Critical Path Security: Mitigating CVE-2024-37085 Exploitation in ESXi Hypervisors

Photo courtesy of Microsoft Microsoft researchers have recently uncovered a significant vulnerability in ESXi hypervisors, CVE-2024-37085, which is being actively exploited by several ransomware operators. This vulnerability allows attackers to obtain full administrative permissions on domain-joined ESXi hypervisors, posing a substantial threat to network security. Understanding the Vulnerability ESXi is a bare-metal hypervisor installed directly onto physical servers, providing direct access and control over underlying resources. It hosts virtual machines (VMs) that often include critical servers within a network. In a ransomware attack, gaining full administrative permissions on an ESXi hypervisor can enable threat actors to encrypt the file system, disrupt hosted servers, exfiltrate data, or move laterally within the network. The identified vulnerability involves a domain group named "ESX Admins." Members of this group are granted full administrative access to the ESXi hypervisor by default, without proper validation. Microsoft disclosed this finding to VMware through Coordinated Vulnerability Disclosure (CVD),…

0 Comments

Harnessing AI and ML in Cybersecurity: Revolutionizing Defense, Detection, and Mitigation

Artificial Intelligence (AI) and Machine Learning (ML) have become pivotal in driving transformative changes in cybersecurity. These technologies are fundamentally reshaping how we understand, detect, and mitigate complex security threats. However, incorporating AI and ML into security operations presents both challenges and opportunities. This article explores the practical applications, challenges, and opportunities of AI and ML in cybersecurity, focusing on the necessity for Extended Detection and Response (XDR), alignment with Zeek, and their impact on Industrial Control Systems (ICS). The Need for XDR in Modern Cybersecurity Extended Detection and Response (XDR) is emerging as a critical component in modern cybersecurity, driven by the integration of AI and ML. XDR enhances threat detection and response across various security layers, providing a more comprehensive security posture. It integrates data from multiple sources, offering a unified view that improves threat visibility and accelerates response times. AI and ML play a crucial role in…

0 Comments

Announcement: Virginia Kelley Promoted to CFO

  Critical Path Security is pleased to announce the promotion of Virginia Kelley from Vice President of Finance to Chief Financial Officer (CFO). Virginia has been a dedicated member of the Critical Path Security team for over five years, contributing significantly to our financial strategy and operations. With a robust background in project management and cybersecurity, Virginia brings a wealth of experience and expertise to her new role. She holds a Certificate in Purchasing, Procurement/Acquisitions, and Contracts Management from California State University-Dominguez Hills and has demonstrated exceptional skills in financial management, strategic planning, and team leadership. During her tenure as VP of Finance, Virginia played a crucial role in optimizing our financial processes and ensuring our fiscal health. Her leadership and innovative approach have been instrumental in driving our company's growth and success. Quote from Patrick Kelley and John Brandreth, Owners and Founders: "Virginia has been an invaluable asset to…

0 Comments

Director, Jared Haviland, interviewed by 11Alive News regarding CrowdStrike

ATLANTA - The recent CrowdStrike software update fiasco serves as a stark reminder of the vulnerabilities inherent in our interconnected world. Jared Haviland, the information security officer at Critical Path Security, was featured in a news interview shedding light on the extensive impact of this event and the critical lessons it offers. Most Americans were asleep when the chaos began, but in other parts of the world, people experienced the full brunt of the issue as it unfolded. The blue screen of death, a term coined for catastrophic Microsoft errors, reappeared, causing significant disruptions. Border crossings out of Canada slowed to a crawl, television stations went off the air, and essential services in hospitals, banks, and transportation were severely impacted. "Systems were going down. People couldn't do what they normally do," Haviland explained during the interview. This event underscores the risk posed by the heavy reliance on a handful of…

0 Comments