Search/broadcom
Vendor

broadcom

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
bcm4339 soc firmware
Connections
761 relationships
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086 (WatchGuard), CVE-2026-80047 (Hugging Face Transformers), CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588 (Sangoma Switchvox SMB), CVE-2026-6881 (Ellucian Advance Web and Legacy Advance), CVE-2026-13381, CVE-2026-13380 (VSee Clinic), CVE-2026-63219, CVE-2026-58400 (GeoNetwork), CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235 (Rockwell Automation), CVE-2026-84115 (Cleo Harmony), CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126 (Mozilla Firefox), CVE-2026-84353, CVE-2026-84352, CVE-2026-85046 (Google Chrome), CVE-2026-19949 (All-in-One WP Migration and Backup), CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212 (Cisco), CVE-2026-15630 (Casdoor), CVE-2026-73749 (Hewlett Packard Enterprise ArubaOS-CX), CVE-2026-67394 (Plesk), CVE-2026-38577 (Tenda), CVE-2026-6471 aka PostGREShell (PostgreSQL), CVE-2026-42038 (Axios), CVE-2026-64532, CVE-2026-64533 (Linux Kernel), CVE-2026-58048 (cPanel and WHM), CVE-2026-14540 (Google mcp-toolbox), CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673 (Jenkins), GHSA-x7v6-xfx3-52j6, GHSA-r7jx-j9h7-j4xj, GHSA-9jcm-x588-gh26, GHSA-6mpx-c8rj-whj5, GHSA-q65v-4w7q-hx3r (FreeRDP), CVE-2026-59346, CVE-2026-59347 (Broadcom VMware Workstation and Fusion), CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060 (MikroTik RouterOS), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190 (Telerik UI for ASP.NET AJAX), CVE-2026-86218, CVE-2026-86206, and CVE-2026-86207 (N-able N-central). 🎥 Cybersecurity Webinars A New Vulnerability Drops. Learn How to Find Out ”If You’re Exposed” Faster → Your security tools have the data. Getting an answer shouldn’t take days. See how Tines brings software, cloud, application, and vulnerability data into one dashboard—and learn how to give your team a faster, clearer view of what’s at risk. Find Which Vulnerabilities Attackers Can Actually Exploit—in Hours, Not Weeks → A vulnerability alert doesn’t tell you whether an attacker can break in. Learn how to test exploitability with real-world attack simulations, identify the gaps that matter, and focus remediation on proven risks—not just severity scores. 📰 Around the Cyber World New Knight Office Microsoft 365 AitM Phishing Kit — A new adversary-in-the-middle (AiTM) phishing toolkit called Knight Office has been spotted in the wild using Docusign-themed lures to direct victims to fake landing pages for AitM token theft and device code phishing attacks, joining the likes of EvilTokens and Kali365. The email "led the victim through a number of redirects (including a redirect via the Monday work management platform and a compromised Joomla website)," Huntress said. "The victim landed on a phishing page, where their valid session tokens were captured and fed to the Knight Office console. Session tokens allow attackers to access victim accounts as if they were logged in, without needing an actual password or a way to bypass multi-factor authentication (MFA)." At least nine total phishing attacks on identities have been linked to this kit over the past two weeks. The Blind Spot in SNMPv3 — SNMPv3 — the protocol widely regarded as the secure standard for managing routers, switches, and firewalls — leaks pre-authentication signals that can allow an unauthenticated remote actor to identify a device’s vendor, confirm valid usernames, and narrow its likely encryption settings before testing a single credential. Validated across approximately 470,000 internet-exposed endpoints, the findings show how these standards-compliant behaviors can collapse a multi-dimensional brute-force problem into a focused password-guessing exercise. "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary," said Kobi Ben-Naim, Co-Founder and CEO of Malanta. "But that answer is incomplete. The protocol does exactly what it was designed to do, and that design hands attackers a roadmap: even properly upgraded deployments, when exposed, leak enough through pre-authentication responses to help an attacker narrow their way in before a single credential is tested. The threat doesn't end with the upgrade." U.S. Announces Reward for Senior Iranian Official — A $10 million reward has been posted by the U.S. State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps' (IRGC) Cyber-Electronic Command (CEC). "Yaryab also oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These malicious cyber groups have used malware to target civilian infrastructure worldwide," the State Department said. Attack on Coder — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to harvest environment variables, API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, external authentication tokens, and Coder database passwords. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry," Coder said. "These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code." Users are advised to look for connections to the malicious domains before applying the latest patches (versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9) U.S.-U.K. Team Up to Shut Down Scam Centers — The U.S. and the U.K. signed a Memorandum of Understanding (MoU) to work together on an initiative to shut down scam centers stealing billions of dollars through investment and romance fraud schemes. "Under the terms of the MOU, each will conduct parallel investigations into common targets, share information on targeting of organized crime syndicates, discuss which jurisdictions to bring specific cases of common interest, and generally prioritize cases on this threat to achieve mutual results," the U.S. Justice Department said. Tampered Exodus Installer Delivers Modular RAT — Victims are being tricked into running a fake PDF document or a software update that leads to the execution of an MSI installer that declares itself a "Background Service" by Apple. "The 'Background Service' installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it," Huntress said. "Only 3 of its 1,973 files differ from the real thing. One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy that enable remote access and browser credential theft. While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts." QR Phishing With No Image — In a new phishing attack detailed by Kaspersky, threat actors are building a QR code out of text characters and markup directly in the email body as opposed to rendering an image. "There is no attachment to open, no embedded picture to decode, and nothing for an image-based or optical-character-recognition (OCR) scanner to key off," PhishU said. "Because it is markup and not a remote image, an inbox with images turned off still paints it. The message shows a perfectly scannable QR to the human reading it, image-blocking and all." Apple Hit With $2.7 Billion Lawsuit Over App Tracking Rules — Apple is facing a £2 billion ($2.7 billion) lawsuit in the U.K. accusing it of imposing stricter App Tracking Transparency rules on third-party developers than on its own advertising services, thereby giving its ecosystem a competitive advantage, according to Reuters. Apple's App Tracking Transparency feature has been the subject of extensive investigations across Europe. Last month, Apple agreed to make changes to the feature across almost all European Union countries following a probe in Germany. Attackers Routinely Target Edge Devices — A joint analysis from SentinelOne and Tenable found that both nation-state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs. "Both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure," the companies said. "The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch." The disclosure comes as current attacker timelines are compressing and moving faster than standard patch cycles can address, driven by frontier AI models that narrow the window between vulnerability discovery and exploitation. The Threat of Indirect Prompt Injection — New research from Forcepoint revealed that an email summarizer running an unguarded LLM pipeline can be manipulated through indirect prompt injection (i.e., hidden instructions in an email) to silently hijack summarizer output and generate false and potentially dangerous summaries without signaling tampering to the recipient. It's the latest example of how attackers can use indirect prompt injections to undermine AI systems and get them to behave in unintended ways when processing external content. It's also a reminder of AI's fundamental limitations. Large language models (LLMs) cannot distinguish between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources, leading to prompt injections. "A regular Outlook email composer does strip styling that hides elements on copy/paste and does not provide any way to hide text other than white text on white background," Forcepoint said. "The hidden styling was not stripped when sent programmatically, or when the message is received and displayed. Hidden HTML tags like these have been commonly used by attackers to circumvent careful reading by victims." Conclusion Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed. Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.
