Global Cyber Campaign Exploits Critical VMware vCenter Flaw

A critical flaw in VMware vCenter is now being actively exploited in a global cyber campaign just days after the vulnerability was disclosed. The flaw, tracked as CVE-2026-59310, affects the vCenter Syslog Server and has a maximum CVSS score of 9.8. Broadcom disclosed the issue on July 29 and warned that an attacker with network … Continued

Attackers Exploit Critical SharePoint Authentication Bypass After Public PoC Release

Attackers have started exploiting a critical vulnerability in Microsoft SharePoint after technical proof-of-concept code was made publicly available. The flaw, tracked as CVE-2026-55040, allows remote attackers to bypass authentication without having valid credentials. Microsoft fixed the issue through its July 2026 security updates, but the recent release of exploit details has increased concern for organizations … Continued

WhatsApp Adds Scam Alert Feature to Detect Suspicious Messages

WhatsApp has started testing a new security feature called Scam Alert, which is designed to warn users when a message may be part of a scam. The feature uses an on-device machine learning model to identify possible scam patterns in messages received from people who are not saved as contacts. WhatsApp is currently introducing the … Continued

Ransomware Hits Colombia’s Justice Ministry Days Before Presidential Transition

Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, 2026, affecting part of its technology infrastructure and reducing the availability of several public-facing digital services. The incident happened just five days before the country’s presidential handover on August 7, when Abelardo de la Espriella was scheduled to take office. The timing … Continued

Lazarus Hackers Exploit Windows Zero-Day to Target Defense Firms

North Korean hackers linked to the Lazarus group have exploited a Windows zero-day to target organizations in the defense, aerospace, and aviation sectors The attacks are connected to Operation Dream Job, where attackers pose as recruiters and use job opportunities to approach potential victims Researchers found activity affecting targets in Western Europe and India, with additional … Continued

CISA Warns Microsoft SharePoint Flaw Is Now Being Used in Ransomware Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are now abusing a serious vulnerability in Microsoft SharePoint Server. The flaw is tracked as CVE-2026-45659 and allows remote code execution through a deserialization weakness. It has been under active exploitation since early July, raising the risk for vulnerable on-premises SharePoint systems. Security … Continued

Critical LoadMaster Flaw CVE-2026-8037 Now Under Active Attack

A critical security flaw in Progress Kemp LoadMaster is an actively exploited vulnerability after the U.S. Cybersecurity and Infrastructure Security Agency added it to the Known Exploited Vulnerabilities catalog. The flaw is tracked as CVE-2026-8037 and carries a CVSS score of 9.6. It is an OS command injection vulnerability that can allow an unauthenticated attacker … Continued

Atlassian Rovo AI Can Be Tricked Into Leaking Jira and Confluence Data

Atlassian’s Rovo AI assistant has been found vulnerable to attacks that can trick it into sending sensitive Jira and Confluence information to an attacker-controlled server. Two security firms independently discovered different ways to manipulate Rovo into performing these actions. The issue is linked to prompt injection, where hidden or attacker-controlled instructions can influence an AI … Continued

Newsletter line