< ciso
brief />
Tag Banner

All news with #broadcom tag

26 articles

SE Labs launches PIVOT test for vendor defences

🛡️ SE Labs has launched a six-month testing program called PIVOT to evaluate how effectively cybersecurity vendors defend against major nation-state and criminal threat groups. The program runs real-world attack chains from July through October in SE Labs’ London test lab and will publish verified results in January 2027. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks and Sophos. Gartner and Forrester analysts will independently verify the findings before publication.
read more →

CISA: Critical VMware vCenter RCE Now Exploited

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that ransomware gangs are now exploiting a critical VMware vCenter vulnerability (CVE-2026-59310) patched by Broadcom on July 29. The flaw is a directory traversal issue in the vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code; Broadcom urged emergency patching. Security firms reported widespread compromises and CISA added the CVE to its KEV Catalog, ordering rapid remediation across government systems.
read more →

Critical VMware Workstation and Fusion Fixes Released

🔒 Broadcom has released patches for two vulnerabilities in VMware Workstation and Fusion, including a critical integer-overflow bug (CVE-2026-59346) that could allow arbitrary code execution from a privileged local VM user. A second fix addresses a stack-based buffer overflow in HGFS (CVE-2026-59347). Both flaws require the attacker to have local administrative privileges on the VM and have been fixed in VMware Workstation 26H1u1 and Fusion 26H1u1. Broadcom credited external researchers for reporting the issues and noted no current evidence of in-the-wild exploitation, though recent attacks on VMware products increase urgency.
read more →

Broadcom issues patches for multiple VMware flaws

🔒 Broadcom has released patches addressing five vulnerabilities across multiple VMware products, with three rated as critical. Affected products include vCenter, ESX, Workstation, Fusion, and various cloud and telco platforms. Issues range from authentication bypass and out-of-bounds write enabling remote code execution to syslog-related arbitrary code execution. Administrators should apply fixes from Broadcom's advisory promptly.
read more →

Three critical VMware flaws permit authentication bypass

🔒 Broadcom issued security updates for multiple VMware products, including ESX, vCenter, Workstation, and Fusion, addressing three critical vulnerabilities. The highest-severity issues include an authentication bypass (CVE-2026-59309) and a directory traversal allowing code execution (CVE-2026-59310) in vCenter. Additional fixes cover VMXNET3 out-of-bounds write, out-of-bounds read, and insufficient logging flaws in ESX and related products. Broadcom reports no evidence of in-the-wild exploitation and has released patches across VMware Cloud Foundation, vSphere, Workstation, and Fusion versions.
read more →

GodDamn ransomware uses signed PoisonX kernel driver

🛡️ GodDamn is a newly observed ransomware family that employs a signed PoisonX kernel driver and a Symantec‑masquerading user‑mode tool to disable endpoint protections. First spotted on May 21, 2026, Broadcom's Threat Hunter Team attributes the lineage to the Hyadina developer and links it to earlier Beast and Monster variants. Attacks used AnyDesk, PsExec, credential harvesters and lateral movement to compromise multiple hosts before deploying the encryptor.
read more →

Mistic backdoor linked to KongTuke access broker

🛡️ Broadcom, Symantec, and Carbon Black report a stealthy backdoor named Mistic (aka MLTBackdoor) deployed since April 2026 across insurance, education, IT, and professional services. The implant runs in memory via DLL side-loading of trusted tooling, includes a kill switch, and was dropped alongside ModeloRAT, a Python RAT tied to the KongTuke access broker. Analysts say the activity appears opportunistic and linked to ClickFix delivery chains and ransomware-related actors.
read more →

Cloud Network Insights: Cross-Cloud Network Observability

🔍 Cloud Network Insights is now generally available as a Google Cloud-native solution, delivered in partnership with Broadcom AppNeta, to provide end-to-end visibility across multi-cloud and hybrid networks. It uses lightweight Monitoring Points and active synthetic probes to measure RTT, packet loss, jitter, and application-level metrics like DNS and page-load times. The service integrates with Cloud Monitoring, Cloud Logging, and supports OpenTelemetry, enabling proactive alerting, SLA validation, and rapid root-cause analysis.
read more →

Protecting Data During Hypervisor Migration Away from VMware

🔒 Broadcom’s acquisition of VMware has accelerated migrations to alternatives such as Microsoft Hyper‑V, Azure Stack HCI, Nutanix AHV, Proxmox VE and KVM, but switching hypervisors introduces complex risks around disk formats, drivers, networking models and snapshot behavior. Successful transitions depend not on conversion tools but on verified, restorable, application‑consistent backups and rehearsed recovery drills performed before cutover. A unified, platform‑agnostic cyber protection approach with immutability, tightened RBAC and an off‑site copy reduces downtime, rollback risk and long‑term vendor lock‑in.
read more →

CISA Adds VMware Aria Operations RCE to KEV Catalog

⚠️ CISA has added a high‑severity VMware Aria Operations flaw, CVE-2026-22719, to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation; the issue is an unauthenticated command injection that can allow arbitrary command execution and potential remote code execution. Broadcom released fixes for VMware Cloud Foundation, vSphere Foundation 9.0.2.0 and Aria Operations 8.18.6, and provided a shell-script workaround (aria-ops-rce-workaround.sh) for appliance nodes. Public details of in‑the‑wild exploitation and attribution remain scarce. Federal civilian agencies must apply the fixes by March 24, 2026.
read more →