thehackernews.comSep 7, 2026extracted
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host," Broadcom said in an alert. The tech giant credited @h4urek, @cameudis, and Stan S for discovering the issue. Also patched by Broadcom is a stack-based buffer-overflow vulnerability in HGFS (CVE-2026-59347, CVSS score: 8.1), which can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab have been acknowledged for reporting the flaw. In both cases, successful exploitation hinges on an attacker already possessing local administrative privileges, although it's worth noting that they can be obtained through a separate compromise through phishing or exploiting weak user configurations. The two vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Broadcom said there are no workarounds that address the two vulnerabilities, adding that they have been patched in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. Although there is no evidence that the security flaws have been exploited in the wild, vulnerabilities in VMware products have been an attack magnet. As recently as last month, threat actors were observed actively exploiting two shortcomings in VMware vCenter, namely CVE-2026-59309 and CVE-2026-59310, with the latter suspected to be weaponized by a China-nexus advanced persistent threat (APT) actor. The activity, which started five calendar days after public disclosure of the flaw, is estimated to have breached 361 unique victim IP addresses across 47 countries. Most of the infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
thehackernews.comSep 5, 2026extracted
VMware Workstation and Fusion Updates Patch Critical Vulnerability
Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as CVE-2026-59346 (CVSS score of 9.3), is described as an integer overflow bug leading to arbitrary code execution. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom notes in its advisory. Tracked as CVE-2026-59347 (CVSS score of 8.1), the second flaw is a stack-based buffer overflow that could lead to similar outcomes, albeit the exploitation conditions are different. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host,” Broadcom explains. Both vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1 and were resolved in version 26H1u1. There are no workarounds for either of the flaws, and Broadcom recommends updating to a patched iteration as soon as possible. The company makes no mention of any of these vulnerabilities being exploited in the wild, and says that both issues were reported to it privately. However, security defects in VMware products are often exploited by threat actors. More than two dozen VMware vulnerabilities are currently included in CISA’s KEV list. Related: Exploit Published for Fresh Cleo Harmony Vulnerability Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Related: Hackers Start Exploiting Critical Langflow Vulnerability
securityweek.comSep 4, 2026extracted
Silent Patches Don’t Stop Attackers – They Blind Defenders
Every so often a vendor decides the smart move is to fix a vulnerability quietly. No advisory, no CVE, no explanation, just the vaguest handwave in a changelog. The logic sounds reasonable on its face: if you don’t explain what a patch does, you avoid handing attackers a roadmap to the root cause. Why publicize your bugs? Here’s why: patches aren’t secrets once they ship. A vendor can skip the CVE, skip the advisory, skip the outreach, but the binary still changes on disk, and anyone with a debugger and a disassembler can diff old and new and figure out what moved. That’s not a hypothetical skill, and lately, the barrier to entry into sophisticated exploit dev just got a lot lower thanks to our LLM friends. Silent patches do not keep vulnerabilities secret. They just keep the details secret from everyone except the people already capable of weaponizing them. Consider who that leaves out. Penetration testers, who you’re paying to demonstrate risk and threats. Vulnerability management and detection engineers building signatures into products you buy for protection. Journalists, academics, and policymakers trying to explain risk to important decision makers. Most importantly, the IT administrators triaging a nearly endless mountain of patches who need some signal for severity and exploitability to decide what gets applied tonight and what waits for the next maintenance window. Almost none of these people are reverse engineering your binary to find out if they should care. They have limited time and attention. Let’s flip the original justification around. Silent patching does not limit knowledge of a vulnerability to a small pool of people. It limits disclosed truth to a small pool of people specifically motivated to reverse-engineer your product, which, in practice, skews toward the attackers with the skill and incentive to do it. Everyone trying to defend your users is left behind, triaging with incomplete data. As a bonus, that includes your own future product engineers, who might reintroduce the same bug because everyone kept it secret the first time around. Where a delay is actually defensible I’ll concede a case for something short of full, instant disclosure, but it’s narrower than most vendors want it to be. Say your product is hosted, SaaS-delivered, and the user has essentially no patching decision to make. No downtime to schedule, no changelog to consult. A brief embargo while you patch your own fleet isn’t hiding anything meaningful, it’s an operational detail. The same goes for products with small, tightly controlled userbases where auto-update means nearly everyone is patched within hours regardless of announcement timing. In both cases, the IT administrator triaging a patch queue hardly matters; they’re getting patched for free, so withholding details for a few days to a couple weeks isn’t putting customers at much risk. The Tanzu Spring twist Broadcom, which now owns VMware and, by extension, the Spring Framework (through VMWare’s Tanzu division), recently expanded a program worth watching closely. As of its June 2026 announcement, paying customers get access to validated, CVE-only patch releases through a private “Spring Enterprise Repository” before the rest of the open source userbase. Broadcom says it will keep issuing CVEs for every supported version of every Spring project, commercial or open source. The practical effect, though, is early access to exploit intelligence for a price, and the biggest difference between the casual criminal script kiddie and the nation-state cyber-spy is budget. So, unless Broadcom is planning on running an unusually robust know your customer (KYC) program around this subscription, you can bet that some nefarious types are going to get pre-alerts to otherwise undocumented vulnerabilities. Short term secrets The problem with the Broadcom approach is that the open source audience is much larger than the small minority of paying customers. And while Broadcom is supplying CVEs, advisories, and patches eventually, I’m worried the lag is effectively creating a window where the most well-resourced attackers can operate with impunity in a sizable ecosystem of targets. The ideal approach to releasing security patches is to be forthright about the risk to everyone, all at once. After all, most people are on your side, even if a few bad guys aren’t, so it’s hard to justify keeping vulnerabilities secret when the patches themselves tell the whole story to anyone with enough patch-diffing smarts. In some limited cases (the SaaS and small audience examples above), I can get behind a patch-then-advisory head start. But, it’s nearly impossible to justify withholding details for weeks on end, or forever. Eric S. Raymond once quipped that given enough eyeballs, all bugs are shallow. I’d posit today that given enough prompt engineering, all patches are advisories. Related: AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Related: Stop Using CVSS to Score Risk
securityweek.comAug 25, 2026extracted
91 Vulnerabilities Patched in Spring Application Framework
The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware. A single vulnerability has been assigned a critical severity rating: CVE-2026-59270. It affects Spring Security’s embedded UnboundID LDAP server and could allow an attacker to authenticate and modify entries in the in-memory directory. Over a dozen vulnerabilities have been classified as high severity. They can be exploited for XSS attacks, information disclosure, remote code execution, DoS attacks, security bypasses, and unauthorized access. The remaining vulnerabilities have medium and low severity ratings. Cybersecurity firm Sonatype has analyzed the patches and found that they impact more than 200,000 software components. The security flaws affect projects such as Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP, and Batch. Sonatype has highlighted two vulnerabilities: CVE-2026-59285, which it describes as a critical remote code execution issue in Spring for GraphQL, and CVE-2026-59318, a medium-severity issue in Spring AI’s tool-calling functionality that can allow privilege escalation through prompt injection. The surge in Spring vulnerabilities is unsurprisingly driven by Broadcom’s use of AI. More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. Spring vulnerabilities can be useful to threat actors, and they have been exploited in the wild, including the notorious Spring4Shell. CISA’s KEV catalog currently includes several such vulnerabilities. Open source projects are advised to review the latest Spring patches and apply them. Related: Critical Isolated-vm Vulnerability Leads to RCE on Host Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Related: Hackers Target Zimbra Servers in Active Exploitation Campaign
securityweek.comAug 24, 2026extracted
USN-8668-1: Linux kernel (GCP) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - RNBD block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clocksource drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Tegra memory controller driver; - Multifunction device drivers; - IBM Advanced System Management driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Ethernet bonding driver; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - MediaTek network drivers; - Near Field Communication (NFC) drivers; - NTB driver; - NVDIMM (Non-Volatile Memory Device) drivers; - NVME drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Broadcom BCM2835 power domain driver; - Power supply drivers; - RapidIO drivers; - Remote Processor subsystem; - RPMSG subsystem; - SCSI subsystem; - Freescale SoC drivers; - Texas Instruments SoC drivers; - SPI subsystem; - Greybus lights staging drivers; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - SM750 framebuffer staging driver; - TCM subsystem; - TTY drivers; - UFS subsystem; - Cadence USB3 driver; - USB Device Class drivers; - ULPI bus; - USB core drivers; - DesignWare USB2 driver; - USB Gadget drivers; - USB Host Controller drivers; - Mustek MDC800 USB digital camera driver; - USB YUREX driver; - Renesas USBHS Controller drivers; - Framebuffer layer; - Xen hypervisor drivers; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - EROFS file system; - Ext4 file system; - F2FS file system; - FAT file system; - FUSE (File system in Userspace); - GFS2 file system; - HFS+ file system; - JFS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - OCFS2 file system; - Proc file system; - Pstore file system; - Diskquota system; - SMB network file system; - SquashFS file system; - UDF file system; - XFS file system; - Audit subsystem; - RAS (Reliability, Availability, Serviceability) subsystem; - Software nodes and device properties; - Memory Management; - KVM subsystem; - Memory management; - PPP protocol drivers and compressors; - Linux Security Modules (LSM) Framework; - Network traffic control; - Bluetooth subsystem; - MAC80211 subsystem; - Netfilter; - IP tunnels definitions; - Tracing infrastructure; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Control group (cgroup); - Kernel fork() syscall; - Kernel futex primitives; - Kernel kexec() syscall; - Kernel module support; - Scheduler infrastructure; - Cryptographic library; - KASAN memory debugging framework; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - CAIF protocol; - CAN network layer; - Ceph Core library; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - Management Component Transport Protocol (MCTP); - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - NFC subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - RF switch subsystem; - Rose network layer; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - Stream parser; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - eXpress Data Path; - AppArmor security module; - Simplified Mandatory Access Control Kernel framework; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - AudioScience HPI driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - SoC audio core drivers; - STI ASoC drivers; - USB sound devices; (CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116, CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545, CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865, CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715, CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221, CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719, CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863, CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006, CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562, CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748, CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103, CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256, CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161, CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274, CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031, CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141, CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220, CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228, CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270, CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286, CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293, CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303, CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318, CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367, CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391, CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425, CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446, CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454, CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467, CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480, CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494, CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540, CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565, CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585, CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701, CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726, CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763, CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015, CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046, CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089, CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242, CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281, CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357, CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420, CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439, CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484, CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860, CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883, CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899, CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912, CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920, CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941, CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956, CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974, CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002, CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015, CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037, CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053, CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072, CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088, CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137, CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189, CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206, CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219, CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231, CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238, CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259, CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274, CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319, CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914, CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920, CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926, CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011, CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088, CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128, CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294, CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306, CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379, CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102, CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153, CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221, CVE-2026-64587)
