Newswire) Cris Hollingsworth, President of Repairify Global Holdings said, "Since its launch into the North American market in 2005, Autel has been known for their consistent delivery of leading innovative solutions across the mechanical and collision markets.". He added, "Repairify is honored to embark on this partnership and to broaden the reach of our solutions through the new and existing Autel network of customers." (Source –CISION PR Newswire) About REPAIRIFY Repairify, founded in 2015 and headquartered in Plano, Texas, along with its family of brands, empower the automotive repair sector to master the data-intensive, modern vehicles. Repairify aids automotive experts in diagnostics, calibration, programming, and workflow by providing new OE tools and certified OEM-compatible technology, services, and information.

Read More

VIRTUAL DESKTOP STRATEGIES, SERVER VIRTUALIZATION

NordVPN's Free Version Marks Milestone in Encrypted Networking through Meshnet

NordVPN | March 16, 2023

NordVPN's current product update features Meshnet file-sharing, easy file-sharing functionality, and an open-source Linux application which provides free meshnet to everyone. Meshnet's benefits no longer require a NordVPN subscription. Computers and mobile devices are now connected via a peer-to-peer VPN tunnel. Users can bypass restrictions by routing their internet traffic through any NordVPN-enabled remote device. Windows, mac, and linux devices can be personal VPN servers. This implies consumers can now enjoy perks at home regardless of their location. Meshnet allows instant unlimited file sharing and sharing unlimited-size photos and videos without quality loss. In addition, it is a safe approach to share files through an end-to-end encrypted peer-to-peer VPN tunnel. Users can share and receive files from their own devices and from NordVPN-installed relatives, friends, and co-workers. Two-way permission ensures privacy with the new functionality. Meshnet lets users avoid internet restrictions by routing their traffic through any remote NordVPN-installed device. Windows, Mac, and Linux devices can serve as personal VPN servers. This means consumers can enjoy all advantages at home regardless of their location. NordVPN has rolled out three of its products under an open-source license: The entire NordVPN Linux application, Libtelio, which is a networking library used throughout NordVPN apps, and Libdrop, a Meshnet file-sharing library. Developers can now audit, review, and contribute to these products' source code, which is publicly available. NordVPN, an opensource shows transparency, community engagement, and product trust by making these products open source. Android, iOS, macOS, Windows, Linux, and Android TV support Meshnet. NordVPN updated its Meshnet documentation page on its website, which states: Internet traffic routing: With Meshnet, travelers can use a laptop left at home to browse the internet with their own IP address. Meshnet lets you establish your own VPN server through your own or your friends' devices, no matter their whereabouts. Secure Remote Device Access: To view shared folders remotely, Meshnet doesn't require public sharing. It secures your home network using a peer-to-peer VPN tunnel, so you're the only one connecting to your home network. Gaming: Meshnet acts as a virtual local area network (LAN), allowing users to play multiplayer games with others without LAN wires. In short, users can connect to the same server from different places. NordVPN Product Strategist, Vykintas Maknickas, remarked, "We are continuously expanding the capabilities of NordVPN. This release marks a significant change in openness by both making part of the service free as well as open-sourcing a substantial part of our client software.” (Source – iTWire) About NordVPN NordVPN, founded in 2012, is a company that protects against ISPs, advertising, and other third-party snoopers. It makes connecting to public Wi-Fi hotspots easy and secure. Meshnet, a recent product, allows instant unlimited file sharing and sharing unlimited-size photos and videos without quality loss. It allows usage of personal VPN using windows, mac, and linux devices. It provides 5600+ servers in 60 countries to browse freely.

Read More

VMWARE, CLOUD

CDI to Leverage VMware Cross-Cloud Managed Services for Enhanced Client Solutions

Businesswire | April 19, 2023

CDI (Computer Design & Integration, LLC), a leading provider of technology solutions and services, announces plans to build and deliver VMware Cross-Cloud managed services to better assist their clients in their journey to the cloud. VMware unveiled the new managed service offerings at the VMware Leadership Summit: Accelerate Managed Services event this week. The team at CDI looks forward to taking part in the initiative, which will enable highly skilled partners to expand their managed services practices, improve profitability, and open new opportunities for growth and expansion. VMware Cross-Cloud managed services are a portfolio of offerings designed to make building managed services faster for CDI and more easily consumed by CDI’s clients. This suite of services, some powered by VMware Cross-Cloud services, offers robust cloud services with the lower risk and fast time to value built on VMware's deeply integrated, enterprise-class multi-cloud infrastructure as a service stack. Additionally, the prescriptive services will provide centralized governance, cost optimization, and cloud-native app delivery. “At CDI, our focus has always been on delivering the best solutions for our clients,” said Will Huber, Chief Technology Officer, CDI. “VMware Cross-Cloud managed services is an excellent opportunity for us to expand our offerings and further empower our clients in their digital transformation journey. We are eager to leverage these cutting-edge services to provide our customers with unparalleled managed services experience.” “Multi-cloud complexity is opening the door for VMware partners to deliver high-value, repeatable, and prescriptive managed services offerings that address our customers state of cloud chaos,” said Zia Yusuf, senior vice president, strategic ecosystem and industry solutions, VMware. “As a VMware partner with a track record in helping customers migrate to the cloud, CDI will be able to utilize VMware Cross-Cloud managed services to add a new level of capabilities that accelerate cloud native app modernization, while making it faster and easier to operate in the cloud.” CDI is dedicated to staying ahead in the fast-paced world of technology and delivering exceptional value to its clients. By adopting VMware Cross-Cloud managed services, CDI will be better equipped to help customers optimize their IT environments, improve operational intelligence across multi-cloud environments, and automate modern DevSecOps platform operations. Most recently, CDI was named as winner of the 2023 VMware Cloud Innovation and SaaS Transformation Award for the Americas region, along with being named VMware Cloud on AWS Partner of the Year and VMware State and Local Government and Education Growth Partner of the Year. While the VMware Cross-Cloud managed services announcement took place on April 18, CDI will not immediately deliver on these services. CDI plans to support all VMware Cross-Cloud managed services, initially offering Cloud Native App Delivery as a Managed Service based on VMware Tanzu to its clients in the near future. About CDI (Computer Design & Integration LLC) CDI, a leading global IT solutions provider, was founded in 1995 with corporate headquarters in New York City and additional offices located throughout the United States, Ireland, and the UK. With a steadfast commitment to client satisfaction, CDI offers businesses of all sizes the most cutting-edge hybrid IT technology solutions available. By focusing on enhancing day-to-day workflow processes, CDI provides clients with digital solutions that address even the most complex business challenges.

Read More