Cybersecurity Threats: A Week in Review
A summary of the latest cybersecurity threats and vulnerabilities.

This week has seen a surge in cybersecurity threats, with various vulnerabilities and exploits being discovered and exploited in the wild. The attacks are not always the most sophisticated, but rather a result of small openings turning into bigger problems due to inadequate defenses.
Suspected China APT Behind Exploitation of New VMware Flaw
A suspected China-nexus APT has been assessed to be behind the exploitation of a newly patched security flaw in VMware vCenter. The attacks involve the exploitation of CVE-2026-59310, a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. In at least one compromised instance, the attacks led to the deployment of a backdoor and a reverse SSH binary, with the attack ultimately leading to the deployment of Babuk-derived ransomware.
| Vulnerability | CVE ID | CVSS Score |
|---|---|---|
| VMware vCenter | CVE-2026-59310 | 9.8 |
The attackers' primary objective is not believed to be ransomware, but rather to distract from the underlying intrusion and hinder subsequent forensic analysis by encrypting evidence.
AI Adoption Is Outpacing Governance
A new survey by SANS has found that 78% of practitioners now say AI is part of their cybersecurity strategy, up from 50% last year. However, governance hasn't kept pace, with only 36% having a formal AI risk program.
| Governance | Percentage |
|---|---|
| Formal AI risk program | 36% |
| AI is part of cybersecurity strategy | 78% |
The survey highlights the need for better governance and risk management in AI adoption.
Other Notable Threats
- Apple macOS Flaw Exploited to Drop Crypto Miner: A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner. The vulnerability in question is CVE-2026-65400, a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials.
- Lazarus Exploits New Windows 0-Day: The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
- GeoServer Patches Critical Flaw Under Attack: GeoServer has released patches for a critical SQL injection vulnerability that can lead to remote code execution (RCE). The issue has been patched in versions 3.0.1, 2.28.5, and 2.27.6.
- Amnesia Stealer Goes Beyond Data Theft: A newly discovered macOS stealer family called Amnesia Stealer has been found to target macOS users via ClickFix attacks. The malware, besides stealing data from 16 Chromium-based web browsers as well as other sensitive information, includes a streaming module that allows the attacker to interactively control the victim's web browser.
- From GhostCommit to GhostSplice: A new attack technique called GhostSplice can sidestep guardrails built around AI coding assistants and parse malicious requests that are split and hidden in a different channel.
- Using Chrome DevTools Protocol for Data Theft: New research from SpecterOps detailed a post-exploitation technique that allows Chromium's CDP protocol to be enabled inside a live Google Chrome or Microsoft Edge process on Windows with an end goal to steal cookies, saved data, and authenticated browser sessions provided an attacker already has code execution permissions on the compromised host.
Trending CVEs
Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. The following are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.
| CVE ID | Description |
|---|---|
| CVE-2026-68820 | Microsoft Windows |
| CVE-2026-58231 | SAP Commerce Cloud |
| CVE-2026-48362 | |
| CVE-2026-71398 | |
| CVE-2026-27302 | Adobe |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense |
| CVE-2026-53413 | Zoom |
| CVE-2026-65400 | Apple macOS |
| CVE-2026-20337 | ClamAV |
| CVE-2026-18412 | Open |
Source: The Hacker News