ubuntu.comAug 21, 2026extracted
USN-8665-1: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. (CVE-2025-62626) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Clock framework and drivers; - Data acquisition framework and drivers; - Counter interface drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - CXL (Compute Express Link) drivers; - DMA engine subsystem; - EDAC drivers; - EFI core; - GPU drivers; - Greybus drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IRQ chip drivers; - LED subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Tegra memory controller driver; - Fastrpc Driver; - IBM Advanced System Management driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Ethernet bonding driver; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - Ethernet team driver; - MediaTek network drivers; - Near Field Communication (NFC) drivers; - NTB driver; - NVDIMM (Non-Volatile Memory Device) drivers; - NVME drivers; - Device tree and open firmware driver; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Broadcom BCM2835 power domain driver; - Generic PM domains; - i.MX PM domains; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - SLIMbus drivers; - Freescale SoC drivers; - Microchip PolarFire SoC system controller driver; - SPI subsystem; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - SM750 framebuffer staging driver; - TCM subsystem; - Thermal drivers; - TTY drivers; - UFS subsystem; - Cadence USB3 driver; - USB Device Class drivers; - ULPI bus; - USB core drivers; - DesignWare USB2 driver; - USB Gadget drivers; - USB Host Controller drivers; - Mustek MDC800 USB digital camera driver; - USB YUREX driver; - Renesas USBHS Controller drivers; - USB Type-C Connector System Software Interface driver; - VFIO drivers; - Framebuffer layer; - TSM TDX Guest driver; - Xen hypervisor drivers; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - EROFS file system; - Ext4 file system; - F2FS file system; - FUSE (File system in Userspace); - GFS2 file system; - HFS+ file system; - Journaling layer for block devices (JBD2); - Network file systems library; - Network file system (NFS) server daemon; - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - OCFS2 file system; - Diskquota system; - SMB network file system; - SquashFS file system; - Tracing file system; - UDF file system; - XFS file system; - Kernel CPU control infrastructure; - QorIQ DPAA2 FSL-MC bus driver; - Memory Management; - Integrity Measurement Architecture(IMA) framework; - KVM subsystem; - Memory management; - Networking core; - padata parallel execution mechanism; - PPP protocol drivers and compressors; - Linux Security Modules (LSM) Framework; - Tracing infrastructure; - Network traffic control; - Distributed Switch Architecture; - IPv4 networking; - IP tunnels definitions; - MAC80211 subsystem; - Netfilter; - User-space API (UAPI); - io_uring subsystem; - Audit subsystem; - BPF subsystem; - Control group (cgroup); - Perf events; - Kernel exit() syscall; - Kernel fork() syscall; - Kernel futex primitives; - KProbes tracing; - Locking primitives; - Kernel module support; - Padata parallel execution mechanism; - Cryptographic library; - Heterogeneous memory management; - KASAN memory debugging framework; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Ethernet bridge; - CAIF protocol; - CAN network layer; - Ceph Core library; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - Management Component Transport Protocol (MCTP); - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - NFC subsystem; - Open vSwitch; - Packet sockets; - Qualcomm IPC Router (QRTR); - RDS protocol; - RF switch subsystem; - Rose network layer; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - Stream parser; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - eXpress Data Path; - Landlock security; - ALSA framework; - Generic PCM loopback sound driver; - FireWire sound drivers; - HD-audio driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - QCOM ASoC drivers; - Renesas ASoC drivers; - Samsung ASoC drivers; - SoC audio core drivers; - SOF drivers; - STI ASoC drivers; - USB sound devices; - Objtool; (CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764, CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239, CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161, CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287, CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993, CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118, CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171, CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244, CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255, CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285, CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303, CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308, CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315, CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321, CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340, CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361, CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365, CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370, CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383, CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389, CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412, CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419, CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448, CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461, CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465, CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475, CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393, CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425, CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429, CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434, CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450, CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473, CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480, CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487, CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498, CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503, CVE-2026-31505, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512, CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519, CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528, CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542, CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549, CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554, CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563, CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31634, CVE-2026-31638, CVE-2026-31639, CVE-2026-31642, CVE-2026-31645, CVE-2026-31646, CVE-2026-31648, CVE-2026-31651, CVE-2026-31655, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31689, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701, CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711, CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728, CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737, CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763, CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772, CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015, CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019, CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43044, CVE-2026-43046, CVE-2026-43047, CVE-2026-43049, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054, CVE-2026-43056, CVE-2026-43057, CVE-2026-43058, CVE-2026-43059, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080, CVE-2026-43081, CVE-2026-43082, CVE-2026-43084, CVE-2026-43085, CVE-2026-43086, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43092, CVE-2026-43093, CVE-2026-43094, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43107, CVE-2026-43109, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43119, CVE-2026-43120, CVE-2026-43129, CVE-2026-43162, CVE-2026-43245, CVE-2026-43252, CVE-2026-43265, CVE-2026-43281, CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355, CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361, CVE-2026-43362, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368, CVE-2026-43370, CVE-2026-43371, CVE-2026-43372, CVE-2026-43373, CVE-2026-43377, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43395, CVE-2026-43397, CVE-2026-43405, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411, CVE-2026-43412, CVE-2026-43413, CVE-2026-43415, CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424, CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436, CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445, CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456, CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471, CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488, CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45855, CVE-2026-45858, CVE-2026-45899, CVE-2026-45911, CVE-2026-45920, CVE-2026-45924, CVE-2026-45942, CVE-2026-45943, CVE-2026-45956, CVE-2026-45958, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987, CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996, CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026, CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037, CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056, CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079, CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084, CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103, CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114, CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46121, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125, CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129, CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46136, CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142, CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152, CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161, CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168, CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174, CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179, CVE-2026-46180, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207, CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212, CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220, CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229, CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46241, CVE-2026-46273, CVE-2026-46274, CVE-2026-46280, CVE-2026-46282, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46291, CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296, CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314, CVE-2026-46319, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925, CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967, CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989, CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050, CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085, CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110, CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117, CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128, CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289, CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295, CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306, CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379, CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851, CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856, CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865, CVE-2026-64164, CVE-2026-64587)
ubuntu.comAug 20, 2026extracted
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 20, 2026extracted
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 20, 2026extracted
AI agent suggested installing a malware package. Engineer almost took its advice
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 20, 2026extracted
ICE boss to agents: Leave the Meta spy glasses at home
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 19, 2026extracted
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CVE-2026-55040 (CVSS score: 9.1) - A weak authentication vulnerability impacting Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-59310 (CVSS score: 9.8) - A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code. CVE-2026-33824 (CVSS score: 9.8) - A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code over a network. Although the vulnerabilities have since been patched by the respective vendors, they have come under active exploitation, according to multiple public reports. While the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner, the SharePoint vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code. The vulnerability affecting VMware vCenter is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor to deploy a backdoor along with reverse_ssh binaries for persistent access to compromised instances. In at least one case, the campaign has led to the deployment of a Babuk-derived ransomware. In all, the activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). CVE-2026-33824, per Palo Alto Networks Unit 42, has been observed being exploited by another Chinese-speaking threat actor, who is said to have simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek and conducted manual operations using known vulnerabilities, including the Microsoft Internet Key Exchange flaw. Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.
