Patching vCenter Is Not Enough Once the Attacker Owns the Control Plane

A vCenter compromise turns patching into incident response. Patch CVE-2026-59310, hunt reverse_ssh persistence and re-establish control-plane trust.

A vCenter compromise turns patching into incident response. Patch CVE-2026-59310, hunt reverse_ssh persistence and re-establish control-plane trust.

The LiteLLM supply chain attack began upstream in Trivy. Trusted security tooling, stolen secrets and automated CI/CD turned one breach into a wider exposure graph.

Attackers probed the GeoServer SQL injection before urgent fixes arrived. Patch 3.0.1, 2.28.5 or 2.27.6, then investigate the pre-patch exposure window.

Apple patched CVE-2026-65400, but attackers were already exploiting internet-exposed macOS Screen Sharing services. The reported compromises reached root and installed Monero miners, turning a patching story into an attack-surface and incident-response problem.

Exploit attempts hit SAP Commerce Cloud honeypots three days after patch day, before any public proof of concept. CVE-2026-58231 shows why internet-facing enterprise systems need an incident path, not a routine patch window.

ShieldBreak is now CVE-2026-69414, a Microsoft Defender elevation-of-privilege vulnerability assessed as exploitation more likely and still awaiting a verifiable fix. This update separates it from RoguePlanet CVE-2026-50656, explains the different CFAPI attack path, conflicting Windows 11 reproduction results, affected-build uncertainty, and the operational controls security teams should use instead of treating patch deployment as proof that exposure is fixed.

France has described three DGFiP data leaks involving tax correspondence, cadastral records and inheritance-related requests. The attack also shows how low-rate extraction can stay below detection thresholds.

Cl0p’s Windchill campaign is not primarily a story about a list of famous victims. It is a warning about what happens when dozens of enterprises expose the same high-value software weakness at the same time. Cl0p says it stole data…

Google found an agentic attack framework managing more than 23,800 harvested secrets. In a separate operation, another framework built and launched a credential campaign in under six hours.

A new White House programme will let vetted U.S. security companies conduct surveillance and disruptive operations against foreign cybercrime groups under federal direction. It is a significant expansion of private-sector offensive capability, but the memorandum’s legal guardrails leave difficult questions about attribution, accountability and escalation.