Skip to content

Applying CIS Benchmarks to Your Linux OS With Hardened Images

About Perforce
The best run DevOps teams in the world choose Perforce. Perforce products are purpose-built to develop, build and maintain high-stakes applications. Companies can finally manage complexity, achieve speed without compromise, improve security and compliance, and run their DevOps toolchains with full integrity. With a global footprint spanning more than 80 countries and including over 75% of the Fortune 100, Perforce is trusted by the world’s leading brands to deliver solutions to even the toughest challenges. Accelerate technology delivery, with no shortcuts.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

IT Event Console: Centralize Logs, Correlate Alerts, and Detect Incidents

When you’re just starting out, you might picture yourself managing your IT infrastructure like Tom Cruise in Minority Report—key information projected in front of you, predicting events before they happen, controlling everything at the speed of thought with cinematic gestures on some kind of holographic computer. But in real life, that infrastructure looks more like a Frankenstein’s monster: a mashup of different technologies, open and closed source tools, various applications and protocols stitched together however possible. We may never be Tom Cruise, but we can get a little closer to his character’s futuristic setup with an IT event console.
Today, one of the biggest challenges in technology management is handling the massive volume of scattered events across complex environments—systems that were never really designed to work together. Efficient management is impossible without unification, and that’s where an IT event console comes in. In this post, we’ll explore everything you need to know: what it is, how it works, benefits, use cases, and more.

What Is an IT Event Console?

An IT event console (not to be confused with the Windows Event Viewer) is a tool designed to add, correlate, and prioritize real-time events coming from multiple sources—servers, networks, applications, IoT devices, and more.
Its main goal is to optimize operational response by filtering out the “noise” and enabling technical teams to act quickly on critical incidents. This ensures systems continue running smoothly and, in the event of issues, guarantees immediate action to minimize downtime, system underperformance, or any other disruption.
Think of the IT event console as a command center for incidents, where all significant events can be monitored and controlled. In fact, at Pandora FMS we call our Metaconsole the Command Center—the crown jewel that lets you feel a bit like Tom Cruise (minus the money, success, looks, and fame) as you manage hundreds of thousands of devices and all their associated events from a single place.
It’s important to note that an event console is not the same as a SIEM (Security Information and Event Management) system. A SIEM focuses on cybersecurity and compliance, whereas an IT event console serves as a broader command hub.
With the event console, you’re ensuring everything is running optimally in terms of performance and service. Yes, it includes security events—but it goes beyond that. If a SIEM is your police detective, the IT event console is more like a super-engineer watching over the entire system for critical operational issues.

What Types of Events Are Managed in IT

When we talk about events in IT, we’re referring to signals that indicate something is happening in our operations or security. And, as life tends to go, those occurrences aren’t usually good—they range from minor failures to critical threats (like something going offline, underperforming, or coming under attack).
As we’ll explore in more detail, these signals are uncovered by aggregating, analyzing, and correlating logs of all kinds—network, system, application, etc. The key point is that an IT event console’s job is to notify us about critical events—not every little thing that happens. Otherwise, we’d just be trading blindness for madness (well, more madness) from constant alerts.
So, what makes an event critical?

  • It impacts operations. For example, the server used by your sales team to log deals goes down, and they can’t work; or the POS system stops working and you’re losing money by the minute.
  • It prevents regulatory compliance. Like with GDPR or PCI DSS, where violations could lead to hefty fines.
  • It poses a security threat. An exploited vulnerability could put your data at risk.
  • It has a certain scale, importance, or recurrence. A one-time CPU spike or a system reboot that never repeats might not be considered critical.

How an IT Event Console Works

To display key information, the event console must work behind the scenes with logs from networks, systems, security, and applications. It generally follows these steps:

  • Log Collection. This can happen via agents installed on systems, EDRs, direct log ingestion, or any other telemetry method. The goal is to gather everything in one central place.
  • Normalization and Compatibility. Collecting data isn’t enough—thanks to the “Frankenstein effect” of most infrastructures, you’ll have a Tower of Babel of standards, formats, and behaviors. That’s why we need to unify and interpret them all, like using Star Trek’s universal translator, normalizing the data so it can be processed and correlated.
  • Automatic Filtering and Validation. You’ll receive thousands of events, but you only want the critical ones. It’s time to sift through them so the console only shows what matters. However, there’s another step that must run in parallel.
  • Event Correlation. Using predefined rules, patterns, and thresholds, we combine data to retrieve insights beyond the sum of the parts. For example, a connection to a “trusted” external domain like Google Drive might not seem suspicious on its own and wouldn’t trigger a critical alert. But if we correlate it with logs showing large, encoded, regular outbound traffic during off-hours from certain endpoints, it could indicate potential data exfiltration.
  • Operational Visualization and Alert Generation for Critical Events. Whether it’s a single-point alert (like a server going down with no clear reason) or a correlated analysis (like realizing that server crashes happen at specific times because sales teams are uploading massive amounts of data—and, unfortunately, you assigned that task to an old Raspberry Pi), the console delivers actionable insight.

Key Benefits for IT Management

Reading the above, it’s easy to see the advantages an IT event console brings to your daily operations, such as:

  • Centralized Visibility of What Matters in Your Infrastructure. Making the old dream come true: your chair feels more like the captain’s seat on the Enterprise, with all critical systems visible and running as one under your command. Though, granted—no Minority Report hand gestures or Star Trek-style voice commands… yet.
  • Reduction of False Positives. Say goodbye to operational “noise” with correlation rules that group related events (triggering a single alert instead of a hundred), filter out irrelevant data (like scheduled reboots), or prioritize based on impact—like detecting an abnormal spike in encrypted outbound traffic, which might indicate a serious security breach.
  • Cross-Team Coordination. Security, performance, support… the console not only unifies tools, but also aligns people and departments. Now everyone has access to the same key data to make optimal decisions together, rather than each team fighting its own battle in isolation.
  • Regulatory Compliance and Auditing. Supporting compliance with GDPR, NIS2, ISO 27001, or whatever standard applies through: centralized log maintenance ready for audit, automated and customizable reporting (with advanced options like those from Pandora FMS), and proactive monitoring of critical requirements—such as MFA for sensitive data, and alerts if accessed without it.

Real-World Use Cases

An IT event console is not just a theoretical concept for optimal infrastructure management—it’s a practical tool conceived to solve problems and make your life easier, as shown in the following real-world use cases.

