Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

A newly disclosed critical flaw in VMware vCenter (CVE-2026-59310) has moved quickly from patch release to active exploitation, according to investigative reporting and telemetry from security firms. The vulnerability—a directory traversal bug that allows an actor with network access to execute arbitrary code—was patched by Broadcom late last month, and forensic evidence collected by QUIRSO indicates attackers were able to

Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Transition

Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Transition

Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, affecting parts of its IT infrastructure and degrading several public-facing services just days before a national presidential handover. The disruption touched systems used for illicit-drug monitoring and legal processes; while some files were encrypted, the acting minister at the time, Cielo Rusinque, said publicly that there was

CISA Flags Actively Exploited Adobe ColdFusion Path Traversal (CVE-2026-48282)

CISA Flags Actively Exploited Adobe ColdFusion Path Traversal (CVE-2026-48282)

Adobe ColdFusion administrators woke up to an urgent warning this week: a critical path traversal vulnerability (CVE-2026-48282) is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026, and issued a binding remediation timeline for federal agencies under BOD 26-04 that requires

70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed

70% of WordPress Sites Running Outdated PHP Versions, Leaving Millions Exposed

A recent analysis of publicly accessible WordPress installations has revealed a startling reality: a large majority of sites are running PHP versions that are no longer supported, creating a widespread and avoidable security risk. While WordPress itself issues regular updates, the underlying server-side language many sites rely on—PHP—has lagged behind in adoption. The result is an ecosystem where millions of

Russia Used Cellebrite’s UFED to Breach an Activist’s iPhone — and the Tools Kept Working

Russia Used Cellebrite’s UFED to Breach an Activist’s iPhone — and the Tools Kept Working

In June 2021, Russian authorities seized the devices of opposition figure Andrey Pivovarov and, according to a forensic report later analyzed by Citizen Lab, used traces of Cellebrite’s Universal Forensic Extraction Device (UFED) to extract messages and search for political names. The case is striking because it appears to show forensic use of Cellebrite technology months after the company publicly

Photo ZIP Campaign Targets Hospitality Industry with Node.js Implant for Persistent Access

Photo ZIP Campaign Targets Hospitality Industry with Node.js Implant for Persistent Access

Microsoft Threat Intelligence has identified an active, multi-stage intrusion campaign that has targeted organizations in the hospitality and hotel industry since April 2026. Attackers delivered browser-downloaded photo-themed ZIP archives that contained executable shortcut files disguised as images. When opened, these shortcuts kicked off an obfuscated PowerShell chain that fetched a Node.js–based implant, established dual registry persistence, and initiated command-and-control (C2)