Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

12/08/2026 0 Comments 0 tags

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

12/08/2026 0 Comments 0 tags

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

12/08/2026 0 Comments 0 tags

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231,

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

12/08/2026 0 Comments 0 tags

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

12/08/2026 0 Comments 0 tags

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

11/08/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

11/08/2026 0 Comments 0 tags

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter’s. The flaw sat in

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

11/08/2026 0 Comments 0 tags

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

11/08/2026 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

11/08/2026 0 Comments 0 tags

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was