Hybrid Infrastructures (Cloud and On-Premises)

A mixed architecture is quite common today, using SaaS services like Salesforce or Office 365 alongside clouds such as AWS and on-premise servers (for sensitive data or backups, for example). So how does an IT event console help in these scenarios?
To begin with, it can collect and analyze local Syslog data, AWS API metrics, and error logs from Office 365 together. Imagine that one day your users complain they can’t work with Microsoft’s suite—but why? Thanks to integration and correlation behind the scenes, the console might reveal whether the issue is local network latency, a cloud API timeout error, or something else entirely.
Let’s go back to our sales team for a moment—those who swapped the old Raspberry Pi setup for Salesforce. They now input their data there, but for some reason, it’s not syncing properly with the ERP system, which we’re still hosting on-premises. The console could detect, for instance, that the local ERP server’s CPU is hitting 100% during certain hours, alongside a wave of 504 timeout errors in the API. That tells us Salesforce isn’t to blame—we’re simply under-provisioned on the local server side, and it’s time to scale up.

SOC Environments (Threat Detection and Response)

While the IT event console isn’t limited to cybersecurity, it certainly includes it—because of how critical security has become. EDRs and firewalls generate massive volumes of alerts for potential breaches, but many are noise or false positives.
The console helps by correlating different types of events to identify which ones represent real threats. For example, a phishing campaign is detected via inbound email scanning. Then, an EDR on a user’s endpoint triggers a malicious process alert, and suspicious IP traffic is flagged showing C2 (command and control) behavior.
This global, correlated view confirms that some phishing emails slipped through, and—one of the few universal truths—there’s always a user eager to click where they shouldn’t.
The console can alert the SOC team, and depending on your defense systems, automated responses may already be in play (like blocking the malicious IP or isolating the user’s laptop with the itchy trigger finger).

Distributed Monitoring (of Endpoints, Networks, and Services)

Today’s companies have employees working from the office, from home, remotely across countries, with all kinds of servers—both SaaS and on-premises—as well as IoT devices. Good luck trying to manually monitor each one of them.
An IT event console makes it possible to scan thousands of devices in just minutes (for instance, Pandora FMS’s Metaconsole can handle hundreds of thousands centrally), allowing you to see how everything is performing and to set thresholds and alerts for anomalies across systems—such as unscheduled reboots, offline statuses, or unusual CPU spikes.

How Pandora FMS Handles It

One of Pandora FMS’s greatest strengths is providing that feeling of control (because we’ve experienced the stress and frustration of not having it) and doing the heavy lifting of collecting, normalizing, and processing key information from logs, to present you with only the critical events.
The crown jewel here is the Metaconsole, which I’ve briefly mentioned before, called the Command Center. It allows you to monitor as many infrastructure components as needed, showing color-coded alerts at a glance based on severity.
Within its interface, there’s also an event management menu. When accessed, you’ll see a color-coded list again, helping you quickly identify severity levels and what they correspond to (blue for maintenance, green for normal, yellow for warning, red for critical, etc.). This provides total control and management capability, allowing you to filter by time, status, take action, and more.
Likewise, you can access the alerts section to review their type, generate reports, or build custom dashboards that allow you to instantly see the status of what matters most—based on your operational needs, not those dictated by the console vendor.
Within this command center, you can also create so-called visual consoles. Thanks to a wizard-based system, you can easily add elements or services, building exactly what you need to take full control of your operations—your reins, your horse.
And it’s all done through an intuitive and visually appealing interface. But as the best stories say, beauty lies within—and that’s true here too. Because the strength of Pandora FMS isn’t just skin deep.
Behind the scenes, correlation and automation rules work tirelessly, built on best practices. Logs in various formats are collected and unified, and integration with ITSM and SIEM tools ensures that alerts, security actions, and tickets are synchronized and working in harmony.

Best Practices for Implementing an IT Event Console

Let’s remember that the purpose of the console is not to report everything that happens, but only what truly matters. To achieve that, these best practices will help:

  • Design correlation rules. Create rules based on real-world patterns and historical data, avoiding ambiguity and fine-tuning thresholds to minimize false alarms.
  • Prioritize critical events. Classify events by impact/urgency to focus on those that threaten revenue, operational continuity, or security.
  • Automate without overloading. Only automate predictable tasks, maintaining human oversight for complex decisions and monitoring the effectiveness of automated scripts.
  • Integrate with operational workflows. Connect the console with ticketing and communication tools—like Pandora FMS does—to unify alerts, actions, and follow-up, eliminating fragmented knowledge silos or manual steps like creating tickets.
  • Start small. It’s easy to get carried away by the power and control of an IT event console, but it’s better to start gradually—you can always add more rules and interactions over time.

All this will help you find the needle of what matters in the haystack of thousands of scattered, heterogeneous logs.
Optimal management always begins with control, and that control starts with the proper handling of information and analysis to bring what matters to light. The key to all these doors is an IT event console—one that alerts you to what’s important without overwhelming you with noise in a context that already has too much of it.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Identity Security Intelligence: From Insight to Attack Prevention

What to Expect in this Blog:
In Part 2 of the Identity Security Intelligence series, we move beyond discovery to the real objective: prevention. You’ll learn how to operationalize identity intelligence through dynamic, automated controls enforcing least privilege, governing privileged access, and detecting risky behavior to proactively reduce your identity attack surface.

In Part 1 of this series of blogs on Identity Security Intelligence, we explored why Identity Discovery is the critical first step in understanding and managing your organization’s modern attack surface. But discovery alone isn’t enough. Knowing which identities exist and what they can access sets the stage. The real impact comes when you act on that intelligence—by putting the right security controls in place to govern identities, enforce least privilege, and proactively reduce identity-related risk.

Welcome to the enforcement phase of Identity Security Intelligence (ISI).

From Discovery to Defense: Why Controls Are the Next Frontier

Once you’ve surfaced every human, non-human (NHI), machine, and service identity,: and mapped their entitlements across environments, – the next question becomes: what do you do with that knowledge?

This is where many organizations hit a wall. The gap between insight and action is often bridged manually, with fragmented processes and point-in-time audits. But attackers don’t wait for your next quarterly review.

To operationalize identity intelligence, organizations need a controls framework that isare:

  • Dynamic – Adapts to changing roles, environments, and behaviors.
  • Automated – Scales with cloud-native architectures and ephemeral workloads.
  • Context-aware – Informed by the risk posture of each identity and privilege.

Key Pillars of Identity Security Controls

To make identity intelligence actionable, enforcement must span five key areas:

1. Least Privilege Enforcement

Why it matters: Excessive access is one of the most common and dangerous identity risks. Most breaches involve over-permissioned users, stale admin rights, or standing access that attackers can weaponize.

