Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Siemens SIPLUS and SIMATIC Products

View CSAF Summary Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIPLUS and SIMATIC Products are affected: • SIMATIC AX Runtime Core Linux Common Debian vers:all/* (CVE-2026-31431) • SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/* (CVE-2026-31431) • SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/* (CVE-2026-31431) • SIMATIC AX Runtime Core Linux VMWare Development vers:all/* (CVE-2026-31431) • SIMATIC CN 4100 vers:intdot/ CVSS Vendor Equipment

·CISA Alerts
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Auditteam has just published a new victim : Wise IT

Wise IT (wiseit. com. ua) is a Kyiv-based Ukrainian system integrator that provides data center, networking, virtualization, cloud migration, cybersecurity, software licensing, and IT outsourcing services, partnering with vendors such as Google, Microsoft, VMware, and Dell.

·Ransomware.live
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 5. The following CVEs are assigned: CVE-2026-59346.

·Zero Day Initiative (Published)
Read →
Breaches & Ransomware
Emerging1 src

8 Microsegmentation Tools: Our Top Picks by Use Case (2026)

Microsegmentation stops attackers moving sideways across networks . Once someone is inside your network through a phished credential, an unpatched server, or a compromised supplier flat internal networks let them reach everything. Microsegmentation puts a policy boundary around each workload so a single compromise stays a single compromise. We scored eight platforms and matched each to the environment it genuinely fits, because a VMware data centre and a Kubernetes estate need very different tools. Best Microsegmentation by Use Case — At a Glance Your situation Our pick Score Existing VMware virtualization estate VMware NSX (Broadcom) 8. 4 Ransomware containment, mixed environments Illumio 8. 8 Data centre and cloud, agentless preference Akamai Guardicore 8. 6 Already on a zero-trust access platform Zscaler 8. 0 Application dependency mapping on a budget Faddom 7.

·CyberPress
Read →
Breaches & Ransomware
Emerging1 src

Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS

Panzer ransomware has entered Italy amid a sharp rise in attacks. The ransomware-as-a-service, or RaaS, operation surfaced on August 5 and listed a kitchen manufacturer in Treviso and a telecommunications engineering firm in Catanzaro among its alleged victims. The group advertises tools for Windows, Linux, FreeBSD, and VMware ESXi systems. An attack on a virtualization host can disrupt many business applications at once, turning one compromised server into a wider outage. Panzer posted victims across 11 countries and the campaign arrived as claimed ransomware incidents in Italy reached 212 by September 6, above the 169 recorded during all of 2025. Researcher Andrea Fortuna said in a report shared with Cyber Security News (CSN) that the Panzer’s victim posts should still be treated carefully.

·Cyber Security News
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Aurora has just published a new victim : Jinny Beauty Supply

[distributors] Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states.

·Ransomware.live
Read →
Vulnerabilities & Patches
Emerging1 src

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U. S. and European Schools Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities U. S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog Crooks Behind Manchester Airports Group Hack Leaked Data of 8.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as CVE-2026-59346 (CVSS score of 9. 3), is an integer-overflow vulnerability. The issue resides in the VMXNET3, a virtual network adapter (virtual NIC) designed by VMware for virtual machines. An attacker with local admin privileges on a virtual machine using a VMXNET3 network adapter could exploit this flaw to run code on the host. “VMware Workstation and Fusion contain an integer-overflow vulnerability.” reads the advisory .

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

What the Flock?

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defense. Researchers uncover a serious PostgreSQL flaw. Google patches an exploited Chrome zero-day. Broadcom fixes VMware vulnerabilities. Attackers target a WordPress plugin flaw. Lawmakers tell license plate surveillance cameras to “Flock off.” Our guest is Kevin Gosschalk, Founder and CEO of Arkose Labs, discussing his new book, After Bots, which questions the old assumption that automated traffic is inherently malicious. Camouflage for the algorithmic age. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode?

·The CyberWire
Read →
Vulnerabilities & Patches
Emerging1 src

VMware Workstation and Fusion Updates Patch Critical Vulnerability

The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization. The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the pair, CVE-2026-59346, is an integer-overflow flaw in the VMXNET3 virtual network adapter. Broadcom rates it at a maximum CVSSv3 score of 9. 3, placing it firmly in the critical range.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

China-linked hackers turn Cisco routers into covert attack infrastructure

A China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia . The threat actor, tracked by Sygnia as Fire Ant, targeted Cisco IOS XR routers in 2026, using them to collect network traffic while suppressing evidence of its activity. The attackers also compromised TACACS authentication infrastructure and Linux management hosts as they explored access to connected high-value environments. The findings build on Sygnia research published last year that documented Fire Ant establishing deep persistence in VMware ESXi and vCenter environments. The latest activity shows the group extending that approach into infrastructure used to route traffic and administer enterprise networks.

