Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Seems like VirtFusion was next, still no details yet

RAVNIXRAVNIX Member, Patron Provider

Just got this email a few minutes ago from VirtFusion

Hi,

We have published VirtFusion 7.0.6, a stable security release that resolves several vulnerabilities, including one high-priority issue. We strongly recommend that you update your VirtFusion clusters to 7.0.6 without delay.

To protect installations while updates are being applied, we are not publishing the technical details at this time. A full, coordinated disclosure will follow once 7.0.6 has been widely deployed, so that everyone has a fair window to update first.

What you need to do

Update every VirtFusion cluster you operate to the stable 7.0.6 release.
Apply the update as soon as possible, rather than waiting for your next planned maintenance window.
How to update

In VirtFusion, go to System → Updates and apply 7.0.6, or
From the CLI on the control server, run: vfcli-ctrl update
7.0.6 also includes a number of other fixes and improvements. You can review the full release notes in our changelog: https://virtfusion.com/news/version-7-0-6-released

Read the security announcement here: https://virtfusion.com/news/security-7-0-6-released

If you have any questions or need assistance updating, please submit a support ticket and our team will be glad to help.

Thank you for updating promptly and keeping your systems secure.

Regards,
The VirtFusion Team

Thanked by 2whiterider zed

Comments

  • tentortentor Member, Host Rep

    Still way better than Virtualizor lol

  • RAVNIXRAVNIX Member, Patron Provider

    @tentor said:
    Still way better than Virtualizor lol

    Well, lets see what the vulnerability is before saying that lol

  • tentortentor Member, Host Rep

    @RAVNIX said:

    @tentor said:
    Still way better than Virtualizor lol

    Well, lets see what the vulnerability is before saying that lol

    Addressing vulnerabilities is still better than what's Virtualizor is doing is what I said

    Thanked by 1whiterider
  • rpqurpqu Member

    Thanked by 1whiterider
  • @RAVNIX said: Well, lets see what the vulnerability is before saying that lol

    The fact that they patched vulnerabilities doesn't mean they were exploited in the wild yet.
    Now ransomware groups will run patch diff tools to try to reverse engineer it.
    Grab your popcorn.

Sign In or Register to comment.