What to do:

  • Automatically compare actual entitlements against job functions.
  • Use identity risk scoring to prioritize over-privileged identities.
  • Remove or downgrade unused, outdated, or unnecessary permissions.
  • Leverage just-in-time (JIT) access for privileged tasks to eliminate standing access.

Example: A DevOps engineer with permanent Admin access to all production accounts is a liability. With JIT access, they can request privilege temporarily, with approval and auditing built in.

2. Privileged Access Governance

Why it matters: Privileged accounts—human and machine—are high-value targets. If compromised, they can grant unrestricted access to sensitive data or systems.

What to do:

  • Centralize control through PAM platforms or privileged access workflows.
  • Monitor privileged sessions in real time, (including service account behaviors).
  • Use multi-factor authentication (MFA) and conditional access for all privileged identities.
  • Rotate secrets and credentials frequently—automate where possible.

Example: A service account running backups across multiple databases should be scoped tightly, monitored continuously, and have keys rotated regularly to reduce risk.

3. Access Lifecycle Management

Why it matters: Identities evolve—people change roles, leave organizations, or take on temporary projects. Without lifecycle management, access persists far beyond necessity.

What to do:

  • Integrate with HR systems or identity lifecycle tools to automatically adjust access based on joiner-mover-leaver events.
  • Define role-based access control (RBAC) and enforce provisioning rules.
  • Regularly review and re-certify access for high-risk roles and sensitive systems.

Example: A finance intern who transfers to marketing should not retain access to payroll and financial reporting tools. Automating revocation helps prevent avoids lingering access.

4. Identity Behavior Monitoring

Why it matters: Even well-configured identities can be compromised. Behavioral context is key to detecting misuse, anomalies, and early signs of intrusion.

What to do:

  • Establish baselines for normal identity behavior (logins, systems accessed, time of day, etc.).
  • Detect deviations—like sudden spikes in access, data exfiltration patterns, or privilege escalation.
  • Integrate with UEBA (User and Entity Behavior Analytics) tools and threat detection systems.

Example: If a service account that usually runs database jobs starts making API calls to billing systems at midnight, that should trigger investigation.

5. Policy and Automation-Driven Remediation

Why it matters: Manual cleanup of access and privileges doesn’t scale. Automation ensures consistency, speed, and resilience against human error.

What to do:

  • Define policies that trigger automatic actions—e.g., disable orphaned accounts after X days of inactivity.
  • Automate access reviews and alerts for high-risk privilege combinations.
  • Use policy-as-code for cloud entitlements and infrastructure roles (e.g., Terraform + OPA).

Example: If an AWS user gains permissions that violates a least privilege policy, automation should flag it immediately and, optionally, remove excess access.

Security Intelligence in Action: From Detection to Prevention

By enforcing identity controls aligned with intelligence, you shift from reactive to proactive defense. Examples include:

  • Proactively preventing privilege escalation by detecting lateral paths through identity graph analysis.
  • Blocking anomalous access from non-compliant locations or devices using conditional access policies.
  • Auto-revoking stale entitlements through risk-based automation tied to inactivity thresholds.
  • Identifying separation-of-duties violations (e.g., a user who can both initiate and approve financial transactions).

This isn’t just about better security—it’s better governance and reduced risk.

What Makes Identity Control Effective?

Identity Security Intelligence becomes powerful when insight leads to intervention. The most effective enforcement models share the following traits:

  • Visibility-driven: Based on complete, contextual discovery of identities and privileges.
  • Risk-prioritized: Driven by real-time scoring, not static role definitions.
  • Integrated: Connected interoperability between IAM, PAM, SIEM, and cloud security platforms.
  • Adaptive: Responds to changing conditions—cloud resource drift, org changes, identity posture shifts.
  • Auditable: Leaves a clear trail for compliance, incident investigation, and accountability.

Getting Started: Operationalizing Identity Security Controls

If you’ve already begun identity discovery, the next steps involve turning that visibility into action:

  1. Audit your current identity and privilege landscape for excess access and orphaned identities.
  2. Define your control framework—least privilege, privilege review, access lifecycle, monitoring, and remediation.
  3. Automate where possible—access revocation, risk scoring, and provisioning.
  4. Continuously monitor identity behaviors and privilege drift across environments.
  5. Integrate ISI into broader detection and response pipelines for holistic threat defense.

The Bottom Line

Discovery gives you awareness. Control gives you power.

Without enforcement, Identity Security Intelligence is just data. With the right controls, it becomes a force multiplier—reducing attack surface, stopping privilege abuse, and elevating your security maturity.

In today’s landscape, where identity is both the front door and the battleground, defenders need more than visibility. They need automated, adaptive, intelligence-informed control over every identity, privilege, and entitlement.

Because in the end, you don’t just want to know what’s out there. You want to secure it.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

AI BOM: Enhancing Transparency and Trust in the Age of Artificial Intelligence

The AI BOM: Unpacking the ‘Ingredient Label’ for Artificial Intelligence  

We use AI services like ChatGPT and Gemini daily, but what’s actually inside them? As AI systems become more powerful and integrated into our lives, a critical question has emerged: how can we trust a technology when its inner workings are often a black box, even to its creators?

In response to this challenge, a global movement toward AI transparency is taking shape, centered on the concept of an Artificial Intelligence Bill of Materials (AI BOM). Drawing inspiration from the Software Bill of Materials (SBOM) in cybersecurity, an AI BOM is a formal record that systematically documents every component of an AI system—from training data and algorithms to models and third-party libraries.

Why Now? The Perfect Storm Driving AI Transparency

The push for the AI BOM is driven by three main forces:

  1. Rising Complexity: Modern AI is a complex web of open-source models and vast datasets, making it difficult to track dependencies and vulnerabilities.
  2. New, AI-Specific Threats: Security risks like toxic data injection, model theft, and adversarial attacks require a more granular understanding of an AI’s composition.
  3. A Global Wave of Regulation: Governments are no longer leaving AI unchecked. Europe’s AI Act, U.S. executive orders, and South Korea’s national roadmap are all mandating greater transparency and accountability for AI systems, especially those deemed “high-risk.”

The Core Benefits of an AI BOM By providing a clear inventory of an AI system’s components, an AI BOM delivers powerful advantages:

  • Enhanced Transparency & Traceability: Understand how an AI system makes decisions and quickly identify the root cause of issues like bias or malfunction.
  • Proactive Risk Management: Identify and mitigate potential risks, such as biased training data or outdated libraries with security flaws, before they cause harm.
  • Streamlined Regulatory Compliance: Easily generate the documentation needed to comply with tightening global regulations and pass internal or external audits.
  • Secure Supply Chains: Verify the source and reliability of third-party and open-source components, strengthening defenses against vulnerabilities.