·CSO Online
Read →
AI Security
Emerging1 src

Broadcom Launches VMware AI Factory to Secure Enterprise AI Agents

Broadcom unveiled VMware AI Factory at VMware Explore 2026 in Las Vegas, introducing a software-defined foundation within VMware Private AI Cloud designed to help enterprises deploy, govern, and secure AI workloads from bare-metal infrastructure through to live model inference. The announcement, made on August 31, 2026, positions the platform as a direct response to enterprise frustration over the slow, costly, and complex path from raw hardware to production-ready AI. Paul Turner, chief product officer of VMware Cloud Foundation Division at Broadcom, said enterprises want AI running where their data already lives, but the journey from metal to model has historically been too cumbersome.

·Cyber Security News
Read →
Threat Actors & Campaigns
Emerging1 src

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor

·The Hacker News
Read →
Threat Actors & Campaigns
Emerging1 src

SLEEPWALKER Backdoor Uses SMB, ICMP, DNS and VMware VMCI for Covert Communications

Researchers have uncovered a previously unknown Windows backdoor named SLEEPWALKER that can receive attacker commands through covert channels including raw network packets, DNS queries , SMB named pipes, ICMP ping traffic, and VMware’s VMCI communication layer. The malware is designed to remain dormant and avoid the usual signs of compromise. It does not contact a hard-coded command-and-control server, open a default listening port, or include an embedded final-stage payload. Instead, it waits for a specially crafted and encrypted trigger packet before activating. SLEEPWALKER was found as an unsigned 64-bit DLL impersonating Microsoft’s dpapi. dll . The sample copies version information from ESET Management Agent and is built to be side-loaded by ERAAgent. exe , the ESET Management Agent executable.

·CyberPress
Read →
Breaches & Ransomware
Emerging1 src

VMware ESXi Flaw CVE-2025-22225: Sandbox Escape in Active Ransomware Attacks

CyberUpdates365 Threat Intelligence Desk (Verified Report): This technical advisory has been fact-checked against the official Broadcom advisory (VMSA-2025-0004) and CISA’s Known Exploited Vulnerabilities (KEV) catalog. All remediation steps are verified for enterprise deployment. The VMware ESXi flaw CVE-2025-22225 is now used in active ransomware attacks, causing massive panic across enterprise data centers. CISA has officially ... Read more The post VMware ESXi Flaw CVE-2025-22225: Sandbox Escape in Active Ransomware Attacks appeared first on CyberUpdates365 • Latest Cybersecurity News & Vulnerabilities .

·Cyber Updates 365
Read →
Breaches & Ransomware
Emerging1 src

Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories of the Week

Welcome to this edition of the CyberPress weekly cybersecurity newsletter — your cybersecurity bulletin covering the 50 most important stories from August 17 to 21, 2026, organized day by day. It was a heavy week for breaches and exploited flaws: Cl0p claimed 89 GB from Shell, stolen Azure credentials exposed millions of employee records, and suspected Chinese actors weaponized a VMware vCenter RCE into ESXi ransomware. CISA sounded alarms on exploited vCenter, Windows IKE and Medusa ransomware, Microsoft patched a critical Entra ID RCE, and the DOJ charged 17 IRGC-linked hackers — all while AI stayed central, from Copilot’s CoSnitch flaw to agents finding 100+ bugs in days. Everything below is curated into one weekly cybersecurity newsletter so you can scan the week in minutes and click through to the full analysis.

·CyberPress
Read →
Phishing
Emerging2 srcs

41 deceptive download sites show a real link, then send you somewhere else

We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. • • • • • • • • • • • • • • • • • They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see isn’t the link you follow. One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens. The link looks safe when you hover, but the click says otherwise.

·Malwarebytes Labs
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-33824   (CVSS score: 9.8)  – Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040   (CVSS score: 9.1) Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310   (CVSS score: 9.8)   Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400  Apple macOS Improper Authentication Vulnerability CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310 , a critical path traversal bug in the Syslog Server, to run commands as root without a normal login. The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP addresses in 47 countries, with technology, research, education and telecommunications environments among the sectors exposed. The scale illustrates why vCenter management systems are such attractive targets. QUIRSO GmbH said in a report shared with Cyber Security News (CSN) that it investigated a compromise where the intrusion progressed from likely unauthenticated code execution to persistent access, account creation, ESXi control and ransomware.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-59310 - Broadcom VMware vCenter Path Traversal Vulnerability

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a

·The Hacker News
Read →
Threat Actors & Campaigns
Emerging1 src

Critical VMware vCenter Flaw Exploited by Advanced APT

Enterprise virtualization infrastructure remains the primary target for advanced persistent threats seeking total network dominance. A devastating new attack campaign has proven that patching delays of even a few days can lead to catastrophic data center compromise. The VMware vCenter flaw CVE-2026-59310 is currently being actively exploited by a highly sophisticated, suspected advanced persistent threat ... Read more The post Critical VMware vCenter Flaw Exploited by Advanced APT appeared first on Cyber Updates 365 .