thehackernews.comAug 19, 2026extracted
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. A fix for the flaw was released by Broadcom on July 29, 2026. German incident response company QUIRSO assessed with moderate confidence that the exploitation campaign aimed at CVE-2026-59310 is operated by a Chinese-speaking threat actor, likely working in the UTC+08:00 time zone, which is predominantly used in Chinese-speaking regions. "This assessment is based on the convergence of Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated operational use of Chinese-language tools and management software, victimology excluding mainland China, and activity patterns compatible with UTC+08:00 working hours," QUIRSO researchers Maike Orlikowski, Çağatay Yürekli, and Denis Szadkowski said. The activity, which commenced five calendar days after public disclosure of the flaw, is estimated to have compromised 361 unique victim IP addresses across 47 countries, with most of the infections scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). Exploitation of CVE-2026-59309 One compromised vCenter Server Appliance analyzed by QUIRSO is said to have been targeted by both CVE-2026-59310 and CVE-2026-59309, an authentication bypass that has also witnessed active scanning efforts. Evidence shows malicious activity consistent with the exploitation of CVE-2026-59309 as early as August 1, 2026, followed by the creation of an administrative account on vCenter. That said, no login events have been observed for the legitimate administrative account that was used to create this new account. The account creation originated from the IP address 146.59.252[.]178 and also involved vSphere discovery via the REST API on August 3 using User-Agent strings like "GoodMoodle-VCFleet/1.0," in an attempt to masquerade it as VMware-related activity. It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances. It encompasses multiple components, including VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains. QUIRSO said there is no overlap between this activity and the chain of events involving the abuse of CVE-2026-59310 on the same system starting August 3, adding the newly created "vcenter_admin" administrator account was not used in subsequent phases of the attack. Exploitation of CVE-2026-59310 As for the exploitation of CVE-2026-59310, the first activity involved the cron daemon (aka crond) logging a malformed cron file called "zz-poc59310-syslog.log." In the next step, a curl command (or alternatively a wget command) is executed to retrieve a backdoor from "5.34.177[.]38:9861" and execute it, and then remove the log file. The naming convention of the log file is significant as it is a direct reference to the CVE identifier and that it was a proof-of-concept (PoC) devised after details of the flaw became public knowledge. "The '-syslog.log' suffix also mirrors the vCSA remote syslog file naming convention, but the file appears under /etc/cron.d rather than the configured syslog output directory," QUIRSO explained. "This suggests that the vCSA syslog server was abused to place files in a privileged execution location. While some files were malformed and not executed by cron, at least one file successfully executed and placed the 'linuxFile' backdoor on the system." The linuxFile implant is designed to provide remote command execution capabilities to the attacker. It establishes a connection to its controller over a WebSocket channel to receive instructions, executes them through /bin/sh, and transmits the results back to the attacker. "The C2 [command-and-control] address is XOR-obfuscated and decoded at run-time, while communications are protected using the malware's own application-layer cryptography despite using an unencrypted ws:// transport," Szadkowski told The Hacker News via email. "It also automatically reconnects on failure and contains routines for establishing persistence through systemd and cron." The threat actor behind the operation also relied extensively on cron to execute malicious payloads, including to fetch and run a shell script ("esxi.sh") from the IP address "185.144.28[.]120:3232." The shell script then serves as a downloader and persistence installer for an architecture-specific reverse SSH ("reverse_ssh") binary that's retrieved from the same infrastructure. Other cron jobs related to creating staging directories, downloading executables, changing their permissions, and running them, while referencing servers at "192.255.141[.]13:8080" and "5.34.176[.]100:5244." In what appears to be an operational security blunder, the latter has been found to expose the reverse SSH binaries toolset via an AList directory listing. A brief description of some of the various actions carried out by the threat actor is as follows - Deploying "linuxFile" (aka systemlog or linux_x86), which connects to "ws://intel.se9ly9upbhay.shop:8080/ws" and establishes persistence via a systemd service. Setting three cronjobs impersonating legitimate VMware services: vmware-vpxd-stats-* (facilitates an SSH-based remote access channel by adding the attacker's SSH public key to the authorized keys file), vmware-perf-collect-* (drops a JSP web shell named "vmware-perf-update.jsp"), and vmware-perf-sync-* (drops the same web shell and runs a Base64-encoded script that performs credential access and sets up a new account called "adminuser," which is then added to the vSphere SSO Administrators group. Creating two additional accounts: adding "vcadmin" to vSphere with a Base64-encoded Python script dropped on disk via bash commands run in a cronjob and creating a vSphere admin account via an external LDAP "Add" operation against vCenter's VMware Directory Service (vmdir) from a remote client by using a pre-existing but compromised administrative account. Creating a file named "/etc/sudoers.d/vmware-perf" with a configuration that grants the "perfcharts" service account unrestricted, non-interactive passwordless sudo access to root. Running shell scripts like "/tmp/.vmware-perf-upd.sh" to obtain credentials for vmdir by querying the HKEY_THIS_MACHINE\services\vmdir registry location. If this method fails, it searches for VMware's vmafd Python module and calls GetMachineName(), GetMachinePassword(), and GetDomainName() to get the distinguished name and password associated with the vCenter machine account. The stolen credentials are used to conduct privileged directory modifications, including adding the aforementioned "adminuser" identity to the Administrators group. Using vSphere API to perform discovery operations and "esxi.sh" to deploy the reverse_ssh client. Creating local accounts on the ESXi hosts (e.g., "adminuser") to enable ransomware encryption. Taking steps to evade detection, reduce forensic visibility, and blend into the VMware environment. The attack ultimately paves the way for the deployment of a ransomware on ESXi hosts that encrypts files with the ".babyk" extension, which is typically associated with Babuk-derived ransomware. It's not clear if this was the end goal of the campaign, or if the Babuk-derived payload was "selected opportunistically or even intentionally" to confuse attribution efforts. QUIRSO told the publication it cannot assess at this stage if the ransomware strain was deployed across other compromised systems as the analysis was limited to only one of the infected systems. However, based on the investigation so far, it's suspected that the deployment of the locker may not have been the primary objective of the campaign. Szadkowski likened the deployment to a smokescreen engineered to distract defenders from the main intrusion and thwart analysis by encrypting the ESXi log files, thereby preventing access to telemetry data that could have offered more insights