The Path Forward: Building a Trustworthy AI Ecosystem Global adoption of the AI BOM is accelerating, from the U.S. military to high-risk sectors in Europe like healthcare and finance. While challenges like standardization remain, the AI BOM is becoming a foundational tool for building a future where artificial intelligence is not only powerful but also transparent, accountable, and safe.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Are You Protecting the Right People in Your Organization?

If your security priorities still center on CVSS scores and device vulnerabilities, you’re missing a significant piece of the risk puzzle. People. Attackers aren’t following your org chart. They’re targeting whoever gives them access.

Enter the concept of Very Attacked People (VAPs): individuals in your environment who attract the most persistent, targeted attacks. And they’re not always the CEO or the CISO.

 

Attackers Follow Access, Not Titles

According to the 2025 Verizon Data Breach Investigations Report, 74% of breaches involve the human element, including phishing, credential theft, and accidental errors. The days of generic phishing blasts are long gone. Today’s attackers are smart, precise, and persistent.

While your executives might still be in the crosshairs, the riskiest users often sit quietly in other roles:

  • A marketing manager approving third-party contracts
  • An HR admin with access to payroll systems
  • A facilities lead managing badge entry systems

 

These users rarely rank as high-value assets in traditional models, but they often hold credentials and access that attackers want.

 

Traditional Risk Scoring Misses the Mark

Most risk models still evaluate device posture, not user behavior. They tell you if a system is out of date, but not whether its user has been phished multiple times or flagged by endpoint detection tools.

Without tying alerts to the person behind the screen, “low-severity” events can fly under the radar. A login anomaly for a guest account might not be a big deal. That same anomaly on your head of finance? That is an entirely different story.

 

Why Your Detection Strategy Needs a Human Layer

Security teams are buried in alerts. Prioritizing based on technical severity alone leads to noise, burnout, and missed threats. Detection becomes more effective when it accounts for who is being attacked, not just how.

At Graylog, we help teams operationalize VAP awareness through practical, people-focused workflows:

  • Correlate attack data across sources like phishing, EDR, anomaly detection, and threat intel
  • Tag users as VAPs in your SIEM’s asset database to give alerts human context
  • Prioritize alerts based on the risk level of the user, not just the event
  • Visualize human-centric attack trends to identify repeat targeting or emerging threats

 

This turns your detection playbook into a risk-based response strategy.

 

Cut Alert Fatigue by Focusing on VAPs

Security teams don’t need more alerts. They need better context.

Graylog reduces noise by highlighting activity tied to your most attacked users. A single phishing email targeting a known VAP triggers a high-priority alert. Repeated login attempts on a VAP’s account get flagged before they become a breach.

VAP-aware dashboards shift your view from disconnected logs to a cohesive story about who is under fire, how often, and why.

 

You Can’t Defend What You Don’t See

Most organizations think they’re protecting their highest-value users. But without clearly identifying your VAPs, you are playing defense with one eye closed. Attackers have already adjusted their tactics. It’s time your detection strategy caught up.

Want to start protecting the people attackers are really targeting? Learn how to identify and respond to Very Attacked People

About Graylog
At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

runZero Accelerates European Growth Through Strategic Partnership with Aqaio

German Cybersecurity Specialist Appointed as Primary Distributor for runZero to Drive Expansion in the DACH-Region

London, United Kingdom – July 24, 2025 – runZero, a leader in exposure management, today announced a strategic partnership with Aqaio, a German value-added distributor specializing in advanced IT security solutions. As runZero’s primary channel partner in Germany, Aqaio will spearhead regional growth efforts by delivering runZero’s expanded exposure management platform to organizations navigating today’s increasingly complex cyber threat landscape.

This alliance represents a significant milestone in runZero’s wider EMEA growth strategy. Leveraging Aqaio’s deep market expertise and established channel network, runZero can now accelerate its European expansion while offering localized support tailored to the specific needs of German organizations.

Partnership highlights include:

  • Localized Expertise: Aqaio brings in-depth knowledge of the German cybersecurity market, enabling specialized customer engagement and faster time-to-value.
  • Expanded Channel Reach: A top-tier network of resellers and systems integrators gain access to runZero’s powerful exposure management platform, enabling them to offer comprehensive proactive cyber defense to their end customers.
  • Streamlined Distribution and Support: Aqaio will facilitate seamless implementation via dedicated consulting, logistics, and certified training services for partners and end users.

“This partnership with runZero is a strategic win for our channel ecosystem,” said Richard Hellmeier, CEO at Aqaio. “They are no longer selling just another product — they’re delivering a vital capability. runZero’s technology is fast to deploy, easy to integrate, and solves a foundational security challenge. It aligns perfectly with our mission to deliver holistic and forward-looking solutions to the market.”

“In today’s rapidly shifting threat landscape, partnerships like this are essential to delivering resilient, scalable cybersecurity,” said Joe Taborek, Chief Revenue Officer at runZero. “Aqaio’s proven expertise and reach across the German market empower us to extend access to the runZero Platform and strengthen cyber readiness from the ground up. Together, we’re helping build a safer, smarter digital future.”

About Aqaio

Aqaio partners with resellers, system integrators, and OEMs. We focus on new technological developments, which we supplement and expand with complementary solutions from market and technology leaders in the IT security field. We also provide 2nd level support and training for our partners and their end-customers. The product portfolio consists of high-end IT products that complement each other and can be combined to create integrated solutions. Additionally, Aqaio offers services such as consulting, marketing support, logistics, training, and technical support. For more information, visit: https://aqaio.com/

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Cybercrime-as-a-service: the business model behind digital attacks

A cybercriminal stands in the shadows against a red background, his eye spotlit

Summary: Cybercrime-as-a-service mirrors the SaaS model, selling attack tools on the dark web. Learn how it works and how to defend your business.

Cybercrime-as-a-service (CaaS) is the dark side of modern software development. While the SaaS business model offers low-cost and flexible solutions, CaaS provides similar benefits for cybercriminals.

Thanks to CaaS, executing data breaches or distributed denial-of-service attacks has never been easier, challenging companies to upgrade their security measures. This article will explain how CaaS works and who is behind it, before exploring practical security responses.

What is cybercrime-as-a-service (CaaS)

Cybercrime-as-a-service is a threat model in which vendors provide services or tools to enable attacks by third-party clients. CaaS vendors generally sell products via pay-per-use or subscription models and use dark web marketplaces to conceal transactions.

