Linux Cryptominer Uses Virtual Machines to Attack Windows, macOS

bleepingcomputer | June 20, 2019

A new cryptocurrency mining malware dubbed LoudMiner uses virtualization software to deploy a Linux XMRig coinminer variant on Windows and macOS systems via a Tiny Core Linux virtual machine.The malware comes bundled within cracked copies Windows and macOS VST software such as Propellerhead Reason, Ableton Live, Sylenth1, Nexus, Reaktor, and AutoTune. LoudMiner is distributed via an attacker-controlled website which currently links to 137 VST-related apps, 42 of them for Windows and 95 for the macOS platform, all of them frequently updated and hosted on 29 servers, as discovered by ESET Research's detection engineer Michal Malik.

Spotlight

Onsite host Joe Zollo asks VMware CEO Raghu Raghuram and President Sumit Dhawan to break down the news coming out of VMware Explore Las Vegas.

Spotlight

Onsite host Joe Zollo asks VMware CEO Raghu Raghuram and President Sumit Dhawan to break down the news coming out of VMware Explore Las Vegas.

Related News

Server Hypervisors, Security

ePlus Achieves VMware Cross-Cloud Managed Service Provider Designation

prnewswire | August 23, 2023

ePlus inc. (NASDAQ NGS: PLUS–news)today announced that it has achieved the VMware Cross-Cloud Managed Service provider status. To attain this designation, ePlus passed a thorough independent audit of its VMware Cloud managed services technical expertise and operational excellence. Complementing this recognition and after a comprehensive service offering review, ePlus Cloud Disaster Recovery powered by VMware Cloud Disaster Recovery has also been recognized by VMware as a Validated Service Offering (VSO). VMware Cross-Cloud managed services are a set of prescriptive offers with enhanced partner and customer benefits that enable highly skilled partners to expand their managed services practices. The VMware Cross-Cloud Managed Service Provider designation signifies partners' experience with delivering VMware-validated managed services offerings and the achievement of the VMware Managed Services Specialization (MSS). "We are proud to be a launch partner for VMware Cross-Cloud managed services, as well as having our Cloud Managed Disaster Recovery offering validated by VMware," saidJustin Mescher, vice president of cloud and data center solutions at ePlus. "ePlus has been providing Cloud Hosted Infrastructure and Cloud Disaster Recovery for more than 10 years, and since migrating these services to VMware Cloud on AWS we have seen significantly increased customer interest and adoption. The capability for on-demand recovery with integrated ransomware detection and response, combined with ePlus' design expertise and failover services, are helping our clients increase confidence in their ability to recover in a cost-effective fashion." "ePlus has been at the forefront of delivering VMware-based managed services that help meet customers' most pressing challenges," saidAbhay Kumar, VP for Hyperscalers and Technology Partners, VMware. "With ePlus Cloud Disaster Recovery, ePlus is delivering an on-demand, easy-to-use service with cloud economicsthat enables business resiliency at scale. This will help deliver on the promise of VMware Cross-Cloud managed services." About ePlusinc. ePlus has an unwavering and relentless focus on leveraging technology to create inspired and transformative business outcomes for its customers. Offering a robust portfolio of solutions, as well as a broad range of consultative and managed services across the technology spectrum, ePlus has proudly achieved more than 30 years of success, carrying customers forward through adversity, rapidly changing environments, and other obstacles. ePlus is a trusted advisor, bringing expertise, credentials, talent and a thorough understanding of innovative technologies, spanning security, cloud, data center, networking, collaboration and emerging solutions, to organizations across all industry segments. With complete lifecycle management services and flexible payment solutions, ePlus' more than 1,850associates are focused on cultivating positive customer experiences and are dedicated to their craft, harnessing new knowledge while applying decades of proven experience. ePlus is headquartered inVirginia, with locations inthe United States, UK,Europe, and Asia‐Pacific.