into threat actor activity. "Exploitation of CVE-2026-59310 provided the actor with immediate, non-interactive code execution in a root context on the vCenter Server appliance," the researchers said. "Subsequent commands recorded by CROND were therefore already being executed as root, giving the actor unrestricted access to the underlying VCSA without first having to compromise an unprivileged local account and escalate from it." Update In a follow-up analysis, QUIRSO said it identified a GitHub repository ("pikpak0066/tmpclean") linked to the same threat actor that, at first blush, appears to be a Go-based program to automatically remove old files from Linux temporary directories. The repository was created on August 14, 2026. It carries the description "Automatic /tmp cleaner daemon for Linux (Go)." "We initially discovered the GitHub repository because we observed the attacker setting it up through the link command of the existing reverse_ssh infrastructure we were monitoring," Szadkowski told The Hacker News. "We then analyzed and reverse engineered the binaries published in the repository's releases. This independently confirmed that they were reverse_ssh builds associated with the attacker's infrastructure." Present in the repository is a Linux systemd service that scans the "/tmp" directory and deletes from it any entries, such as files, symlinks, sockets, and others, whose modification time is at least 24 hours old, and repeats it every hour. Given that the majority of the malicious artifacts associated with the intrusions are staged in the "/tmp" location, it's believed that the threat actor may be using the tool as a way to systematically wipe evidence of the intrusion and complicate analysis. What's more, a release version named "tmpclean v3.0.0" has been found to include updated "reverse_ssh" binaries, suggesting an attempt to distribute additional compiled payloads through the GitHub-based vector. It's not clear what drove the threat actor to set up the repository in the first place, although one possibility is that they are actively tracking public disclosure and are attempting to introduce new cleanup mechanisms to fly under the radar. (The story was updated after publication to include additional insights from QUIRSO.)
thehackernews.comAug 17, 2026extracted
When companies get specific about AI, revenue growth looks different
When companies get specific about AI, revenue growth looks different Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples depending on data availability. The data included 478 corporate 10-K filings, more than 30,000 classified job postings, financial information, market data, and the AI Transformation Tracker built by Larridin. The tracker assigns companies scores from 1 to 5 across three areas: AI adoption, workforce proficiency and realized impact. It also provides an overall maturity index. The January 2026 Tracker score vintage contained scores for 562 companies, corresponding to 538 after the researchers’ deduplication process. “Generalized AI investment alone tells us little about a company’s ability to create value,” said Ameya Kanitkar, CTO of Larridin. “What matters is identifying where AI is being deployed, measuring adoption and workforce proficiency, understanding how customers and employees are benefiting, and connecting those efforts to quantifiable business results.” Detailed AI disclosures linked to revenue growth One of the most distinct indicators was what the researchers call “narrative concreteness.” The measure looks at how specifically a business describes its AI deployments and results in regulatory filings. Companies that named AI systems, explained how they were being used and provided measurable outcomes tended to perform better on revenue growth. In the researchers’ adjusted model, companies at the top of the narrative-concreteness distribution were associated with 8.0 percentage points higher year-over-year revenue growth than companies at the bottom. The researchers evaluated adoption, employee proficiency, realized impact, overall AI maturity, investment intensity, AI-focused hiring and the level of detail in corporate disclosures. Six score- and filing-based measures were significantly associated with revenue growth in unadjusted analyses. The hiring measure was not. Several of the broader adoption and composite measures weakened once differences in industry, company size and previous growth were taken into account. Detailed descriptions of AI deployments continued to carry information about revenue growth after those adjustments. Job postings offered another way to examine adoption. A total of 30,861 postings across 536 companies were classified to determine the share of hiring aimed at roles focused on building or operating AI and machine learning systems. The researchers caution that the job-posting data were collected after the revenue period being studied, so the hiring measure should be treated as descriptive evidence rather than a prospective predictor of revenue growth. AI adoption shows little connection to margins Greater signs of AI adoption were not associated with improved operating margins. No significant margin effects were found among the public signals examined. The results provide little evidence of broad operating-margin improvements associated with the AI signals examined. The study did not directly measure individual cost categories or workforce reductions. Stock market performance followed a similar pattern. None of the public AI signals predicted risk-adjusted stock returns over the following four months after controls and adjustments for multiple testing were applied. AI infrastructure providers outperform Companies supplying infrastructure for the AI market produced a different result. AI infrastructure suppliers outperformed sector- and size-matched peers by about 32 percentage points over four months. Five large semiconductor companies, Nvidia, Broadcom, AMD, Micron and Intel, were excluded from the main analysis to prevent their performance during the AI investment boom from having an outsized effect on the results. Running the calculations with those companies included did not change the main conclusions. The relationship between detailed AI disclosures and revenue was particularly useful in asset-heavy industries, where implementation may require changes to physical infrastructure, operations and established processes. Specific descriptions can help distinguish companies that have put AI into use from those still discussing plans or early experiments. The results show association, not causation The results do not establish that AI caused stronger revenue growth. Companies that are already performing well may have more resources to deploy AI, measure its impact and provide detailed information about those deployments. Existing growth trends could also influence subsequent results, although prior revenue growth was among the factors included in the main statistical controls. The work instead identifies a statistical relationship between observable evidence of AI use and revenue growth. The strongest result centers on concrete disclosures rather than broad claims of AI adoption, suggesting that specific information about deployed systems and measurable outcomes may provide a useful signal of how far implementation has progressed. “The study suggests companies are using AI primarily to expand capabilities, improve customer experiences, and create new growth opportunities,” said Shixiang (Woody) Zhu, Assistant Professor at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy. “At this stage, AI’s measurable impact is appearing more clearly in revenue growth than in operating margins or stock performance, indicating that its value goes beyond cost reduction.”