CaaS operations allow attacks by unskilled criminal groups, expanding the community of threat actors. They cover many cyber threats, including ransomware, DDoS attacks, and credential theft. This makes cybercrime-as-a-service a critical part of the global threat landscape.

How the service model works in cybercrime

Cybercrime-as-a-service (CaaS) functions similarly to conventional third-party applications or cloud services. This familiarity is one reason why CaaS is spreading rapidly. Once restricted to specialist hackers, advanced tools are now available to novice threat actors.

How the cybercrime-as-a-service works in a  nutshell

CaaS attacks follow a lifecycle that starts with purchasing and ends with successful cyber attacks:

Purchase

Vendors create kits that include the tools needed to mount cyber-attacks. They offer these products for sale via encrypted sites. Popular purchasing platforms include dark web marketplaces and encrypted communication tools like Telegram channels.

Buyers can choose between several different kits depending on their goals and budget. CaaS vendors typically offer ransomware-as-a-service kits, tools to spread malware, and phishing kits featuring templates for fake websites and login portals.

Purchases typically take place via hard-to-trace cryptocurrencies. Transactions could be one-off purchases, but subscriptions are common. Marketplaces also often apply escrow models to enforce standards and resolve disputes.

Deployment

Cybercriminals customize CaaS kits to suit their needs before deploying attacks via their favored method. Forms of deployment include:

  • Drive-by downloads: Cybercrime services create credible websites to deceive victims and deploy downloads containing malicious payloads.
  • Phishing emails. Automated kits send personalized phishing emails to mount targeted attacks on victims. Emails persuade victims to download infected attachments, provide login credentials via fake websites, or take other risky actions.
  • Malvertising. CaaS kits deploy fake ads that are infected with malicious software. Malware spreads as users visit websites hosting the ads, enabling secondary data theft or ransomware attacks.

In the above deployment methods, off-the-shelf kits do the technical work (bypassing encryption, anonymizing attackers, or creating convincing fake assets).

CaaS kits also implant malicious tools on target systems. They seek ways to achieve lateral movement and discover sensitive data, often deploying credential theft tools to expand their reach. Backdoors also enable unskilled attackers to achieve persistence and execute sophisticated attacks.

Outcomes

After deploying threats and achieving persistence, cybercriminals can launch many types of cyberattacks.

For example, criminals use cybercrime services for gaining access to a target’s network security and implanting ransomware agents. These agents encrypt sensitive data or infrastructure until victims pay a ransom.

CaaS can also enable distributed denial-of-service (DDoS) attacks against network systems. Cybercriminals can extract data from cloud databases, use stolen financial credentials to make illicit transfers, or launch crypto-jacking attacks.

Who runs cybercrime-as-a-service operations?

Security experts estimate that cybercrime-as-a-service vendors earn over $23 billion annually, with an annual growth rate of over 12 percent. The market is increasingly complex, creating an ecosystem with many specialized roles.

Developers handle the production aspect of CaaS. For example, developers might create and update malware to stay ahead of cybersecurity measures. Other development teams focus on building botnets or exploit kits to target recently discovered vulnerabilities.

Affiliates tend to handle marketing and sales for developers. Marketers advertise CaaS products on the dark web and Telegram, along with prices and payment plans. Affiliates often earn commissions from successful attacks (sometimes as high as 30 percent).

Resellers operate independently from developers and affiliates. They sell products directly to customers, often those with less tech knowledge or awareness of the cybercrime landscape. Resellers may combine CaaS sales with tech support to attract buyers. They also buy in bulk and resell subscriptions at significant discounts.

Where does that leave the customers who actually purchase off-the-shelf CaaS products? Many buyers are new entrants to the cybercrime ecosystem. So-called “script kiddies” with few skills use CaaS kits to launch previously inaccessible attacks.

However, organized cybercriminals also rely on CaaS products to expand their operations. These criminals act like conventional businesses, seeking ways to cut costs and maximize revenues.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Navigating the Maze: Why Unified IT Management is No Longer a Luxury

Navigating the world of IT today feels less like mapping a clear path and more like finding your way through a maze.

Despite advancements in the tools at your disposal, critical gaps remain. Relying on many point solutions can make your systems feel disconnected instead of cohesive. You put in a lot of effort to make everything fit. But not all systems work well with your tech stack. This leads to frustrating inefficiencies.

Three key challenges stand in the way of progress: vendor sprawl, hidden user activity, and unknown security risks. 

These blind spots obscure your vision and prevent you from achieving the clarity and control you need. This article looks at these challenges. We’ll also see how unifying your systems can show you the clear path forward you need.

Tackling the Chaos of Vendor Sprawl

Vendor sprawl complicates IT operations, making management increasingly difficult. Relying on multiple providers for various devices, access methods, and use cases creates silos that disrupt workflows and fragment your systems.

This lack of cohesion makes daily management harder. It slows decision-making and weakens efforts to create a unified IT strategy. Each platform has its own interface and limits. They also have a steep learning curve. This means you need a lot of training on different systems. The burden of ongoing maintenance for each individual solution adds to the complexity, draining both time and energy.

It’s hard to see your whole infrastructure when important data spreads across different systems. Accessing information locked in separate vendor platforms takes extra time and effort. This makes it harder to manage users, devices, or your overall security posture effectively.

The risks don’t end there.

More vendors mean more vulnerabilities. Each new tool can create security gaps and risks of misconfiguration. This expands the attack surface and raises the chance of expensive security breaches.

Over time, not integrating leads to inefficiencies, security risks, and missed chances to improve your IT operations. A streamlined, unified approach is essential to overcoming these challenges and achieving operational excellence..

The Threat of Unseen User Activity

Unseen user activity is a natural occurrence. It includes the actions users take across different platforms and tools that are hard to track or measure. This might include users accessing SaaS apps they acquired and onboarded on their own. Or in a more nuanced example, seeing which buttons they are pushing and what reports they are pulling within sanctioned ones.

Without a unified view of user behavior, gaining meaningful insights becomes an uphill battle. Small data gaps quickly add up, leaving you struggling to connect the dots. For many organizations, combining data from different systems to create unified reports seems like a distant dream rather than a practical goal.

This lack of visibility triggers a ripple effect. It creates inefficiencies. Troubleshooting takes longer. Optimizing resources, like finding unused software licenses, turns into guesswork. Also, managing your IT environment becomes very hard.

From a security perspective, the consequences are even more critical. Lack of clear insights makes it tough to spot insider threats. It also complicates finding anomalies that might indicate breaches. Plus, it’s harder to revoke access when employees leave. In short, the absence of unified data impacts not just efficiency, but security too.

