Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
11 / 11 results
criticalbug_reportVulnerabilityCritical VMware Workstation/Fusion integer overflow enables VM-to-host escape
VMware Workstation and VMware Fusion versions 25H2 and 26H1. Affects systems using VMXNET3 virtual network adapter (CVE-2026-59346) and HGFS feature (CVE-2026-59347). Both products patched in version 26H1u1.
criticalbug_reportVulnerabilityVMware Workstation and Fusion overflow flaws require immediate patching
VMware Workstation and VMware Fusion virtualization products. Specific affected versions not disclosed in available information. Overflow vulnerabilities present significant exploitation risk.
highperson_alertThreat ActorFire Ant Expands Espionage to Cisco Routers and TACACS Servers
Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.
criticalbug_reportVulnerabilityCISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack
Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…
criticalperson_alertThreat ActorChina-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware
A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.
criticalbug_reportVulnerabilityVMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access
VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.
criticalbug_reportVulnerabilityVMware vCenter CVE-2026-59310 exploited in wild for RCE and persistence
Broadcom VMware vCenter Server (all unpatched versions prior to late July 2026 patch release). Affects 361+ confirmed victim IPs across 47 countries, primarily Germany, US, Turkey, Iran, and France.
criticalbug_reportVulnerabilityCritical vCenter vulnerabilities require immediate patching
VMware vCenter Server component across multiple VMware product deployments. Specific affected versions not provided in advisory. Widespread impact expected given vCenter's role in VMware infrastructure management.
criticalbug_reportVulnerabilityVMware vCenter, ESXi critical flaws enable auth bypass and VM escapes
VMware vCenter Server (versions prior to 9.1.0.0300, 9.0.2.0100, 8.0 U3k), VMware ESXi (versions prior to 9.1.0.0200, 9.0.2.0100, 8.0 U3k), VMware Workstation and Fusion (25H2 and earlier), VMware Cloud Foundation 5.x, VMware vSphere Foundation, VMwa…
criticalbug_reportVulnerabilityCritical VMware vCenter auth bypass allows remote system compromise
VMware vCenter Server in VMware Cloud Foundation and vSphere Foundation versions 9.1.x.x (prior to 9.1.0.0300), 9.0.x.x (prior to 9.0.2.0100), vCenter 8.0 (prior to 8.0 U3k), and VMware Cloud Foundation 5.x.
highbug_reportVulnerabilityThree high-severity XSS flaws in VMware Telco Cloud and Aria Operations
VMware Telco Cloud/vSphere Foundation and VMware Aria Operations. Specific affected versions not provided in advisory; consult VMware security bulletin for version details.