
Ransomware Exploits vCenter; CISA Issues Alert in 47 Nations
The agency confirmed that ransomware gangs joined espionage efforts exploiting CVE-2026-59310 in vCenter's Syslog component.
Security & Risk
140 analyses

The agency confirmed that ransomware gangs joined espionage efforts exploiting CVE-2026-59310 in vCenter's Syslog component.

Socket reveals that the Twitch Enhanced Viewer extension routes OAuth tokens from 30K Chrome users and 552 Firefox users to a Russia-based commercial bot server.

A group in northern Yemen used Claude Code to develop missile guidance systems; operators linked to Alibaba extracted 151 million conversations. Report covers operations from December 2025 to August 2026.

CISA added three vulnerabilities to its actively exploited catalog, requiring U.S. federal agencies to address them by September 12, 2026.

Anthropic's intelligence report covers Dec 2025 to Aug 2026, mapping seven abuse categories including state operations and weapons research.

The September threat intelligence report describes 3,500 fraudulent accounts aggregating nearly 3 million daily exchanges with Opus 4.6 and 4.7, attributed to Alibaba for training Qwen versions 3.5, 3.6, and 3.7.

Microsoft corrected 974 vulnerabilities in September, 5.6x the pre-2026 monthly average. Two zero-days in Windows were already listed in CISA's KEV catalog before the patch.

The largest Patch Tuesday in Microsoft history arrives with vulnerabilities already exploited in attacks on Windows ALPC and the Windows Update Stack, both elevating privileges to SYSTEM.

StyleSmuggler was added to CISA's KEV catalog on September 8. It is an unauthenticated RCE, CVSS 10, in the Magento template engine, with a Rust backdoor disguised as an NTP server.

APSB26-146 addresses CVE-2026-75650 exploited since September 4 in fully updated Magento stores. Sansec identified the unauthenticated remote execution route.

CERT Polska coordinated the disclosure of six vulnerabilities in RouterOS; the combination of two of them allows remote root control via SSH without credentials and is already being exploited.

Trezor confirms that ShipMonk retained orders it claimed to have deleted; a flaw in Metabase (CVE-2026-72898) opened an additional 67,000 records, bringing the total to over 80,000.