Federal Agencies Told to Act Quickly to Turn Back Cyberthreat

May 18, 2022 by Dan McCue
Federal Agencies Told to Act Quickly to Turn Back Cyberthreat

WASHINGTON — The entity charged with protecting federal agencies from bad cyber actors issued a rare emergency directive Thursday, warning they should quickly take steps to protect themselves from vulnerabilities found in VMware.

VMware is a cloud computing and virtualization technology company headquartered in Palo Alto, California. It is primarily known for creating a platform for the virtualization of IT infrastructure as an alternative to having dedicated hosts.

According to the Cybersecurity and Infrastructure Security Agency, vulnerabilities found in five of the company’s products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager (vRSLCM) have placed federal networks and systems at immediate risk of a cyber intrusion.

It goes on to say the problem is a vulnerability that permits attackers to gain deep access into computer systems without the need to authenticate. 

“These vulnerabilities pose an unacceptable risk to federal network security,” said CISA Director Jen Easterly in a written statement. 

“CISA has issued this Emergency Directive to ensure that federal civilian agencies take urgent action to protect their networks. We also strongly urge every organization — large and small — to follow the federal government’s lead and take similar steps to safeguard their networks.”

The federal civilian executive branch agencies to whom the warning applies include every executive branch department — Energy, Commerce, Homeland Security, Treasury, Transportation, etc. — as well as “smaller” agencies like the board of governors of the Federal Reserve, the Federal Trade Commission, the National Transportation Safety Board, the Environmental Protection Agency and the Nuclear Regulatory Commission.

Even the Peace Corps could be vulnerable to the threat.

On its website CISA said VMware first discovered new vulnerabilities in early April and released an update to address the problem.

Unfortunately, the agency said, “threat actors were able to reverse engineer the update and begin exploitation of impacted VMware products that remained unpatched within 48 hours of the update’s release.”

Earlier today, VMware released an update for two new vulnerabilities. 

“Based on the above, CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products,” the agency said. “Exploiting the above vulnerabilities permits attackers to trigger a server-side template injection that may result in remote code execution; escalate privileges to ‘root’; and obtain administrative access without the need to authenticate.

“CISA has determined that these vulnerabilities pose an unacceptable risk … and require emergency action,” the agency said.

Dan can be reached at [email protected] and @DanMcCue


A+
a-
  • cyber intrusion
  • cybercrime
  • Cybersecurity and Infrastructure Agency
  • federal agencies
  • VMware
  • In The News

    Health

    Voting

    Cybersecurity

    July 18, 2023
    by Tom Ramstack
    Congress Told AI Holds Great Risks and Benefits for US Military

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it... Read More

    WASHINGTON — Artificial intelligence experts warned Tuesday during a congressional hearing of ominous dangers for the United States if it falls behind in developing the technology but a bright future by taking the lead. One of the greatest risks would be defending against a foreign enemy... Read More

    July 17, 2023
    by Dan McCue
    DOE, Sandia Labs to Host Bioenergy Cybersecurity Workshop

    WASHINGTON — The Department of Energy’s Bioenergy Technologies Office is partnering with the Sandia National Laboratories in New Mexico to... Read More

    WASHINGTON — The Department of Energy’s Bioenergy Technologies Office is partnering with the Sandia National Laboratories in New Mexico to present a virtual workshop on the cybersecurity risks in biofuel and bioproduct manufacturing. The Microsoft Teams session will be held on Sept. 11 from 1 p.m.... Read More

    May 17, 2023
    by Tom Ramstack
    US Prosecutors Indict Russian for Ransomware Attacks

    WASHINGTON — The Justice Department indicted a Russian citizen Tuesday prosecutors accused of ransomware campaigns that netted him and his... Read More

    WASHINGTON — The Justice Department indicted a Russian citizen Tuesday prosecutors accused of ransomware campaigns that netted him and his conspirators about $200 million in stolen payments. The victims were mostly in the United States. They included nonprofits, hospitals and police departments, such as the Washington,... Read More

    Congress Eyes New Rules for Tech: What's Under Consideration

    WASHINGTON (AP) — Most Democrats and Republicans agree that the federal government should better regulate the biggest technology companies, particularly... Read More

    WASHINGTON (AP) — Most Democrats and Republicans agree that the federal government should better regulate the biggest technology companies, particularly social media platforms. But there is very little consensus on how it should be done. Should TikTok be banned? Should younger children be kept off social... Read More

    April 19, 2023
    by Tom Ramstack
    House Panel Demands Stronger Cybersecurity in Wake of Health Records Breach

    WASHINGTON — A month after cyberthieves looted a local health insurance database making off with the sensitive personal records of... Read More

    WASHINGTON — A month after cyberthieves looted a local health insurance database making off with the sensitive personal records of members of Congress and thousands of others, a member of a congressional panel looking into the incident on Wednesday declared "that may not be the full... Read More

    March 16, 2023
    by Tom Ramstack
    SEC Seeks Court Order in Investigation of Chinese Cyberattack

    WASHINGTON — A Securities and Exchange Commission investigation of a Chinese cyberattack is being opposed by some of Washington, D.C.’s... Read More

    WASHINGTON — A Securities and Exchange Commission investigation of a Chinese cyberattack is being opposed by some of Washington, D.C.’s biggest law firms. The SEC says it is trying to investigate the extent of 2020 cyberattacks in the United States, such as the one that penetrated... Read More

    News From The Well
    scroll top