August 14, 2026
vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
64 of 70 sources → 444 gathered → 400 triaged → 41 clustered → 41 written
A patched-but-still-dangerous VMware vCenter RCE is being exploited in a global campaign, and patching alone won’t evict the attackers. Separately, the White House deputized private security firms to run offensive “hack-back” operations, and the LiteLLM supply-chain breach turned out far larger than first reported.
Vulnerabilities & Exploits
- Critical VMware vCenter RCE (CVE-2026-59310) is under active global exploitation. The directory-traversal flaw in the vCenter Syslog Server allows unauthenticated remote code execution, and attackers are chaining it to drop a reverse-SSH tool for persistent access — meaning patching may not fully evict an intruder who already established a foothold. Denmark’s national CERT reports abuse across 47 countries. (BleepingComputer, CERT.dk)
- Adobe Commerce/Magento CVE-2026-71362 is being exploited within hours of disclosure. The critical flaw lets attackers hijack customer accounts; exploitation attempts were observed almost immediately after Adobe shipped the patch. (BleepingComputer, SecurityWeek)
- The Metabase pre-auth SQL injection zero-day now has a CVE and a technical writeup. Horizon3 details CVE-2026-72898, an actively exploited unauthenticated SQLi in Metabase before x.63.5 that yields admin access, config modification, and data theft — the flaw that had circulated without a CVE now formally tracked (earlier coverage). (Horizon3)
- A one-instruction CPU microcode unlock exploit was disclosed. Christopher Domas (xoreaxeaxeax) published a single
xorwrite that reportedly unlocks CPU microcode and grants access to the platform security processor and system management mode — a deep-platform primitive with obvious downstream implications. (@thegrugq) - LoongLeak cache side-channel hits Chinese Loongson (LoongArch) CPUs. Researchers found leaky caches enabling unprivileged cross-application and cross-VM data extraction, with limited mitigation options. (The Register)
- Chrome DevTools Protocol abuse sidesteps cookie-theft hardening. SpecterOps shows that enabling CDP inside a running browser lets an operator hijack the session outright — routing around recent app-bound cookie encryption defenses. (@ipurple)
- CSS-only Outlook password theft. Gareth Heyes published a whitepaper demonstrating credential exfiltration using nothing but CSS embedded in an email. (@garethheyes via @cyb3rops)
New Tools & Releases
- SharpDCSync — a C# DCSync implementation that replicates directory secrets without touching Mimikatz, giving red teams a lower-signature path to credential extraction from a domain controller. (Red Teaming Army)
- CVE-2026-68138 PoC — a working proof-of-concept for a race condition in the Linux kernel’s traffic-control (
net/schedqdisc rate-table) subsystem yielding local privilege escalation. (GitHub) - forkd — an open-source Firecracker-based microVM sandbox runtime aimed at AI-agent fan-out, code interpreters, and eval harnesses; it boots one warmed parent VM and forks copy-on-write children (100 sandboxes in ~101ms in its own benchmark). Worth noting @realfipso counters that gVisor already achieves sub-second sandbox spin-up. (@oliviscusAI)
- DeepSeek Harness v0.1 — DeepSeek open-sourced its agent runtime under MIT alongside V4-Pro’s GA, pitched as plugin-everything infrastructure for continuous (“recursive self-improvement”) agent self-modification with rollback guarantees. API prices rose in the same move, with cache hits jumping ~6x. (The Decoder)
Threat Activity
- Akira affiliates now reboot victims into Safe Mode with Networking to strip EDR — Huntress published full analysis of the technique, and in the observed cases the crew exfiltrated data but failed to encrypt (earlier coverage). (BleepingComputer)
- Cisco Talos dissected “JWR,” an operator-driven real-time phishing framework. Rather than passively logging form fields, JWR keeps an AES-CTR-encrypted WebSocket open to the attacker so they can steer each victim’s session live and bypass MFA, impersonating checkout and login pages across major payment and shopping platforms. (Talos)
- Near-autonomous AI agents attacked Taiwan’s nuclear safety agency and energy sector. Suspected Chinese operators reportedly used self-correcting AI agents to run multi-wave intrusions against government and energy targets, exfiltrating sensitive data. (The Register)
