daily cyber × ai intelligence

index

tagged

[vmware]

5 editions · 5 items

September 1, 2026

  • Fire Ant has expanded from VMware hypervisors into routing and authentication infrastructure, compromising Cisco IOS XR routers, TACACS servers and Linux management hosts for credential theft and security-log blinding. Sygnia found the activity after spotting a live GRE tunnel interface that appeared in neither the running config nor the commit history (Sygnia, BleepingComputer). · Threat Activity

in Attackers Are Living in the Management Plane

August 14, 2026

  • Critical VMware vCenter RCE (CVE-2026-59310) is under active global exploitation. The directory-traversal flaw in the vCenter Syslog Server allows unauthenticated remote code execution, and attackers are chaining it to drop a reverse-SSH tool for persistent access — meaning patching may not fully evict an intruder who already established a foothold. Denmark's national CERT reports abuse across 47 countries. (BleepingComputer, CERT.dk) · Vulnerabilities & Exploits

in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries