{"id":36789,"date":"2022-06-24T04:27:00","date_gmt":"2022-06-24T04:27:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/36789"},"modified":"2022-06-24T04:27:00","modified_gmt":"2022-06-24T04:27:00","slug":"us-cyber-agency-in-fresh-warning-over-log4shell-risk-to-vmware","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=36789","title":{"rendered":"US cyber agency in fresh warning over Log4Shell risk to VMware"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/06\/us-cyber-agency-in-fresh-warning-over-log4shell-risk-to-vmware.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The US government\u2019s Cybersecurity and Infrastructure Security Agency (CISA) yesterday <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-174a\">issued a new warning<\/a> over continuing exploitation of the dangerous CVE-2021-44228 Apache Log4j vulnerability \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252510860\/What-is-Log4Shell-and-why-are-we-panicking-about-it\">also known as Log4Shell<\/a> \u2013 on VMware Horizon and Unified Access Gateway (UAG) servers.<\/p>\n<p>In its advisory, the agency said threat actors were, by and large, using Log4Shell as a means to obtain initial access to organisations that did not apply available patches or workarounds when the vulnerability was exposed in December 2021.<\/p>\n<p>Since that time, it said, multiple groups have exploited Log4Shell on unpatched, public-facing Horizon and UAG servers, usually to implant loader malware with embedded executables enabling remote command and control. In at least one known case, an advanced persistent threat (APT) actor was able to move laterally within its victim\u2019s network, gain access to a disaster recovery network, and steal sensitive data.<\/p>\n<p>\u201cIf updates or workarounds were not promptly applied following <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0028.html\">VMware\u2019s release of updates<\/a> for Log4Shell in December 2021, treat all affected VMware systems as compromised,\u201d CISA said.<\/p>\n<p><a href=\"https:\/\/www.logichub.com\/\">LogicHub<\/a> founder and CEO Kumar Saurabh commented: \u201cThis vulnerability has followed a typical path \u2013 after initial discovery, there was a flurry of patching by security-conscious organisations, and then it dropped out of the news. But there are always servers that get missed, or organisations that don\u2019t keep up with patching.<\/p>\n<p>\u201cVulnerabilities can stay around for a long time and continue to be exploited as long as there are gaps. It is critical that we remain vigilant about any exploit, even if it has been checked off the list as \u2018done\u2019.\u201d<\/p>\n<p>Erich Kron, security awareness advocate at <a href=\"https:\/\/www.knowbe4.com\/\">KnowBe4<\/a>, added: \u201cPatching is a critical part of any organisation\u2019s security plan, and devices connected to the internet while unpatched, especially against a well-known and exploited vulnerability, create a serious risk for the organisations and their customers.<\/p>\n<p>\u201cWhile patching can be a challenge and can even pose a real risk of an outage if there are problems, any organisations that have internet-facing devices should have a system in place, and testing, to reduce the risk significantly. The guidance issued by CISA and CGCYBER, that unpatched VMware servers vulnerable to the Log4Shell remote code execution vulnerability should be considered already compromised, only goes to underscore the severity of this vulnerability and the capabilities of the actors that are exploiting it.\u201d<\/p>\n<p>This is not the first time that VMware\u2019s Horizon lines have been <a href=\"https:\/\/www.computerweekly.com\/news\/252515229\/Wave-of-Log4j-linked-attacks-targeting-VMware-Horizon\">singled out for particular attention<\/a>. Back in March, Sophos published intelligence warning that attackers were exploiting Log4Shell to deliver backdoors and profiling scripts to unpatched Horizon servers, laying the groundwork for persistent access and future cyber attacks, including ransomware.<\/p>\n<p>\u201cWidely used applications such as VMware Horizon that are exposed to the internet and need to be manually updated are particularly vulnerable to exploitation at scale,\u201d said Sean Gallagher, senior security researcher at Sophos.<\/p>\n<p>More in-depth technical information on some of the observed Log4Shell incidents to which CISA has rendered assistance, including indicators of compromise (IoCs) and mitigation advice, <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-174a\">can be read in full on the agency\u2019s website<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US government\u2019s Cybersecurity and Infrastructure Security Agency (CISA) yesterday issued a new warning over continuing exploitation of the dangerous CVE-2021-44228 Apache Log4j vulnerability \u2013 also known as Log4Shell \u2013 on VMware Horizon and Unified Access Gateway (UAG) servers. In its advisory, the agency said threat actors were, by and large, using Log4Shell as a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":36790,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-36789","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36789"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36789\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/36790"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}