You Can’t Secure What You Can’t See

Effective security hinges on control. Yet, in practice, this goal often devolves into a fragmented patchwork of inconsistent controls and blind spots. When technical safeguards fall short, organizations are left relying on little more than hope—trusting employees to consistently make smart choices on their own.

You may offer training and support, but as your organization grows, adopts new tools, and becomes more distributed, maintaining these efforts becomes increasingly unmanageable. This leads to widening security gaps, turning access management into an uphill battle.

As a result, your organization is left exposed to escalating—but avoidable—risks.

At its core, the issue is clear: fragmented systems and the absence of a unified strategy are complicating your security posture. They are leaving your IT environment dangerously vulnerable. Every new tool or platform brings its own access rules, authentication protocols, and audit logs. This scattered approach obscures visibility, making it nearly impossible to enforce consistent policies, detect lateral threat movement, or securely de-provision access when roles change or employees leave.

Without a central control system, you stay in a reactive loop. You keep reacting to threats like a game of whack-a-mole. This reactive approach puts your key assets at risk from inside and outside threats. It stops you from having real proactive security.

How Unification Creates A Clear Path Forward

Now, consider the alternative. Investing in a unified platform for managing devices, identities, and access offers a compelling path forward. This consolidation of tools and processes simplify IT management, breaking down silos and providing a much-needed central point of control.

But the benefits don’t stop there. By making automation a core component of this unified platform, IT teams can finally break free from the shackles of routine, time-consuming tasks. Imagine your skilled IT professionals being liberated to focus on strategic initiatives, innovation, and driving real business value instead of endless password resets and user provisioning.

The message is clear: in today’s dynamic IT landscape, a unified and automated approach isn’t just a nice-to-have – it’s the key to navigating the maze and achieving true IT efficiency and control.

Automate Your Way to More Impactful IT

Our webinar, “6 IT Automations to Help You Boost your Bandwidth” offers practical strategies for replacing those time-consuming manual processes with intelligent, productivity-boosting automations. Discover how to free your team’s time and brainpower for higher-value projects.

Want to experience this transformation for yourself? JumpCloud’s unified platform for identity, access, and device management is built precisely for this. See how easy it is to simplify complex IT operations with comprehensive automation.It’s time to elevate your IT. Start your free JumpCloud trial today!

About JumpCloud
At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to find VMware ESXi installations on your network

Latest VMware ESXi vulnerabilities #

Broadcom has disclosed four vulnerabilities in certain versions of VMware ESXi, Workstation, Fusion, and Tools that, when combined, allow an adversary who already has privileged access (administrator or root) in a VM’s guest OS or has compromised a VM’s guest OS or services and gained privileged access to escape into the hypervisor and execute arbitrary code on the vulnerable system.

  • VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability due to an out-of-bounds write in the VMXNET3 virtual network adapter. An adversary with local administrative privileges on a virtual machine with the VMXNET3 virtual network adapter may exploit the vulnerability and execute arbitrary code on the host. Non-VMXNET3 virtual adapters are not affected by the vulnerability. This vulnerability has been designated CVE-2025-41236 and has been rated critical with a CVSS score of 9.3.
  • VMware ESXi, Workstation, and Fusion contain an integer-underflow vulnerability due to an out-of-bounds write in the VMCI (Virtual Machine Communication Interface). An adversary with local administrative privileges on a virtual machine may exploit the vulnerability and execute arbitrary code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the Workstation or Fusion host machine. This vulnerability has been designated CVE-2025-41237 and has been rated critical with a CVSS score of 9.3.
  • VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. An adversary with local administrative privileges on a virtual machine may exploit the vulnerability and execute arbitrary code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and exploitable only with configurations that are unsupported. On Workstation and Fusion, this may lead to code execution on the Workstation or Fusion host machine. This vulnerability has been designated CVE-2025-41238 and has been rated critical with a CVSS score of 9.3.
  • VMware ESXi, Workstation, Fusion, and VMware Tools contain an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. An adversary with local administrative privileges on a virtual machine may exploit the vulnerability and leak memory from processes communicating with vSockets. This vulnerability has been designated CVE-2025-41239 and has been rated high with a CVSS score of 7.1.

The following versions are affected

  • VMware ESXi versions 7.0 prior to 7.0.3 build-24784741
  • VMware ESXi versions 8.0 prior to 8.0.2 build-24789317
  • VMware ESXi versions 8.0 prior to 8.0.3 build-24784735
  • VMware Workstation version 17.x prior to 17.6.4
  • VMware Fusion version 13.x prior to 13.6.4
  • VMware Tools on Windows version 11.x.x or 12.x.x prior to 12.5.3
  • VMware Tools on Windows version 13.x.x prior to 13.0.1.0

What is the impact? #

Successful exploitation of these vulnerabilities would allow an adversary with privileged access in a VM’s guest OS to escape into the hypervisor and execute arbitrary code on the vulnerable system, potentially leading to complete system compromise.

Are updates or workarounds available? #

VMware has released updates for supported versions of the impact products to address these vulnerabilities. All users are urged to update as quickly as possible.

Product

Version

Fixed Version

Workarounds

ESXi

7.0

ESXi70U3w-24784741

None

ESXi

8.0

ESXi80U2e-24789317

None

ESXi

8.0

ESXi80U3f-24784735

None

Workstation

17.x

17.6.4

None

Fusion

13.x

13.6.4

None

Tools on Windows11.x.x, 12.x.x12.5.3None
Tools on Windows13.x.x13.0.1.0None

How to find VMware installations with runZero #

From the Asset Inventory, use the following query to locate assets running vulnerable versions of VMware ESXi:

os:"vmware esxi" AND ((os_version:>7 AND os_version:<"7.0.3 build-24784741") OR (os_version:>8 AND (os_version:<"8.0.2 build-24789317" OR os_version:<"8.0.3 build-24784735")))

Vulnerable versions of Workstation and Fusion can be found in the Software inventory using the following query:

vendor:vmware AND ((product:Workstation AND version:<17.6.4) OR (product:Fusion AND version:<13.6.4))

All versions of Workstation and Fusion can be found in the Software inventory using the following query:

vendor:vmware AND (product:Workstation OR product:Fusion)

March 2025: (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) #

On March 4th, 2025, Broadcom disclosed several vulnerabilities in all versions of its VMware ESXi, Workstation, and Fusion products. They also indicated that these are known to be exploited in the wild. Public information indicates that these vulnerabilities are potentially being leveraged by ransomware groups.