helpnetsecurity.comAug 17, 2026extracted
Scottish prosecutors cast eye over leaky supplier after staff data exposed
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 14, 2026extracted
Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations
Security researchers from Broadcom’s Threat Hunter Team have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber-espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns. In a new report published on August 13, the threat intelligence team – which brought together experts from Symantec and Carbon Black – shed new light on the advanced persistent threat (APT) group, also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049. The researchers revealed that Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia as well as a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals. “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,” the Broadcom report noted. At least one of the operators, likely running what Broadcom described as “the commercial arm of the business,” identified as ‘ople500’ in the group’s control panel, has been identified as using the ‘paopaodada’ (‘bubble boss’) persona. This individual has been advertised on Telegram as the contact for a “website ranking rental” service. Broadcom associated the individual “with high confidence” to a company, described as an SEO business, registered in Changsha, the capital of the Hunan province. The Threat Hunter Team has identified the name of the sole legal representative of this company and assessed that that person supplies access, infrastructure and delivery to the espionage operation rather than being part of the team of operators. Cyber Espionage Targets Jewelbug's cyber espionage operations had already been reported by various threat intelligence teams, including Trend Micro's TrendAI, Palo Alto Networks' Unit 42 and Check Point Research. Researchers found the actor typically gained access through vulnerable IIS and SharePoint servers before deploying web shells and a sophisticated backdoor tracked as VARGEIT, Squidoor or FinalDraft. The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling. After a months-long investigation into some of the threat group’s operations, Broadcom researchers found it has targeted several government organizations across the Middle East and Southeast Asia, with more than 90 police and government email addresses in South Asia. They also found a victim database which recorded more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations. One set of implants was configured to utilize the internal proxy of a major US aerospace and industrial manufacturer. In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once. Crypto Fraud Targets Meanwhile, some of Jewelbug's infrastructure was used to run a cryptocurrency fraud business on the side. The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan. The report added that the common thread across the group's espionage targets was government communications systems and the service providers that host them, potentially providing long-term access to official correspondence. Jewelbug’s Common Infrastructure for Espionage and Fraud At the center of both the espionage and cryptocurrency fraud operations was XG-Web, a browser-based C2 platform that acted as the group's central management console. According to the Broadcom report, the same XG-Web infrastructure was used to administer victims from both campaigns, with implants, stolen data and operator activity all feeding into a shared backend database. One of the primary tools connected to this infrastructure was Antino, the group's Windows backdoor. Antino communicated with operators through the Microsoft Graph API, allowing C2 traffic to blend in with legitimate Microsoft cloud services. The Broadcom report said the malware was used across multiple Jewelbug campaigns and was deployed through fake software installers and themed lures. The group also operated a malicious Chrome and Firefox extension called ‘PDF Viewer,’ which was paired with a helper program disguised as a Microsoft Edge component. The combination gave operators extensive access to victims' browsers, enabling them to steal cookies, credentials and browsing data, while also providing a command shell on the compromised host through a native messaging component. Alongside Antino, Jewelbug used a Linux and router implant known as ClientKing, which supported multiple C2 methods, including DNS tunnelling and provided remote shell access and pivoting capabilities. The researchers noted that ClientKing infrastructure overlapped with the group's wider XG-Web ecosystem, further linking the espionage and fraud operations. Finally, the group also abused Google Docs for payload delivery and C2. When operators launched a campaign, the backend created public Google documents containing obfuscated payloads, which implants would retrieve and execute. By leveraging Google's infrastructure, the group was able to disguise malicious activity as legitimate traffic and reduce the likelihood of detection.
infosecurity-magazine.comAug 14, 2026extracted
New Zealand says China tried using space investments to spy on local affairs
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 14, 2026extracted
Critical VMware vCenter RCE flaw exploited for reverse SSH access
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France. Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that could be exploited by an unauthenticated attacker with network access to execute arbitrary code. The vendor provides no workarounds or mitigations and urges system administrators to apply the emergency update and consult the FAQ post for additional information. The following vCenter releases address the security issue: vCenter 9.1: 9.1.0.0300 vCenter 9.0: 9.0.2.0100 vCenter 8.0: 8.0 U3k or 8.0 U2f, depending on the branch VMware vCenter is a centralized management software for controlling, monitoring, and configuring an organization’s VMware virtual infrastructure, including virtual machines, ESXi servers, configurations, and access permissions. The product is a frequent target for its broad control over multiple critical systems. Attackers can use this access for data theft and operational disruptions. According to digital forensics and incident response (DFIR) company QUIRSO, compromised systems started to connect to attacker-controlled infrastructure on August 3, just five days after Broadcom disclosed the flaw and released the emergency patch. The campaign expanded quickly, with 151 new victim IP addresses being observed on August 4. By the next day, the count of victim IPs reached 343. However, QUIRSO notes that it identified a total of 361 victim IPs by August 7. After obtaining access to vulnerable vCenter systems, the attacker deployed the open-source reverse_ssh framework to establish persistence and gain remote access. The reverse SSH connection provides an outbound command-and-control (C2) channel and can also help bypass firewalls or other network security measures. QUIRSO has released a generic YARA rule that detects reverse_ssh client binaries. It should be noted that legitimate use of the tool also triggers the alert. The researchers believe that an advanced persistent threat (APT) actor is behind the exploitation activity, although they provided no evidence to support this and are withholding specific indicators due to ongoing coordination with law enforcement authorities. QUIRSO plans a more detailed follow-up report that covers the attacker’s infrastructure, techniques, persistence, and post-exploitation activity. BleepingComputer has contacted Broadcom for a statement on QUIRSO’s findings, but we have not received a response by publication time. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 13, 2026extracted
vCenter Flaw Exploited Just Five Days After Disclosure
A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems. The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10. The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries while cautioning that an IP address does not necessarily correspond to a single organization. The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code, turning a service built to collect logs into a route into the operating system. Five Days From Advisory to Compromise Broadcom published advisory relating to the flaw on July 29, stating in an accompanying FAQ that it had not observed exploitation. It revised the advisory on August 3 to add 8.0 U2f express patches. Quirso's team said they first observed compromised systems contacting attacker infrastructure on August 3. The following day brought 151 further victim IPs, and by August 5 roughly 95% of the 361 total had appeared. Germany, the United States, Turkey, Iran and France accounted for 185 of them. While the attacker may have had prior knowledge of the flaw, Quirso said the strong correlation between disclosure and exploitation points to the advisory as the campaign's starting point. Two Clocks to Manage For persistence the actor deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing. Because it dials outward rather than accepting inbound connections, it can bypass controls designed to block unsolicited inbound access. QUIRSO stressed that its presence alone is not proof of compromise. Jason Soroko, senior fellow at certificate lifecycle management (CLM) provider Sectigo, said patching would not resolve the incident by itself. "There are therefore two clocks to manage," he said, one for closing the vulnerability and one for evicting anyone who entered before the patch. Broadcom has not published a workaround. Fixed vCenter releases are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the deployed branch, and address both critical vCenter flaws in the advisory, the exploited directory traversal and an authentication bypass in VMware Directory Service.
infosecurity-magazine.comAug 13, 2026extracted
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Threat actors have started exploiting a recently patched critical-severity vulnerability in VMware vCenter, rapid incident response company Quirso reports. The bug was disclosed on July 29, when Broadcom patched it alongside four other security defects in multiple VMware products. Tracked as CVE-2026-59310 (CVSS score of 9.8), the flaw is described as a directory traversal issue in the Syslog server that leads to remote code execution. “A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code,” Broadcom’s advisory reads. According to Quirso, an advanced persistent threat (APT) actor has been exploiting web-accessible VMware vCenter servers vulnerable to CVE-2026-59310, using a reverse shell for persistent access. The cybersecurity company identified over 360 victim IP addresses across 47 countries, half of which are distributed across only five countries: Germany, the US, Turkey, Iran, and France. “The exact number of victim organizations cannot be inferred from these IP addresses, as an IP address does not necessarily correspond to a unique company or physical system. Some addresses belong to hosting providers, cloud networks, or shared infrastructure,” Quirso says. According to the company, the exploitation started on August 3, with over 340 victim IP addresses seen connecting to the attackers’ infrastructure by August 5. “While the attacker might have had prior knowledge of the vulnerability, the strong correlation between the time of disclosure and exploitation suggests the disclosure as the initial starting point for the campaign,” Quirso notes. Following initial compromise, the attackers dropped the open source SSH reverse shell framework reverse_ssh to maintain an outbound control connection from the compromised systems, bypassing security controls that typically block inbound connections. Quirso released a generic YARA rule for identifying reverse_ssh builds. As the tool can also be used for legitimate penetration testing, organizations with publicly accessible vCenter systems are advised to validate any detections by also looking for unauthorized installations and unexpected outbound connections and execution. Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Related: Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
securityweek.comAug 13, 2026extracted
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 12, 2026extracted
Brit rail cops bring live facial recognition to the London Underground
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 12, 2026extracted
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were released by Broadcom late last month. The German cybersecurity company said it discovered the activity following an incident response engagement. The attack chain is said to have exhibited path traversal activity consistent with the flaw, followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh, an open-source tool used for setting up SSH connections to threat actor-controlled infrastructure. Compromised systems identified by QUIRSO were found to first establish contact with the attacker's domains on August 3, five days after Broadcom publicly disclosed the flaw. In all, there are as many as 361 unique victim IP addresses located across 47 countries. Most of them are located in Germany, the U.S., Turkey, Iran, and France. "While the attacker might have had prior knowledge of the vulnerability, the strong correlation between the time of disclosure and exploitation suggests the disclosure as the initial starting point for the campaign," QUIRSO added. It's not clear who is behind the exploitation campaign, but it's believed to be the work of a suspected advanced persistent threat (APT) actor. It's worth pointing out that VMware appliances have been a lucrative target for Chinese threat actors like UNC5174, who have weaponized security flaws impacting VMware Tools and VMware vCenter in various espionage campaigns. In April 2025, SentinelOne disclosed details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts. The use of reverse_ssh is notable as it allows the attacker to establish an outbound connection to an endpoint under their control, effectively bypassing security controls designed to prevent suspicious inbound requests. "The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity," QUIRSO noted. "In combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, however, it is a high-priority indicator requiring investigation." The disclosure comes as Defused Cyber said it's observing a spike in scanning against VMware vCenter that is indicative of potential exploitation efforts targeting CVE-2026-59309 (CVSS score: 9.8). "Our honeypots are logging increased fingerprinting – such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow – coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8)," the cybersecurity company said. Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310. "What we can say with much higher confidence is that the activity we investigated represents a successful compromise rather than merely exploitation attempts, and the forensic evidence strongly points toward CVE-2026-59310 as the initial access vector," Szadkowski added.
