The CISA orders US federal civilian agencies to patch or remove VMware products affected by a critical RCE vulnerability that hackers are actively exploiting
Security flaws in VMware and F5's BIG-IP are being exploited by malicious hackers. — Malicious hackers, some believed to be state-backed … Source: CISA , VMware , CISA , and CISA .
Ars Technica Dan Goodin
Related Coverage
- View article CSO
- DHS orders federal agencies to patch VMware bugs within 5 days BleepingComputer · Sergiu Gatlan
- VMware patches critical auth bypass flaw in multiple products BleepingComputer · Sergiu Gatlan
- US officials order government agencies to fix serious software bugs that hackers are exploiting CNN · Sean Lyngaas
- CISA issues rare emergency directive as ‘critical’ cyber vulnerabilities emerge Federal News Network · Jason Miller
- View article Help Net Security
- CISA: Hackers Will Quickly Start Exploiting Newly Patched VMware Vulnerabilities SecurityWeek · Eduard Kovacs
- Daily Drop (139) — Thursday, May 19, 2022 // (IG): BB //Weekly Sponsor: Unsafe Waters — PSA: Bob's Newsletter · Bob Bragg
- VMware Releases Patches for New Vulnerabilities Affecting Multiple Products The Hacker News · Ravie Lakshmanan
- CISA urges govt agencies to remove or update VMWare products Cybernews.com · Vilius Petkauskas
- VMWare vulnerabilities are actively being exploited, CISA warns Malwarebytes Labs · Pieter Arntz
- CISA calls VMWare vulnerabilities ‘unacceptable risk’ in emergency order to feds SC Media · Derek B. Johnson
- Patch your VMware gear now - or yank it out, Uncle Sam tells federal agencies The Register · Simon Sharwood
- US orders federal agencies to update or remove some VMware products iTnews · Raphael Satter
- CISA Orders Agencies to Mitigate VMWare Vulnerabilities Under Deadline Nextgov · Mariam Baksh
- CISA Warns That Hackers Are Exploiting a Flaw in F5's Big-IP PCMag · Nathaniel Mott
- CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ org The Record · Jonathan Greig
- CISA to Federal Agencies: Patch VMWare Products Now or Take Them Offline Dark Reading
- CISA directs civilian agencies to patch ‘critical’ VMware vulnerabilities FedScoop · Billy Mitchell
- U.S. orders federal agencies to update or remove certain VMWare products from networks Reuters · Raphael Satter
- VMSA-2022-0014 … 1. Impacted Products — VMware Workspace ONE Access (Access) VMware
- EMERGENCY DIRECTIVE 22-03 MITIGATE VMWARE VULNERABILITIES CISA
- CISA Issues Emergency Directive and Releases Advisory Related to VMware Vulnerabilities CISA
- Alert (AA22-138B) — Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control CISA
- Daily Intel Brief Overt Operator
Discussion
-
@kimzetter
Kim Zetter
on x
🚨"assume compromise** “for all instances of impacted VMware products that are accessible from the internet: Assume compromise, immediately disconnect from the production network, and conduct threat hunt activities as outlined in CISA CSA available here: https://www.cisa.gov/...”
-
@vickerysec
Chris Vickery
on x
Emergency Directive from CISA (gov). Patch your VMWare deployments or disable them. Dangerous vulnerabilities exist. Update now- https://www.cisa.gov/... https://twitter.com/...
-
@ericgeller
Eric Geller
on x
CISA's worried enough about two VMware vulnerabilities that it's giving agencies 5 days to apply the new updates: https://www.cisa.gov/...
-
@bad_packets
Bad Packets
on x
CVE-2022-22972 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. https://www.vmware.com/...
-
@vmwaresrc
VMware Sec Response
on x
Today we released a new Critical Severity VMware Security Advisory. Check out https://www.vmware.com/.... #VMware