- DarkHotel (APT-C-06) malicious MSI chain. Nextron identified samples that run AV/environment checks, create scheduled tasks, and pull PowerShell-staged payloads with shellcode injection for evasion. (Nextron)
- DPRK-linked NullReceiver loaders found in infected GitHub repositories. The loaders decode Ethereum wallet recipient addresses as embedded IPv4 stages — reusing the C2 technique documented by OpenSourceMalware. (OpenSourceMalware)
- AmnesiaStealer targets macOS via ClickFix lure. A new Rust-based stealer spread through a fake “verified publisher” GitHub download page hijacks Chromium sessions for live browser control, deployed after victims paste a Base64 command into Terminal. (The Hacker News)
- WindRelay + SpyNote combo relays live credit-card data. A new Android NFC-relay malware paired with the SpyNote RAT streams card data to attackers in real time and takes out fraudulent loans. (BleepingComputer)
- Recorded Future profiled the malware-crypting service economy. Insikt Group analyzed 24 crypting vendors that now operate as full malware-enablement platforms — payload wrapping, in-memory execution, anti-analysis, injection, persistence, and post-detection re-crypting. (Recorded Future)
- SideCopy delivering CrimsonRAT via Outlook
.msglures, and BitterAPT using malicious.accdrdocuments against government, defense, and maritime targets — both flagged by Nextron with fresh IOCs. (SideCopy, BitterAPT) - First fully autonomous information operation, under controlled conditions. Researcher Lukasz Olejnik released a multi-month study running an end-to-end automated influence operation in a contained environment. (@lukOlejnik via @thegrugq)
AI & Model Security
- Apple paid a $150,000 bounty for a prompt-injection attack against Private Cloud Compute (CVE-2026-20685). The writeup goes “beyond prompt injection” into hacking Apple’s confidential-compute AI backend. (Sentry Security)
- Google shipped Gemini 3.7 Flash just three weeks after 3.6, claiming coding and agent gains over Claude Sonnet 5 and GPT-5.6 Terra at half the price. Notably, Florian Roth ran it through his THOR finding-triage benchmark and it took the top spot at 72.5% with 100% threat capture and zero critical misses. (The Decoder, @cyb3rops)
- Multiple jailbreaks landed against the new DeepSeek V4-Pro. Researchers reported near-total bypass of guardrails across privesc, KRACK, and physical-crime framings under “defender/academic” pretexts, with cyber/chem/bio production cited as the remaining hard wall. (@SingulCore)
Supply Chain
- The LiteLLM compromise is far larger than initially reported. New reporting from CloudSEK and Hudson Rock puts the blast radius at ~2,500 organizations — including Nvidia, AWS, and Samsung Electronics — with terabytes of credentials exfiltrated in a ~40-minute window and 434,000 CI/CD pipelines exposed (earlier coverage). Some commenters flagged it as possibly the largest credential compromise on record. (Ars Technica, discussion)
Industry & Policy
- The White House authorized vetted private security firms to conduct offensive cyber operations. A presidential memorandum stands up a federal program letting approved U.S. companies run Cyber Surveillance and Cyber Effects Operations — accessing and disrupting foreign cyber-criminal infrastructure — “under the control and oversight” of the government. Contracts may require a $1M forfeitable bond, and observers noted the memo’s language echoes both CFAA definitions and historical letters of marque. (The Record, BleepingComputer, SecurityWeek)
Data Breaches
- Trezor disclosed a shipping-provider breach affecting ~13,700 recent customers, with ~11,700 exposing full name, email, phone, and home address. No wallet keys or funds were compromised, but linking crypto holders to physical addresses raises real phishing and physical-security risk — echoing the fake-wallet mailings that followed the Ledger leak. (BleepingComputer)
- RingCentral was added to Have I Been Pwned covering 1,596,490 breached accounts. (HIBP)
- A forum actor claims to have breached France’s tax administration, advertising a partial database of 678,438 records allegedly obtained via VPN access to internal lookup tools before being disconnected mid-scrape. Unverified. (@DarkWebInformer)
Topics
Vendors
Threat actors