Watch out: Attackers are exploiting VMware vCenter for persistence.
Watch out: Attackers are exploiting VMware vCenter for persistence. After exploiting CVE-2026-59310, they planted a malicious cron job running reverse_ssh to maintain access. Researchers identified up to 361 victim IPs across 47 countries. Read more:
How much malware is hiding beyond what's reported?
How much malware is hiding beyond what's reported? Stairwell analyzed 1,085 public threat reports and found that every published malware hash corresponded to an average of 2.4 additional malicious variants, uncovering more than 54,000 related malicious files t
398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs. Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM. It also closes the RCE half of a SharePoint exploit chain. He
Fake job interviews are delivering a VPN that can run commands.
Fake job interviews are delivering a VPN that can run commands. CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute commands and fetch a second-stage payload. R
Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing.
Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing. The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and targets Android TV boxes through exposed ADB. Read more:
Malicious MCP servers can make AI coding agents exfiltrate SSH keys, .env secrets, source cod...
Malicious MCP servers can make AI coding agents exfiltrate SSH keys, .env secrets, source code, and customer data. The attack, dubbed “GhostSplice,” splits a request across MCP channels so no single fragment looks overtly malicious. In the researchers’ tests,