News

National Security Agency targets virtual workspace vulnerability

A recently released National Security Agency (NSA) Cybersecurity Advisory maintains Russian entities have exploited virtual workspace vulnerability in VMware products to access protected data on affected systems.

The advisory details the importance for National Security System (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) system administrators to apply vendor-provided patches, as soon as possible, to impacted VMware identity management products.

Authorities indicated the process involving a suspected compromise focuses on checking server logs and authentication server configurations, in addition to applying the product update. If an immediate patch is not possible, system administrators would apply mitigations detailed in the advisory to reduce the risk of exploitation, compromise, and attack.

The advisory indicates password-based access to the web-based management interface of the device is required to exploit the vulnerability, adding using a strong and unique password lowers the risk of exploitation.

Additionally, officials said the risk is decreased if the web-based management interface is not accessible from the internet. It is critical when running products that perform authentication that the server and all the services that depend on it are properly configured for secure operation and integration

If integrating authentication servers with Active Directory Federation Services (ADFS), NSA recommends following Microsoft’s best practices, specifically related to securing security assertion markup language (SAML) assertions and requiring multi-factor authentication.

Douglas Clark

Recent Posts

New Raytheon advanced ground system gives U.S. advanced warning for space-based missiles

Thanks to work by Raytheon, an advanced new ground system for space-based missile warning recently…

11 hours ago

FBI Report: Older population hit by more than $3.4B in scam losses in 2023

According to the latest Elder Fraud Report from the Federal Bureau of Investigation (FBI), 2023…

11 hours ago

Protect and Serve Act would elevate the harming or attempted harm of law enforcement to a federal crime

Following the deaths of four police officers while executing an arrest warrant in North Carolina…

1 day ago

U.S. Reps. Steil, Dean introduce legislation to target human trafficking among other countries

As a way to crackdown on human trafficking, two U.S. representatives recently introduced the Exposing…

1 day ago

DoD challenge brings opportunities for nine new ideas in talent management

A Department of Defense (DoD) 2040 Task Force (D2T) challenge on talent management innovation drew…

4 days ago

TSA publishes final rule on Flight Training Security Program improvements

For the first time since its creation in 2004, the Transportation Security Administration’s (TSA) Flight…

4 days ago

This website uses cookies.