  • CVE-2025-22224 is rated critical with a CVSSv3 base score of 9.3. Successful exploitation of this vulnerability would allow a local administrative user in a guest virtual machine to execute arbitrary code as the guest virtual machine’s VMX process on a vulnerable host system. Impacts VMware ESXi and Workstation.
  • CVE-2025-22225 is rated important with a CVSSv3 base score of 8.2. Successful exploitation of this vulnerability would allow a malicious actor with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. Impacts VMware ESXi.
  • CVE-2025-22226 is rated important with a CVSSv3 base score of 7.1. Successful exploitation of this vulnerability would allow a local administrative user in a guest virtual machine to leak memory from the VMX process on a vulnerable host system. Impacts VMware ESXi, Workstation, and Fusion.

What is the impact? #

Upon successful exploitation of these vulnerabilities, an attacker with administrative rights in a guest virtual machine would be able to perform a VM Escape and execute code on the hypervisor host.

Are updates or workarounds available? #

VMware has released updates for supported versions of the impact products to address these vulnerabilities. All users are urged to update as quickly as possible. Users of unsupported version should review the download portals for their product to see if Broadcom has made patches available. They have reportedly done so for VMware ESXi 6.5 and 6.7. That said, Broadcom strongly encourages all customers using vSphere 6.5 and 6.7 to update to vSphere 8.

Product

Version

Fixed Version

Workarounds

ESXi

8.0

ESXi80U3d-24585383

None

ESXi

8.0

ESXi80U2d-24585300

None

ESXi

7.0

ESXi70U3s-24585291

None

ESXi6.7ESXi670-202503001None

Workstation

17.x

17.6.3

None

Fusion

13.x

13.6.3

None

How to find VMware installations with runZero #

From the Asset Inventory, use the following query to locate assets running vulnerable versions of VMware ESXi:

os:"vmware esxi" AND (os_version:<6 OR (os_version:>6 AND os_version:<"6.7.0 build-24514018")   OR (os_version:>7 AND os_version:<"7.0.3 build-24585291") OR (os_version:>8 AND os_version:<"8.0.2") OR (os_version:>"8.0.2" AND os_version:<"8.0.2 build-24585300") OR (os_version:>"8.0.3" AND os_version:<"8.0.3 build-24585383"))

Additionally, using the runZero VMware integration, use the following Asset Inventory query to locate virtual machines running inside VMware, which could be potential sources of exploitation:

source:vmware


Vulnerable versions of Workstation and Fusion can be found in the Software inventory using the following query:

vendor:vmware AND ((product:Workstation AND version:<17.6.3) OR (product:Fusion AND version:<13.6.3))


All versions of Workstation and Fusion can be found in the Software inventory using the following query:

vendor:vmware AND (product:Workstation OR product:Fusion)

Multiple CVEs (June 2024) #

Broadcom has disclosed a vulnerability in their ESXi product that involves a domain group that could contain members that are granted full administrative access to the ESXi hypervisor host by default without proper validation.

CVE-2024-37085 is rated medium with CVSS score of 6.8 and allows an attacker with sufficient Active Directory (AD) permissions to bypass authentication.

What is the impact? #

A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group (‘ESXi Admins’ by default) after it was deleted from AD. The three ways this can be exploited are:

1. Creating the AD group ‘ESX Admins’ to the domain and adding a user to it (known to be exploited in the wild)

2.
 Renaming another AD group in the domain to ‘ESX Admins’ and adding a new or existing user to it

3.
 Refreshing the privileges in the ESXi hypervisor when the ‘ESX Admin’ group is unassigned as the management group.

Are updates or workarounds available? #

Product

Version

Fixed Version

Workarounds

ESXi

8.0

ESXi80U3-24022510

KB369707

ESXi

7.0

No Patch Planned

KB369707

VMware Cloud Foundation

5.x

5.2

KB369707

VMware Cloud Foundation

4.x

No Patch Planned

KB369707

How to find potentially vulnerable systems runZero #

From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:

os:ESXi

Additionally, using the runZero VMware integration, use the following query to locate virtual machines running inside VMware, which could be potential sources of exploitation:

source:vmware

Multiple CVEs (March 2024) #

On March 5th, 2024, VMware disclosed several vulnerabilities in its ESXi, Workstation, and Fusion products.

The vulnerabilities, reported as CVE-2024-22252CVE-2024-22253CVE-2024-22254, and CVE-2024-22255 allow code running inside virtual machines to access the host system in unauthorized ways.

The CVSS scores range from 7.1 (high) to 9.3 (critical); the vulnerabilities affecting ESXi are limited to high severity, but the vendor has indicated that taken together the vulnerabilities should be considered critical.

What is the impact? #

Upon successful exploitation of these vulnerabilities, an attacker who can execute code inside a virtual machine can access the host system and perform actions ranging from arbitrary code execution to sensitive information disclosure.

Are updates or workarounds available? #

VMware has released new versions of these products to address these vulnerabilities. All users are urged to update as quickly as possible.

How to find VMware installations with runZero #

From the Asset Inventory, use the following query to locate assets running potentially vulnerable versions of VMware ESXi or running VMware products:

os:ESXi

Additionally, using the runZero VMware integration, use the following query to locate virtual machines running inside VMware, which could be potential sources of exploitation:

source:vmware

Additional fingerprinting research is ongoing, and additional queries will be published as soon as possible.


CVE-2021-21974 (February 2023) #

In February 2023, popular hypervisor ESXi made the news due to fresh targeting by a new strain of ransomware. Known as ESXiArgs, this ransomware leveraged a 2-year old heap overflow issue in the OpenSLP service that can be used to execute remote code on exploitable targets (CVE-2021-21974). Many vulnerable public-facing ESXi servers had already been affected by this malware (at the time over 1,900 via Censys search results).

What was the impact? #

Targets of this new ransomware campaign were older ESXi servers running certain versions of 6.5, 6.7, or 7 releases and also had the OpenSLP service enabled (it has not been enabled by default in ESXi releases since 2021). Upon successful exploitation of CVE-2021-21974, the ESXiArgs ransomware encrypted a number of file types on the target system, including VM-related files with extensions .vmxf, .vmx, .vmdk, .vmsd, and .nvram. Ransom notes were saved as HTML files on compromised systems for admins and users to subsequently discover. While some of these ransom notes claim to have stolen data from vulnerable targets, no data exfiltration had been observed at the time.