Read More

Virtual Desktop Strategies, Virtual Server Management

VMware Advances Autonomous Workspaces with AI-Powered Integrations

Business Wire | August 28, 2023

VMware Explore 2023 — Data and intelligence play a key role in enabling automation and implementing a successful hybrid work strategy, but a holistic approach is required to maximize its advantages. Today, VMware announces modern AI integrations to the Anywhere Workspace platform, part of the VMware Cross-Cloud services portfolio, that automatically optimize employee experience, drive new vulnerability management use cases, and simplify application lifecycle management. VMware Anywhere Workspace is the only hybrid work platform that integrates digital employee experience (DEX), virtual desktop infrastructure and apps (VDI and DaaS), unified endpoint management (UEM) and security to enable a seamless and secure workspace on any device or location. “Last year, we announced our Autonomous Workspace vision as a path forward for organizations to navigate the challenges brought on by hybrid work,” said Shankar Iyer, senior vice president and general manager, End-User Computing, VMware. “We are thrilled to unveil new advancements for our customers that expand data sources and insights, integrate with technology partners for improved security, and unify app delivery strategy across all virtual desktops and apps. These innovations continue to progress our vision of providing the next evolution of digital workspaces.” Integrated AI-Driven Platform Scales Experience Management VMware continues to leverage data, intelligence, and automation to improve the employee and IT experience by introducing new Insights and Playbooks based on greatly expanded data and machine learning algorithms that enhance DEX remediation capabilities. These updates broaden access to data, help strengthen VMware Insights, and allow for remediation of more issues. VMware will now enable delivery of new app performance scores, in addition to existing mobile device, desktop, and virtual environment experience scores. If a SaaS app service goes down, IT is proactively alerted and employees are automatically notified. This allows IT to quickly resolve the outage without dealing with inbound support tickets and employees don't waste time trying to access unavailable services. But simply providing IT with more data is not enough to empower them to work smarter. VMware’s AI-driven Insights feature now provides anomaly detection that informs IT of potential experience issues for frontline devices and VDI environments, in addition to mobile and desktop environments. Today’s announcement of new Playbooks enables IT to create step-by-step remediation workflows to resolve incidents more efficiently and use success rate analytics to automate the resolution process and streamline execution over time. “Workspace ONE Intelligence has been a game changer for us when it comes to automating life cycle management inside UEM. We have been utilizing it for automatically tagging devices and assigning them into smart groups. We have also used several dashboard templates for monitoring our security stance and helping remediate high-risk security threats,” said George March, manager of digital workspace and development, Information Technology, USA Health. “Next on our roadmap is implementing the ITSM connector, and with the addition of remediation playbooks, we are so excited about the way it will streamline our help desk support teams workflows.” Unique Partner Integration Powers New Security and Manageability Use Cases Ensuring end-to-end manageability and security for today’s distributed workforce is critical and requires a holistic approach to vulnerability assessment, prioritization, remediation, out-of-band support, and reporting. Collaboration with a best-of-breed partner ecosystem that offers speed, breadth, and depth in vulnerability management is necessary to protect against sophisticated attack vectors. VMware is committed to innovating together with our technology partners to provide customers with more secure and seamless hybrid experiences. Today, VMware continues this mission by announcing an expanded partnership with Intel through a one-of-a-kind, cloud-native integration of Workspace ONE with Intel vPro®. This chip-to-cloud integration makes it easier to secure and remotely manage work devices entirely from the cloud, with no additional on-premises infrastructure and management software needed. Through line of sight and out-of-band management of vPro powered devices, IT teams can have below-the-OS vulnerability insights, and visibility to reduce the impact of potential exploits quickly and efficiently. Using Workspace ONE, customers can have centralized visibility into Intel vPro-powered PCs and accelerate patch remediation cycles for devices located outside of office perimeters, even if the devices are sleeping or powered off. This improves security and compliance by accomplishing higher patch saturation with fewer remediation steps and reduces potential disruption to employee productivity. Modern App Management Simplifies Virtual Environments Managing and delivering apps across VDI, DaaS, and published app environments has become increasingly complex and inefficient due to silos of legacy tools used. VMware recently introduced Apps on Demand, powered by VMware App Volumes, to unify app management and intelligently deploy apps to published app hosts or non-persistent desktop environments, all based on real-time app usage. Today, VMware announces additional expansion of App Volumes support to deliver apps on demand to persistent virtual desktops. Now in beta availability, customers with persistent VMware Horizon environments will be able to use App Volumes to capture their apps once and deliver to many persistent virtual desktops. This automates the app delivery process with up to 99% compatibility and reduces management time and costs for any desktop or published app environment. VMware App Volumes is the only solution to help organizations deliver and manage apps across VMware Horizon, Citrix, Microsoft, and Amazon virtual desktop and app deployments as part of VMware’s Apps Everywhere vision. Boeing: A ‘Hybrid Workforce Innovator’ The Boeing Company (Boeing) has used VMware Workspace ONE across the United States and in more than 65 countries to support its global workforce of 140,000 employees who develop, manufacture and service commercial airplanes, defense products and space systems for its customers. At VMware Explore 2023 Las Vegas, they were named ‘Hybrid Workforce Innovator’ as part of the 2023 VMware Customer Achievement Awards for the Americas for enabling its workforce to work from anywhere in the world, improving the user experience while reinforcing and advancing security for devices and applications. “VMware Anywhere Workspace helps us manage and protect end points, provide a common platform to access apps and tools, as well as helping facilitate a digital experience for our employees,” said Kristina Ross, Boeing Workplace Solutions director for Research & Technology. “Workspace ONE helped streamline our transition from traditional PC lifecycle management to Windows 10 modern management which was enabled by our shift to a SaaS-based solution for the company. Today, we have a unified view to oversee all endpoint requirements, and the adoption of SaaS enhanced our scalability and ability to shift focus from infrastructure to business facing solutions.” About VMware VMware is a leading provider of multi-cloud services for all apps, enabling digital innovation with enterprise control. As a trusted foundation to accelerate innovation, VMware software gives businesses the flexibility and choice they need to build the future. Headquartered in Palo Alto, California, VMware is committed to building a better future through the company’s 2030 Agenda.

