小心:攻击者正在利用 VMware vCenter 实现持久化。在利用 CVE-2026-59310 后,他们植入了一个运行 reverse_ssh 的恶意 cron 任务,以维持访问。...
小心:攻击者正在利用 VMware vCenter 实现持久化。在利用 CVE-2026-59310 后,他们植入了一个运行 reverse_ssh 的恶意 cron 任务,以维持访问。研究人员识别出多达 361 个受害者 IP,遍布 47 个国家/地区。阅读更多:
所有带有「TheHackersNews」标签的 AI 情报。
7 条情报小心:攻击者正在利用 VMware vCenter 实现持久化。在利用 CVE-2026-59310 后,他们植入了一个运行 reverse_ssh 的恶意 cron 任务,以维持访问。研究人员识别出多达 361 个受害者 IP,遍布 47 个国家/地区。阅读更多:
在报告之外还隐藏着多少恶意软件?Stairwell 分析了 1,085 份公开威胁报告,发现每个已发布的恶意软件哈希平均对应 2.4 个额外的恶意变种,并发现了超过 54,000 个未被报告的关联恶意文件。
398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs. Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM. It also closes the RC
Fake job interviews are delivering a VPN that can run commands. CERT-UA says Sandworm-linked UAC-0145 is targeting Ukrainian IT workers with recruiter lures, then pushing a modified WireGuard client that can execute comm
Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing. The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and targets Android TV box
Malicious MCP servers can make AI coding agents exfiltrate SSH keys, .env secrets, source code, and customer data. The attack, dubbed “GhostSplice,” splits a request across MCP channels so no single fragment looks overtl
Rogue AI • Metabase 0-day • Spectre bypass • Webmail attacks • Router backdoors • MCP supply-chain malware • 440 poisoned packages • AI token jacking • Device-code phishing • $30M crypto attacks • 26 ransomware hits a da