VMware made patches available when the OpenSLP heap-overflow vulnerability was initially reported in 2021. The following ESXi releases had been patched against this attack vector and exploited by the ESXiArgs campaign:

  • ESXi version 7+ (ESXi70U1c-17325551 and later)
  • ESXi version 6.7+ (ESXi670-202102401-SG and later)
  • ESXi version 6.5+ (ESXi650-202102101-SG and later)

VMware also offered patched releases for Cloud Foundation (ESXi), which included an ESXi component:

  • Cloud Foundation (ESXi) version 4.2+
  • Patching instructions for Cloud Foundation (ESXi) version 3.x can be found here

Patching (and also ensuring that your ESXi servers were running a supported, not end-of-life/end-of-support version) was the best course of action. If patching was not a near-term option, VMware recommended mitigation via disabling the OpenSLP service.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Identity Security Intelligence: Why Identity Discovery is the Bedrock of Modern Risk Management

Blind spots in identity are today’s biggest security risk. Here’s how to fix them.

In today’s hyper-connected and threat-saturated digital landscape, one truth is rapidly becoming self-evident to defenders across every industry: identity is the new perimeter, and access is the new security. As traditional network boundaries dissolve in favor of hybrid and cloud-first infrastructures, adversaries are increasingly pivoting toward the exploitation of identities—privileged accounts, service identities, orphaned users, misconfigured roles—as the primary path to breach and move laterally within environments.

But here’s the catch: you can’t protect what you don’t know exists. This is where Identity Security Intelligence becomes not just useful but essential. And at the core of that intelligence lies a foundational capability: Identity Discovery.

What is Identity Security Intelligence?

Identity Security Intelligence (ISI) is the ability to aggregate, analyze, and act on data about identities, their associated roles, privileges, behaviors, and risks across the entirety of an organization’s infrastructure—from on-premises directories to SaaS applications and multi-cloud platforms.

Think of it as the intersection between Identity and Access Management (IAM), risk analytics, and threat detection. It’s not just about managing identities; it’s about understanding them deeply—who they are, what they can do, where they exist, and how they behave over time.

The Foundation: Identity Discovery

Before an organization can reason intelligently about identity risk, it must first discover all identities that exist across its environment. This includes:

  • Traditional/On-Prem Identities: Users in Active Directory, service accounts in legacy apps, local admin accounts on servers, etc.
  • Cloud Identities: Identities in Azure AD, AWS IAM users and roles, Google Workspace users, cloud-native service principals, API keys, containers, and ephemeral workloads.
  • Shadow and Orphaned Identities: Legacy accounts no longer linked to active users, leftover access from decommissioned applications, services, and mismanaged credentials hiding in infrastructure-as-code.

A robust Identity Discovery capability surfaces all these identities, —whether they’re centralized or scattered, active or dormant, human or non-human.

Why Identity Discovery is Challenging (Yet So Crucial)

The complexity arises from the fact that identity is now distributed. No longer tethered to one central directory, identities live in different silos across multiple environments and systems. Each cloud provider has its own model. Each SaaS app may define roles and entitlements differently. Each legacy system might still have its own local accounts.

This fragmented landscape creates massive blind spots:

  • Privileged accounts in cloud environments that bypass central logging.
  • Orphaned identities with persistent access to sensitive data.
  • Service accounts with excessive, never-reviewed permissions.
  • Redundant roles due to M&A, org restructuring, or tool proliferation.

Without discovery, these blind spots can easily lead to compromised credentials.

Beyond Inventory: Discovering Roles, Privileges, and Entitlements

Discovery doesn’t stop at listing accounts. To enable true security intelligence, you must also map the roles, privileges, and entitlements tied to each identity.

This means answering questions like:

  • What can this identity do?
  • Where can it go?
  • What data can it access?
  • What systems does it control?
  • Are these privileges aligned with its purpose?

For example, discovering an AWS IAM user is useful. But understanding that the user has AdministratorAccess across multiple production accounts—and the account hasn’t logged in for 90 days—is critical.

Or take an identity in Microsoft 365 that has full mailbox access across HR, Finance, and Legal departments. Is that intended? Necessary? Or a remnant of an old project no one cleaned up?

Mapping these entitlements and privilege chains across your hybrid estate helps you:

  • Identify toxic combinations of access.
  • Enforce the principle of least privilege.
  • Detect privilege escalation paths.
  • Uncover misconfigurations before attackers do.

Identity Risk: The Unseen Attack Surface

The more fragmented and complex your identity environment, the greater your exposure. Attackers thrive in this chaos.

From techniques like Kerberoasting, Golden SAML, and token theft, to exploiting cloud misconfigurations and unused admin roles, modern adversaries are experts at chaining together identity weaknesses and misconfigurations.

By contrast, organizations that maintain a comprehensive view of identity risk across the board can:

  • Detect anomalous behavior in context (e.g., a service account accessing finance systems for the first time).
  • Shut down dormant or orphaned accounts.
  • Flag privilege drift over time.
  • Simulate attack paths based on current entitlements.
  • Proactively remediate risk without waiting for incidents.

What Makes Identity Security Intelligence Actionable?

Let’s be clear: data alone is not intelligence. Intelligence emerges when data is correlated, contextualized, and operationalized.

An effective Identity Security Intelligence program must provide:

  • Continuous Discovery: Real-time or near-real-time visibility into new, removed, or changed identities.
  • Entitlement Mapping: Deep visibility into fine-grained privileges across cloud and on-prem environments.
  • Risk Analytics: Automated scoring based on behavior, privilege level, and exposure.
  • Historical Context: Identity behavior over time—who did what, when, and whether it deviated from the norm.
  • Integrations: Feeds into SIEM, SOAR, and IAM/PAM platforms for proactive and reactive response.

This turns identity data into strategic insight—fuel for critical decisions in security operations, compliance, audits, and incident response.

Getting Started: Build Your Identity Intelligence Baseline

If your organization is just starting down this path, here’s a basic roadmap:

  1. Inventory all identities—human, service, machine—across on-prem and cloud.
  2. Map entitlements for each identity across applications, infrastructure, and data.
  3. Assess privilege levels and compare against business needs and least privilege standards.
  4. Identify toxic combinations—privilege escalations, cross-boundary access, unused high-risk roles.
  5. Establish continuous discovery and monitoring, not just point-in-time scans.
  6. Feed this intelligence into your risk models and threat detection systems.

The Bottom Line

In the same way that endpoint detection changed the game a decade ago, Identity Security Intelligence is becoming table stakes for defending against modern threats. Attackers know that identity is the weakest link in many organizations. Our job as defenders is to turn it into a strength.

By investing in identity discovery—including deep insight into roles, entitlements, and privileges—you build a clear, contextual picture of your true identity surface. Only then can you manage it, reduce it, and defend it with confidence.

In a world where credentials are more valuable than malware, identity intelligence isn’t just good hygiene—it’s your first line of defense.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.