top of page

Insights from the Field
Security analysis, platform hardening strategies, and lessons learned from real-world assessments.


My Day at BSidesCharm 2025: Reflections from the Field
By Demetrios Mustakas, HUME-IT Cybersecurity conferences come in many shapes, but few offer the blend of community, content, and candor that BSides events are known for. On Saturday, April 12, I had the opportunity to attend BSidesCharm 2025 in Towson, Maryland. The conference was held over two days, but it was a single day for me; one packed with insight, new perspectives, and important reminders about the work we do, the people doing it, and the stakes we all face. From the

Demetrios Mustakas Jr.
Apr 15, 2025


Two Fronts, One War: Ransomware in Healthcare and Finance
Introduction On January 27, 2025, Frederick Health Hospital in Maryland fell victim to a ransomware attack that disrupted core medical services and exposed sensitive patient data, including records belonging to my wife and daughter. As an IT security professional who has worked with hospitals and financial institutions across the U.S., this event struck a deeply personal chord. It was no longer just a headline; it became a threat to my own family’s safety and privacy. Just mo

Demetrios Mustakas Jr.
Apr 7, 2025


VMware Security Alert: Admin-to-Root Escalation in Aria Operations (CVE-2025-22231)
Introduction Broadcom has released VMSA-2025-0006, disclosing a local privilege escalation vulnerability in VMware Aria Operations. The vulnerability is tracked as CVE-2025-22231 and impacts multiple VMware platforms. Any attacker with local administrative access to the appliance can escalate privileges to root. There is no workaround. Patching is required. What Is It? CVE-2025-22231 is a local privilege escalation vulnerability affecting the following products: VMware Aria O

Demetrios Mustakas Jr.
Apr 2, 2025


VMSA-2025-0005: Why This VMware Tools for Windows Vulnerability Demands Immediate Attention
Introduction Broadcom has issued a new VMware Security Advisory, VMSA-2025-0005, disclosing a flaw in VMware Tools for Windows. This vulnerability, tracked as CVE-2025-22230, allows local attackers to bypass authentication controls and execute privileged operations from a non-admin account inside the guest OS. Important to note: This vulnerability does not appear to affect the ESXi hypervisor, vCenter Server, or any other virtual machines running in the same environment. Base

Demetrios Mustakas Jr.
Mar 26, 2025


VMware Security Alert: Hypervisor Vulnerabilities CVE-2025-22224, 22225, 22226 Explained
Introduction On March 4, 2025, Broadcom issued VMSA-2025-0004, disclosing actively exploited vulnerabilities in VMware ESXi, Workstation, and Fusion. CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 allow attackers to escape virtual machines, execute arbitrary code on the host, and exfiltrate sensitive data. These threats pose a critical risk to cloud and enterprise environments where VMware hypervisors are foundational. Organizations must act immediately to patch affected

Demetrios Mustakas Jr.
Mar 4, 2025


Urgent: Patch These VMware Vulnerabilities Now VMSA-2025-0003 Explained
Introduction Broadcom VMware has released VMSA-2025-0003, a security advisory detailing multiple vulnerabilities affecting VMware Aria Operations for Logs, Aria Operations, and VMware Cloud Foundation. These vulnerabilities range from information disclosure to privilege escalation and stored cross-site scripting (XSS), posing risks to system integrity, confidentiality, and overall security. For organizations leveraging VMware’s cloud and virtualization management platforms, u

Demetrios Mustakas Jr.
Feb 3, 2025


Protecting VMware Avi Load Balancer from Critical SQL Injection Vulnerability (VMSA-2025-0002)
Introduction Today, VMware disclosed a significant security vulnerability VMSA-2025-0002 (CVE-2025-22217) impacting its Avi Load Balancer platform. With a CVSSv3 score of 8.6 (Important), this unauthenticated blind SQL injection flaw has the potential to severely compromise critical systems, making it essential for organizations using this platform to act swiftly. Here’s what you need to know about the vulnerability, its implications, and how to protect your environment. What

Demetrios Mustakas Jr.
Jan 29, 2025


Diving Into VMSA-2025-0001: What This SSRF Vulnerability Means for VMware Environments
Recently, VMware issued VMSA-2025-0001, addressing a Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-22215, in VMware Aria Automation and Cloud Foundation. For anyone managing virtualized or hybrid environments, this raises important questions about how vulnerabilities like SSRF could be leveraged to enable broader attacks. Let’s unpack what this means and why it matters. What is SSRF and Why Should You Care? SSRF (Server-Side Request Forgery) is a vulnerability th

Demetrios Mustakas Jr.
Jan 8, 2025


Comparing CVE-2024-38814, CVE-2024-38812, and CVE-2024-38813: Independent Exploits or Shared Vulnerabilities?
Recently, VMware disclosed multiple critical vulnerabilities affecting vCenter Server, with CVE-2024-38814 , CVE-2024-38812 , and CVE-2024-38813 grabbing the attention of security professionals. While these vulnerabilities all have severe impacts on vSphere environments, it’s essential to understand their individual characteristics, how they differ, and any shared factors that might link them. Here’s a detailed comparison of these three vulnerabilities: CVE-2024-38814: Remot

Demetrios Mustakas Jr.
Oct 18, 2024


Quick Wins: Effective Management of VMware vSphere Permissions and Roles
What are "Quick Wins"? Short, focused articles offering practical security improvements without unnecessary complexity. Just the Facts Effective permission and role management in VMware vSphere is crucial for preventing unauthorized access and minimizing security risks. By applying a few best practices, organizations can reduce attack surfaces, strengthen access control, and enhance visibility into user activity. This article outlines five high-impact Quick Wins to immediatel

Demetrios Mustakas Jr.
Aug 11, 2023


Must-Have VMware Security Features You Can’t Ignore
This article aims to delve into the "so what?" aspect surrounding the prominent security features within modern vSphere editions by VMware. It isn't designed as an intricate technical exploration. Instead, its focus is on advocating for these features through three fundamental questions: What is its purpose? Why does it hold importance? What steps should be taken? Without delay, let's delve into the approximately 5 VMware Security features that are likely indispensable, deman

Demetrios Mustakas Jr.
May 2, 2023
bottom of page
