Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

A newly disclosed critical flaw in VMware vCenter (CVE-2026-59310) has moved quickly from patch release to active exploitation, according to investigative reporting and telemetry from security firms. The vulnerability—a directory traversal bug that allows an actor with network access to execute arbitrary code—was patched by Broadcom late last month, and forensic evidence collected by QUIRSO indicates attackers were able to

Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Transition

Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Transition

Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, affecting parts of its IT infrastructure and degrading several public-facing services just days before a national presidential handover. The disruption touched systems used for illicit-drug monitoring and legal processes; while some files were encrypted, the acting minister at the time, Cielo Rusinque, said publicly that there was

CISA Flags Actively Exploited Adobe ColdFusion Path Traversal (CVE-2026-48282)

CISA Flags Actively Exploited Adobe ColdFusion Path Traversal (CVE-2026-48282)

Adobe ColdFusion administrators woke up to an urgent warning this week: a critical path traversal vulnerability (CVE-2026-48282) is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026, and issued a binding remediation timeline for federal agencies under BOD 26-04 that requires

70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed

70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed

A recent analysis of publicly accessible WordPress installations has revealed a startling reality: a large majority of sites are running PHP versions that are no longer supported, creating a widespread and avoidable security risk. While WordPress itself issues regular updates, the underlying server-side language many sites rely on—PHP—has lagged behind in adoption. The result is an ecosystem where millions of

Microsoft Extends Windows 10 Extended Security Updates Through October 2027

Microsoft Extends Windows 10 Extended Security Updates Through October 2027

Microsoft has quietly extended its consumer Extended Security Updates (ESU) program for Windows 10, pushing the cutoff for critical security patches out another year to October 12, 2027. The move gives millions of users who have not yet migrated to Windows 11 additional time to receive important and critical security fixes, while Microsoft continues to encourage upgrades to the newer

Russia Used Cellebrite’s UFED to Breach an Activist’s iPhone — and the Tools Kept Working

Russia Used Cellebrite’s UFED to Breach an Activist’s iPhone — and the Tools Kept Working

In June 2021, Russian authorities seized the devices of opposition figure Andrey Pivovarov and, according to a forensic report later analyzed by Citizen Lab, used traces of Cellebrite’s Universal Forensic Extraction Device (UFED) to extract messages and search for political names. The case is striking because it appears to show forensic use of Cellebrite technology months after the company publicly