Kryptovalutaticker:
sysadmin från Cyber Security News

VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

Tushar Subhra Dutta
5 hours ago
33 Visningar
0 Kommentarer
VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a critical path traversal bug in the Syslog Server, to run commands as root without a normal login. The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP addresses in 47 countries, with technology, research, education and telecommunications environments among the sectors exposed. The scale illustrates why vCenter management systems are such attractive targets. QUIRSO GmbH said in a report shared with Cyber Security News (CSN) that it investigated a compromise where the intrusion progressed from likely unauthenticated code...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!