A newly disclosed critical flaw in VMware vCenter (CVE-2026-59310) has moved quickly from patch release to active exploitation, according to investigative reporting and telemetry from security firms. The vulnerability—a directory traversal bug that allows an actor with network access to execute arbitrary code—was patched by Broadcom late last month, and forensic evidence collected by QUIRSO indicates attackers were able to
Latest Articles

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Microsoft’s SharePoint platform is facing active exploitation following the public release of a proof-of-concept (PoC) for a critical authentication bypass vulnerability tracked as CVE-2026-55040. Patched in July’s Patch Tuesday, the flaw allows unauthenticated actors to impersonate SharePoint users by forging JSON Web Tokens (JWTs). Since the PoC surfaced, security researchers and telemetry providers have observed real-world attempts that underscore the urgency for administrators to apply updates and audit their environments. What happened Microsoft disclosed CVE-2026-55040 as a high-severity authentication feature…
Continue readingRansomware Strikes Colombian Justice Ministry Ahead of Presidential Transition
Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, affecting parts of its IT infrastructure and degrading several public-facing services just days before a national presidential handover. The disruption touched systems used for illicit-drug monitoring and legal processes; while some files were encrypted, the acting minister at the time, Cielo Rusinque, said publicly that there was
Microsoft Confirms July Windows Update Is Causing Some Dell Laptops to Shut Down and Overheat
Microsoft has acknowledged that a recent Windows 11 preview update has caused a limited number of Dell laptops to experience unexpected shutdowns, higher operating temperatures, rapid battery drain, and reduced performance. The issue was first flagged during Dell’s internal testing and later confirmed by Microsoft on July 14, 2026. A specific Intel driver interacting with a newly introduced Windows USB-C
CISA Flags Actively Exploited Adobe ColdFusion Path Traversal (CVE-2026-48282)
Adobe ColdFusion administrators woke up to an urgent warning this week: a critical path traversal vulnerability (CVE-2026-48282) is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026, and issued a binding remediation timeline for federal agencies under BOD 26-04 that requires
70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed
A recent analysis of publicly accessible WordPress installations has revealed a startling reality: a large majority of sites are running PHP versions that are no longer supported, creating a widespread and avoidable security risk. While WordPress itself issues regular updates, the underlying server-side language many sites rely on—PHP—has lagged behind in adoption. The result is an ecosystem where millions of
Microsoft Extends Windows 10 Extended Security Updates Through October 2027
Microsoft has quietly extended its consumer Extended Security Updates (ESU) program for Windows 10, pushing the cutoff for critical security patches out another year to October 12, 2027. The move gives millions of users who have not yet migrated to Windows 11 additional time to receive important and critical security fixes, while Microsoft continues to encourage upgrades to the newer





