Kryptovaluta-ticker:
sysadmin fra Cyber Security News

VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

Tushar Subhra Dutta
5 hours ago
31 Visninger
0 Kommentarer
VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a critical path traversal bug in the Syslog Server, to run commands as root without a normal login. The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP addresses in 47 countries, with technology, research, education and telecommunications environments among the sectors exposed. The scale illustrates why vCenter management systems are such attractive targets. QUIRSO GmbH said in a report shared with Cyber Security News (CSN) that it investigated a compromise where the intrusion progressed from likely unauthenticated code...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!