thehackernews.comAug 12, 2026extracted
Cybersecurity jobs available right now: August 11, 2026
Cybersecurity jobs available right now: August 11, 2026 CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection logic, deploying and tuning analytics, maintaining cyber threat intelligence workflows, and continuously improving detections to keep pace with evolving adversary tactics, techniques, and procedures (TTPs). Cloud Solution Architect Tata Consultancy Services | Canada | On-site – View job details As a Cloud Solution Architect, you will design secure, scalable cloud and application architectures with a focus on modern frontend development, identity and access management, API security, and authentication technologies such as MFA, SSO, OAuth2, JWT, and OpenID Connect. You will collaborate with engineering, security, and DevOps teams to implement enterprise security controls, conduct security reviews and threat modeling, and ensure compliance with security standards. Cyber Defense Incident Responder EY | USA | On-site – View job details As a Cyber Defense Incident Responder, you will coordinate responses to cyber incidents caused by external threats, collaborate with internal and external stakeholders, support incident management programs, lead small to medium-sized projects, develop and maintain incident response processes, playbooks, and documentation, prepare leadership communications and metrics, manage the team’s knowledge base, and participate in an on-call rotation to support incident response outside normal business hours. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Security Engineer Broadcom | USA | On-site – No longer accepting applications As a Cyber Security Engineer, your responsibilities include responding to cyber security incidents through detection, containment, and remediation, conducting proactive threat hunting, developing and tuning new threat detections, integrating log sources with the SIEM platform, and building and managing security automation playbooks. Cyber Security Specialist – Blue Team HBX Group | Spain | Hybrid – View job details As a Cyber Security Specialist – Blue Team, you will protect the organization’s security posture by detecting and responding to cyber threats, conducting threat hunting, managing vulnerabilities, securing cloud and AI environments, supporting incident response, and collaborating with cross-functional teams to strengthen security through proactive engineering and automation. Cybersecurity Manager Unity Infotech | UAE | On-site – No longer accepting applications As a Cybersecurity Manager, you will lead cybersecurity engineering and DevSecOps initiatives by embedding security into the SDLC and CI/CD pipelines, driving application security and cloud security programs across Azure and AWS, establishing AI security governance frameworks, managing enterprise security tools, ensuring regulatory compliance, collaborating with cross-functional teams to deliver secure technology solutions, and mentoring cybersecurity engineering teams while fostering continuous improvement. Director of IT Security ETAP | USA | Hybrid – View job details As a Director of IT Security, you will lead the organization’s security strategy, governance, and risk management programs, establish security policies and controls, oversee compliance, audits, and regulatory requirements, provide security architecture guidance across cloud, identity, networks, and applications, lead incident response and business continuity planning, manage third-party security risks. Manager, Threat Remediation Pfizer | USA | Hybrid – No longer accepting applications As a Manager, Threat Remediation, you will lead the organization’s threat remediation program by prioritizing and coordinating the resolution of cybersecurity threats and exposures. You will work with security, engineering, infrastructure, and business teams to develop remediation plans, track progress, validate outcomes, and support the response to high-severity incidents. Network Security Specialist Candescent | USA | On-site – View job details As a Network Security Specialist, you will define and execute the organization’s network security strategy, design and manage secure network architectures across cloud and on-premises environments, oversee firewall and secure connectivity technologies, integrate security into infrastructure and DevOps workflows, ensure compliance with security standards and regulations, maintain technical documentation, support audits and risk assessments, and lead cross-functional initiatives while mentoring network security engineers and promoting secure-by-design practices. Security Analyst – Tier 3 Nebius | Israel | On-site – View job details As a Security Analyst – Tier 3, you will lead complex investigations from initial scoping through technical analysis, impact assessment, and root-cause determination. You will serve as the SOC’s senior escalation point, support incident response, improve investigation methods and tooling, mentor Tier 1 and Tier 2 analysts, collaborate with security teams to strengthen detection and response, participate in readiness exercises, and provide senior on-call support outside business hours. Security Tool Management Specialist Kapalins | India | Remote – No longer accepting applications As a Security Tool Management Specialist, you will administer, configure, and optimize the organization’s security tool stack, including vulnerability management, GRC, DLP, PAM, EDR/XDR, email security, and SIEM integrations. You will monitor tool performance, support remediation and compliance efforts, maintain security workflows and reporting, collaborate with security and IT teams to improve security operations, and manage tool lifecycle activities, including upgrades, vendor relationships, and licensing. Senior Cybersecurity Engineer Modine Manufacturing Company | USA | Remote – No longer accepting applications As a Senior Cybersecurity Engineer, you will design, implement, and manage enterprise security technologies across endpoint, identity, email, cloud, vulnerability management, SSE/SASE, and security monitoring platforms, while supporting upgrades, integrations, and deployments. Senior Engineer, Network Observability CoreWeave | Ireland | Hybrid – View job details As a Senior Engineer, Network Observability, you will develop and maintain scalable network observability platforms, build telemetry and automation solutions using Python and Golang, integrate logs and metrics across network infrastructure, enhance monitoring and alerting capabilities, collaborate with engineering and operations teams to improve network visibility and reliability, participate in on-call support, and mentor junior engineers. Staff Hardware Security Engineer Arm | United Kingdom | Hybrid – View job details As a Staff Hardware Security Engineer, you will assess the security of SoC hardware components and security features, identify and validate hardware vulnerabilities through architecture reviews and hands-on testing, develop proof-of-concept demonstrations, create tools and methodologies for hardware security evaluation, and collaborate with architecture, silicon, firmware, and platform teams to communicate findings and implement effective mitigations. Technical Cyber Threat Investigator Anthropic | USA | On-site – View job details As a Technical Cyber Threat Investigator, you will detect and investigate attempts to misuse Anthropic’s AI systems for cyber operations, develop threat detection strategies, produce actionable threat intelligence, conduct cross-platform investigations, improve safety measures based on investigation findings, research emerging AI threats, collaborate with external intelligence partners, and help build Anthropic’s threat intelligence program. Threat Analyst ThreatLocker | USA | On-site – No longer accepting applications As a Threat Analyst, you will research and investigate emerging cybersecurity threats, track threat actors and their tactics, analyze malware and attack campaigns, produce technical threat intelligence and research reports, identify detection gaps, collaborate with detection engineering to improve threat coverage.