·Cyber Updates 365
Read →
Breaches & Ransomware
Emerging1 src

Massive ransomware operation targets VMware ESXi: How to protect from this security threat - TechRepublic

Massive ransomware operation targets VMware ESXi: How to protect from this security threat TechRepublic

·TechRepublic Cybersecurity
Read →
Breaches & Ransomware
Emerging1 src

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 Stories

This week’s roundup covers a record-setting Microsoft Patch Tuesday, an actively exploited Cisco firewall zero-day, a Lazarus-linked Windows kernel bug, and critical flaws across TP-Link, Palo Alto Networks, Fortinet, and VMware — plus a first-of-its-kind autonomous AI agent “hack” and a DEF CON in-flight Wi-Fi scare. Ransomware & Threat Actor Campaigns Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA A joint FBI, CISA, NSA, and South Korean advisory has exposed the Gunra ransomware group, a Conti-derived double-extortion operation that emerged in April 2025 and has since matured into a full ransomware-as-a-service model rebranded as “Golden Community.”

·Cyber Security News
Read →
Breaches & Ransomware
Emerging1 src

🏴‍☠️ Medusalocker has just published a new victim : Twal Family IT Lab

Personal IT home lab. AD domain: twalfamily. com. VMware vSphere, multiple AD domains. Daniel Al Twal works at Technology North Corp (Edmonton), former DND co-op. No corporate target. Previously misidentified as Forces/forces. gc. ca. • 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada

·Ransomware.live
Read →
DFIR
Emerging1 src

Infosec News Nuggets — August 14, 2026

vCenter Flaw Exploited Just Five Days After Disclosure A critical directory-traversal flaw in VMware vCenter’s Syslog server, rated CVSS 9. 8, was already being exploited within five days of Broadcom’s disclosure, with researchers tracing 361 victim IP addresses across 47 countries. The attacker deployed an open-source reverse shell tool to maintain access to compromised systems, and while Broadcom has released patches, defenders are warned that patching alone won’t remove intruders who got in before the fix was applied. Hackers leverage new Microsoft SharePoint exploit in attacks A proof-of-concept exploit for a critical SharePoint authentication bypass flaw was weaponized within a day of its publication, letting unauthenticated attackers impersonate site users or administrators to access files and modify data.

·AboutDFIR
Read →
Threat Actors & Campaigns
Emerging1 src

Global Threat Campaign Hits Critical VMware vCenter Flaw - Dark Reading

Global Threat Campaign Hits Critical VMware vCenter Flaw Dark Reading

·Dark Reading
Read →
Vulnerabilities & Patches
Emerging1 src

Global Threat Campaign Hits Critical VMware vCenter Flaw

Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.

·Dark Reading
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Suspected APT Exploits Critical VMware vCenter Vulnerabilities in 47 Countries - Hackread

Suspected APT Exploits Critical VMware vCenter Vulnerabilities in 47 Countries Hackread

·Hackread
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

·SecurityWeek
Read →
Breaches & Ransomware
Emerging1 src

Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure

A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums. The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure. Unlike traditional single-OS malware, Eclipse Ransomware is engineered from the ground up as a multi-platform deployment. The Windows payload is written in Rust, leveraging the language’s memory-safety, performance, and evasion characteristics, while the variants targeting Linux, NAS devices, ESXi, and Nutanix environments are developed in C++.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access

An active cyberattack campaign targeting internet-accessible VMware vCenter instances. QUIRSO researchers uncovered evidence that advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks. Tracked as CVE-2026-59310 , the flaw is a maximum-severity directory-traversal vulnerability residing in the VMware vCenter Syslog server component. VMware vCenter Systems Exploited for Remote Access Broadcom released a security advisory warning that unauthenticated attackers with network access to an exposed vCenter instance can exploit the vulnerability to achieve remote code execution (RCE) with system privileges.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Critical VMware vCenter Directory Traversal Flaw Used in Global Attacks

Broadcom VMware vCenter administrators are facing an intrusion campaign targeting CVE-2026-59310 , a critical directory-traversal vulnerability in the vCenter Syslog Server. Threat researchers at QUIRSO said they identified 361 unique victim IP addresses across 47 countries, with evidence suggesting a suspected advanced persistent threat is using the flaw to obtain code execution and establish remote access. The campaign shows attackers rapidly operationalizing weaknesses in exposed virtualization-management infrastructure. Broadcom issued advisory VMSA-2026-0006 on July 29, 2026. Critical VMware vCenter Directory Traversal Flaw QUIRSO observed affected systems begin connecting to attacker-controlled infrastructure on August 3 five calendar days later.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9. 8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

·The Hacker News
Read →