Read More

Virtual Desktop Strategies, Virtual Server Management

LogicMonitor Expands Observability Intelligence to New Environments

businesswire | August 18, 2023

LogicMonitor, a leading SaaS-based unified observability platform for hybrid IT infrastructure, today announced expanded integrations, insights and workflows to the LM Envision Platform. LogicMonitor is also introducing Dexda, an event management solution that filters through the noise of thousands of daily alerts by using advanced machine learning (ML) techniques, contextual enrichment capabilities and deduplication efforts. Together, these additions allow customers to reach a significantly lower mean time to resolution and lower risks to the business. “Every business is under tremendous pressure to seamlessly deliver exceptional digital performance,” states Christina Kosmowski, CEO, LogicMonitor. “To efficiently do that, our customers look to us to contextualize the overwhelming amount of data within their complex IT environments.“ The core of LogicMonitor’s platform has been built with advanced machine learning, intelligence and automation, combined to abstract complexity and deliver business impact through IT data collaboration. The company has focused its product roadmap in the areas of intelligence, experience and extensibility. Intelligence and Automation Dexda is the next evolution of AI Ops. It is built on top of LogicMonitor’s extensive data set and integrated into its platform, so users can effortlessly move from alerting to automating actions. Key attributes of Dexda include: Adaptive Correlation- Alerts are automatically re-clustered when a more optimal option is detected. ServiceNow Ready- Automatically enriches Dexda alerts with ServiceNow CMDB data to drive additional context for ML correlations. User-defined Correlation- Dexda admins can now fine-tune the ML models to meet their unique needs or build new ML models. In addition to Dexda, LogicMonitor has also delivered: Event-Driven Ansible Integration- This jointly developed solution with Red Hat assists with auto-remediation and auto-troubleshooting. This integration lets customers trigger remediation workflows in Ansible and act in accordance with predefined rules. Datapoint Analysis- Leverages machine learning techniques to find related metrics and patterns across different resources, which in turn reduces MTTR and increases productivity. Unified Platform Experience A unified platform experience is critical for consistency, adaptability and scalability while reducing tool sprawl and data complexity. Troubleshooting in hybrid modern environments requires a contextual and intuitive UX across devices, services and networks. This modernization and unification effort is the key to continually delivering new capabilities to users and keeping time to value short for new customers. UI Modernization- Optimized to present information in complex hybrid environments. Components for all parts of the LM Envision platform now include bulk actions, better search and filtering and new editors for LogicModules. Expanded Cloud Support- 20 new out-of-the-box dashboards for AWS and Azure, accelerating time to value while providing service-specific views for more insight into health, performance and availability. Log Ingest and Filter Simplification- Introduced declarative UI to simplify log collection and configuration. Users can also add custom LM Properties to the logs which allows for more flexible searching and potentially faster MTTR. Digital Experience Monitoring- Synthetic tests now support multi-factor authentication (MFA) and automated alerts for latency and error conditions. Extensibility As a trusted partner in the advancement of monitoring across on-prem, hybrid and cloud environments, LogicMonitor continues to invest in new ways to manage and monitor network equipment through integrations woven tightly into its overall platform experience. Improved VMware vSphere Support- Support for vSphere 8 and automation for the discovery and monitoring of new ESXi Hosts and mission-critical Virtual Machines, eliminating manual processes – reducing the time, resources and risk involved in repeatable remediation processes. Cisco Meraki and Catalyst SD-WAN- These new integrations make it easier than ever to monitor Cisco environments in the broader context of one's heterogenous hybrid infrastructure. Customers can now get alerted about anomalous events, visualize network traffic usage and see how Cisco vEdge/cEdge (formerly Viptela), SD-WAN Controllers, Meraki Security Appliances, Switches, Wireless Access Points and Smart Cameras connect to their network and where alert conditions exist. Improved Kubernetes Monitoring- Greater coverage and deeper visibility into frequently changing cloud environments with new support and coverage for Amazon Elastic Kubernetes Service (Amazon EKS) Anywhere and enhanced Kubernetes helm and scheduler monitoring. SaaS Monitoring-M365 and Okta logs allow users to clearly understand why problems happen, pinpoint the root cause and quickly troubleshoot alongside alerts. By advancing many key features of its platform, LogicMonitor customers can harness the full potential of their data to make informed decisions with confidence and efficiency. This approach not only streamlines operations, but also provides clarity and precision to the complexities of their IT landscape. About LogicMonitor LogicMonitor’s SaaS-based observability intelligence platform, LM Envision, helps ITOps, CloudOps, DevOps, CIOs, and business leaders gain operational visibility into and predictability across the technologies that modern organizations depend on to deliver extraordinary employee and customer experiences. LogicMonitor seamlessly enables unified observability across infrastructure, networks, clouds, containers and applications, empowering companies to focus less on troubleshooting and more on innovation.

Read More