CISA Flags VMware Aria Operations RCE as Exploited

🚨 CISA has added a VMware Aria Operations command injection flaw (CVE-2026-22719) to its Known Exploited Vulnerabilities catalog and is treating the issue as exploited in attacks. Broadcom says it is aware of reports of exploitation but cannot independently confirm them. VMware released patches on February 24 and provided a temporary workaround script (aria-ops-rce-workaround.sh) that disables vulnerable migration components; administrators should apply the updates or the workaround immediately.
read more →

VMware patches Aria Operations command injection flaw

🔒Recent patches from VMware address several high- and medium-risk vulnerabilities in Aria Operations, Cloud Foundation, and Telco Cloud products. The most serious, CVE-2026-22719, is an unauthenticated command injection that could lead to remote code execution but requires support-assisted product migration to be exploitable, so it is rated high rather than critical. Broadcom recommends upgrading to Aria Operations 8.18.6 and applying corresponding updates for VMware Cloud Foundation and Telco Cloud components to mitigate these issues.
read more →

CISA: VMware ESXi Flaw Now Used in Ransomware Attacks

🔒 CISA confirmed ransomware gangs are exploiting a high-severity VMware ESXi sandbox escape (CVE-2025-22225) patched by Broadcom in March 2025 alongside related fixes. The vulnerability permits an attacker with privileges in the VMX process to trigger an arbitrary kernel write and escape the virtual machine sandbox. Organizations are urged to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue affected products if mitigations are unavailable.
read more →

CISA Adds Actively Exploited VMware vCenter Flaw Patch Urged

⚠️ CISA has added CVE-2024-37079, a critical heap overflow in Broadcom VMware vCenter's DCE/RPC implementation, to its Known Exploited Vulnerabilities catalog citing evidence of active exploitation. The flaw (CVSS 9.8) can enable remote code execution via a crafted network packet; Broadcom released fixes in June 2024 alongside CVE-2024-37080, with related patches issued in September 2024. Broadcom confirms in‑the‑wild abuse and Federal civilian agencies must update to the latest vCenter release by February 13, 2026.
read more →

CISA Adds VMware vCenter CVE to KEV Catalog January 2026

⚠️ CISA has added CVE-2024-37079, an out-of-bounds write in VMware vCenter Server (Broadcom), to the Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This class of memory-corruption flaw is a common attacker vector and poses significant risk to the federal enterprise. Under BOD 22-01, FCEB agencies must remediate cataloged vulnerabilities by the required due date; CISA urges all organizations to prioritize timely remediation and to reduce exposure to active threats.
read more →

High-severity Broadcom WiFi bug enables 5GHz DoS risk

⚠️ Researchers at Black Duck's Cybersecurity Research Center found a high-severity flaw in Broadcom WiFi chipset software that lets an unauthenticated attacker within radio range disable all clients on the 5 GHz band by sending a single crafted 802.11 frame. The behavior was observed while testing ASUS routers but was traced to Broadcom's chipset code rather than router firmware. Broadcom issued a patched software build to customers and ASUS released firmware updates, although a comprehensive list of affected devices has not been published. Recommended mitigations include segmenting wireless networks, auditing legacy access points, and prioritizing firmware updates based on business criticality.
read more →

Chinese-linked actors exploit VMware ESXi via SonicWall VPN

🔍 Huntress says Chinese-speaking threat actors used a compromised SonicWall VPN appliance in December 2025 to deploy a multi-stage exploit against VMware ESXi, leveraging three zero-day vulnerabilities disclosed by Broadcom in March 2025 (CVE-2025-22224/22225/22226). The toolkit includes an orchestrator dubbed MAESTRO, an unsigned kernel driver loaded via KDU, and a VSOCK-based ELF backdoor called VSOCKpuppet. The attack chain enabled VM-to-hypervisor escapes, remote control of ESXi hosts over VSOCK port 10000, and file transfer capabilities from guest VMs, all of which were halted by Huntress before a suspected ransomware stage could complete.
read more →

CISA Flags VMware Tools Zero-Day in KEV Catalog; Exploited

🛡️ CISA has added the high-severity flaw CVE-2025-41244, impacting Broadcom VMware Tools and VMware Aria Operations, to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The bug (CVSS 7.8) allows a malicious local, non-administrative user with VM access and SDMP enabled to escalate privileges to root on the same VM. Broadcom-owned VMware released a patch last month, but NVISO Labs says the zero-day was exploited in the wild since mid-October 2024 and attributes activity to a China-linked actor tracked as UNC5174. Federal civilian agencies must implement mitigations by November 20, 2025.
read more →

CISA orders federal patch for VMware Tools privilege bug

⚠️ CISA has ordered Federal Civilian Executive Branch agencies to remediate a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools (CVE-2025-41244), patched by Broadcom in October 2024. The flaw enables a local, non-administrative user on a VM to escalate privileges to root when Aria Operations’ SDMP is enabled or when VMware Tools runs in credential-less mode. Agencies must patch within three weeks under BOD 22-01; CISA also urges all organizations to prioritize mitigations or discontinue affected products if no fix is available.
read more →

CISA Adds Two CVEs to Known Exploited Vulnerabilities

🔔 CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2025-24893 (XWiki Platform eval injection) and CVE-2025-41244 (Broadcom VMware Aria Operations and VMware Tools privilege-defined unsafe actions). Evidence indicates active exploitation and substantial risk to the federal enterprise. Under BOD 22-01, affected FCEB agencies must remediate by required due dates. CISA urges all organizations to prioritize timely remediation as part of routine vulnerability management.
read more →