VMware has released a security update to address multiple vulnerabilities in Aria Operations for Networks (Formerly vRealize Network Insight). The vulnerabilities were evaluated to fall within the critical severity range, as a malicious actor with network access may be able to perform a command injection attack resulting in remote code execution. Patches have been made available to remediate the vulnerabilities found in VMWare products.
CISA encourages users and administrators to review VMware Security Advisory VMSA-2023-0012 and apply the necessary updates.

HEAVYGRAM: Puerta Trasera de Vigilancia Abusa de la API de Telegram como C2
Investigadores de seguridad han detallado las operaciones de “HEAVYGRAM”, una sofisticada puerta trasera para Windows activa desde otoño de 2023. Este malware de vigilancia está


