August 17, 2026
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 15, 2026
- VMware vCenter exploitation widened: Broadcom pushed VMSA-2026-0006.1, adding a critical auth-bypass (CVE-2026-59309, CVSS 9.8) and a VMXNET3 out-of-bounds write (CVE-2026-47876) alongside the directory-traversal RCE CVE-2026-59310 already under active APT exploitation for reverse-SSH persistence (Broadcom advisory, earlier coverage).
· Vulnerabilities & Exploits
in A Heavy Day for Exploit Research and In-the-Wild N-Days
August 14, 2026
- Critical VMware vCenter RCE (CVE-2026-59310) is under active global exploitation. The directory-traversal flaw in the vCenter Syslog Server allows unauthenticated remote code execution, and attackers are chaining it to drop a reverse-SSH tool for persistent access — meaning patching may not fully evict an intruder who already established a foothold. Denmark's national CERT reports abuse across 47 countries. (BleepingComputer, CERT.dk)
· Vulnerabilities & Exploits
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
July 30, 2026
- Broadcom patched critical VMware flaws including a vCenter authentication bypass (CVE-2026-59309), a Directory-Service/Syslog directory traversal (CVE-2026-59310), and an ESXi VM-escape enabling code execution on the host. No exploitation reported yet, but escape-class bugs warrant priority. The Hacker News, SecurityWeek
· Vulnerabilities & Exploits
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius