HomeSecurityVMware: also affected by SolarWinds breach

VMware: also affected by SolarWinds breach

The most recent of the companies affected by the SolarWinds breach is VMware, which acknowledged the incident but stated that it has not suffered any further intrusions .

vmware

The company said the hackers made no attempt to further exploit their access after deploying the backdoor, which has been dubbed Sunburst or Solarigate.

“While we have identified limited instances of the vulnerable SolarWinds Orion software in our internal environment, our own internal investigation has not revealed any evidence of exploitation,” the company said in a statement.

VMware also disputed media reports that a vulnerability in several of its products, reported by the NSA, was used as an additional attack vector in addition to the SolarWinds Orion platform to compromise high -profile targets.

The vulnerability identified as CVE 2020-4006 was publicly disclosed in November and patched in early December.

The National Security Agency (NSA) issued an advisory three days later, after addressing the security flaw, saying that Russian hackers exploited the vulnerability to gain access to protected data on affected systems.

VMware: also affected by SolarWinds breach

However, VMware denied that CVE-2020-4006 was used as an additional method to compromise government services during the recent surge in attacks.

While CVE-2020-4006 has not been abused in any of the breaches related to the SolarWinds supply chain attack, VMware says all customers should apply the security updates for affected products.

"VMware encourages all customers to apply the latest product updates, security fixes, and mitigations available for their specific environment," the company said.

FireEye is currently tracking the threat actor behind the SolarWinds supply chain attack , while Volexity has linked the activity to a threat known as Dark Halo .

Dark Halo operators are behind multiple malicious campaigns carried out between 2019 and July 2020, successfully targeting and compromising the same US-based think tank three times in a row.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS