SprySOCKS Backdoor Malware and Vali Cyber’s ZeroLock® Defense

SprySOCKS malware is a new Linux-targeted backdoor that has combines elements from Trochilus (a Windows backdoor) and the Socket Secure (SOCKS). This threat is orchestrated by the China-linked Earth Lusca group, which has relentlessly targeted government entities...

VMware Aria exploit Neutralized by Vali Cyber’s ZeroLock®

VMware Aria Operations for Networks (formerly vRealize Network Insight) is vulnerable to a critical severity authentication bypass flaw that could allow remote attackers to bypass SSH authentication and access private endpoints. Join Nathan Montierth, Vali...

Lockdown Rules

Using ZeroLock® lockdown rules to prevent ESXi attacks

CLI-MFA

ZeroLock® prevents unauthorized access with CLI-MFA

GameOver(lay) Gets Destroyed by Vali Cyber’s ZeroLock®

CVE-2023-2640 and CVE-2023-32629 are two easy-to-exploit privilege escalation vulnerabilities in the OverlayFS module in Ubuntu that affect 40% of Ubuntu cloud workloads. Cleverly nicknamed gameOver(lay), Vali Cyber’s ZeroLock can both remediate as well as...

AI Kills Hash Based Detections

Whether it is ChatGPT, GPT4, Bard, or any of the other AI systems competing for public attention, these systems represent a significant leap forward in Malware as a Service (MaaS) capabilities. While it is true there are supposed to be guard rails that prevent...

A Brief History of NAS Ransomware

It is no secret that NAS devices are frequently targeted by ransomware attacks, and for good reason. Critical data is often stored on devices. Furthermore, NAS devices typically store large amounts of data. NAS devices run Linux operating systems, so malware written...