Comunidad Pen7esting
3.61K subscribers
513 photos
40 videos
142 files
5.09K links
Download Telegram
VMSA-2022-0029

CVSSv3 Range: 3.3
Issue Date: 2022-11-29

CVE(s): CVE-2022-31693

Synopsis:
VMware Tools for Windows update addresses a denial-of-service vulnerability (CVE-2021-31693)

https://www.vmware.com/security/advisories/VMSA-2022-0029.html
👍1
"72% de las organizaciones siguen siendo vulnerables a Log4j" Tenable
https://blog.segu-info.com.ar/2022/12/72-de-las-organizaciones-siguen-siendo.html
VMSA-2021-0025.5

CVSSv3 Range: 7.1
Issue Date: 2021-11-10
Updated On: 2022-12-08
CVE(s): CVE-2021-22048

Synopsis:
VMware vCenter Server updates address a privilege escalation vulnerability (CVE-2021-22048)

Impacted Products
VMware vCenter Server (vCenter Server)
VMware Cloud Foundation (Cloud Foundation)

Introduction
A privilege escalation vulnerability in VMware Center Server was privately reported to VMware. Workarounds are available to remediate this vulnerability in the affected VMware products.

https://www.vmware.com/security/advisories/VMSA-2021-0025.html
▶️ BlackMagic ransomware y el negocio del robo de datos

Un nuevo grupo de ransomware llamado BackMagic ha sido identificado durante ejercicios rutinarios de threat-hunting por CRIL (Cyble Research and Intelligence Labs)

https://unaaldia.hispasec.com/2022/12/blackmagic-ransomware-y-el-negocio-del-robo-de-datos.html
Abuso de SQL basado en JSON malformados para saltear WAF
https://blog.segu-info.com.ar/2022/12/abuso-de-sql-basado-en-json-malformados.html