helpnetsecurity.comAug 11, 2026extracted
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 9, 2026extracted
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 7, 2026extracted
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 7, 2026extracted
IBM's agentic AI platform is under active attack - patch now
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 5, 2026extracted
VMware製品にCVSS 9.8の脆弱性、回避策なし 速やかなアップデートを推奨
Broadcom��VMware���i�Q�ɑ��݂���5���̐Ǝ㐫���C�������BvCenter�ł͍ō��[���xCVSS 9.8�̔F�؉����C�ӃR�[�h���s�̌��ׂ��m�F����Ă���B�����͗p�ӂ���Ă��炸�A���₩�ȃp�b��K�p�����߂���B ���̋L������������ł��B����o�^����ƑS�Ă������������܂��B �@Broadcom��2026�N7��29���i���n���ԁj�A�uVMware ESX�v�uVMware vCenter Server�v�uVMware Workstation�v�uVMware Fusion�v�ɑ��݂���5���̃Z�L�����e�B�Ǝ㐫���C�������B �@�Ώۂɂ́uVMware Cloud Foundation�v�uVMware vSphere Foundation�v�uVMware Telco Cloud Platform�v�uVMware Telco Cloud Infrastructure�v���܂܂��B���ʐƎ㐫�]���V�X�e���iCVSS�jv3�̃X�R�A�͈͂�2.7�9.8�B�����͗p�ӂ���Ă��炸�ABroadcom�͊Y���łւ̏C���p�b��K�p��������ɋ������B �@vCenter�ɉe������ł��[����2���̌��ׁiCVSS 9.8�j�𒆐S�ɁAESXi��Workstation�^Fusion���܂ޑS5���̐Ǝ㐫�T�v�Ƃ��ꂼ��̏C���ŏ����܂Ƃ߂�B �@�uCVE-2026-59309�v��VMware Directory Service�̔F�؉���̌��ׁB�l�b�g���[�N�o�R��vCenter�ڑ��\�ȍU���҂��F���I�A�V�X�e���֕s���A�N�Z�X���鋰�ꂪ����BCVSS v3.1�̃X�R�A�l��9.8�ŁA�[���x�ً͋}�iCritical�j�ƕ]������Ă���B�uCVE-2026-59310�v��Syslog�T�[�o�̃f�B���N�g���g���o�[�T���̌��ׂŁA�������l�b�g���[�N�ڑ����\�ȍU���҂ɂ��C�ӃR�[�h���s�ɂȂ���B�[���x��CVE-2026-59309�Ɠ������B �@�C���ł́AvCenter 9.1�n���u9.1.0.0300�v�A9.0�n���u9.0.2.0100�v�A8.0�n���u8.0 U3k�v�܂��́u8.0 U2f�v�ƂȂ�B�Ȃ��A9.1�n�ɂ�����CVE-2026-59309�̓o�[�W����9.1.0.0200�ŏ��߂ďC�����ꂽ���A���݂͍ŐV�̗ݐύX�V�v���O�����ł���9.1.0.0300�̓K�p�����������B �@ESX�ł�VMXNET3���z�l�b�g���[�N�A�_�v�^�[�̋��E�O�������݂̌��ׁuCVE-2026-47876�v�����������BVMXNET3����������z�}�V���Ń��[�J���Ǘ��Ҍ��������U���҂́A�z�X�g��ŃR�[�h�����s���鋰�ꂪ����BVMXNET3�ȊO�̉��z�A�_�v�^�[�͉e�����Ȃ��BCVSS v3.1�̃X�R�A�l��9.3�ŁA�[���x�ً͋}�iCritical�j�ƕ]������Ă���B �@�C���ł́AESX 9.1�n���uESXi-9.1.0.0200-25557999�v�A9.0�n���uESXi-9.0.2.0100-25595025�v�A8.0�n���uESXi80U3k-25595708�v�܂��́uESXi80U2f-25626445�v�ƂȂ�B �@�uCVE-2026-41703�v��ESX�AWorkstation�AFusion�̋��E�O�ǂݎ��̌��ׁB���z�}�V���̔z�����������U���҂����E�O�ǂݎ����N�����A���R������z�X�g�v���Z�X�̃T�[�r�X���ۂ��������ꂪ����BWorkstation��Fusion�ł͉e�������R�����T�O�Ɍ�����BCVSS v3.1�̃X�R�A�l��7.6�ƕ]������Ă���B �@Workstation 25H2��Fusion 25H2�ł̓X�R�A�l��2.7�Ƃ���A�C���ł͂�������u26H1�v�ƂȂ�B �uCVE-2026-41709�v��ESX�̃��O�L�^�s���̌��ׁB���ӂ���Ǘ��҂�����̑�����L�^�Ɏc�������{���鋰�ꂪ����BCVSS v3.1�̃X�R�A�l��2.7�B �@�C���ł́AESX 9.1�n���uESXi-9.1.0.0-25370933�v�A9.0�n���uESXi-9.0.2.0100-25595025�v�A8.0�n���uESXi80U3j-25429389�v�ƂȂ�B�Ȃ��ACloud Foundation 5.x��ʐM���Ǝҗp���i�ɂ͔��p�b��菇��ʂ̃i���b�W�x�[�X��������Ă���B �@Broadcom�͑S5���̐Ǝ㐫�ɂ��đ�֍�������Ă��炸�A�Ώۊ��ɉ������C���ł̓������A�i�E���X�����B�e�����郆�[�U�[�͑��₩�ɍX�V�����������B Copyright © ITmedia, Inc. All Rights Reserved.
itmedia.co.jpAug 5, 2026extracted
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Research. "The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0[.]143:8080," researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared with The Hacker News. Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to compromised systems. The activity has not been attributed to any known threat actor or group. The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan. Securonix said its investigation commenced following the discovery of a live WsgiDAV server that served two purposes: stage malicious payloads and maintain command-and-control (C2) over existing infected machines through a ScreenConnect relay on port 8041. An analysis of the ScreenConnect relay configuration strings embedded in the MSI and EXE payloads has uncovered three distinct C2 clusters, each associated with software update, document review, and document viewer decoy binaries. The initial access vector is assessed to be spear-phishing, with the emails serving as a conduit for an obfuscated Visual Basic Script (aka VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes, and aborts if any of the following executables are running - Wireshark (wireshark.exe) Process Monitor (procmon.exe) Oracle VM VirtualBox (vboxservice.exe) Broadcom VMware Tools (vmtoolsd.exe) Citrix XenServer (xenservice.exe) Fiddler Classic (fiddler.exe) If the environment checks pass, the script proceeds to decrypt a PowerShell command that fetches a C# payload from "207.189.11[.]170" and executes it. Alternatively, attacks have been observed using business-themed lures to trick recipients into running a VBScript that ultimately leads to ScreenConnect installation. A third sample linked to the activity is delivered as a compressed archive, from which a batch script is run to disable Windows Antimalware Scan Interface (AMSI), escalate privileges by means of a User Account Control (UAC) prompt, turn off SmartScreen protections via Registry modifications, and then remove the Zone.Identifier alternate data stream (ADS) from the downloaded MSI file before running it. "The actor's delivery strategy has also rotated across multiple trusted hosting services," Securonix said. "An early phishing page ('zoom-update.html') delivers its payload via a Dropbox shared link, bypassing domain reputation filters since Dropbox is an allow-listed platform in most corporate environments." "A compiled .NET loader ('MemoryLoader.cs') references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure that is rarely monitored. The staging server itself runs cloudflared.exe, confirming that the actor uses the Cloudflare binary directly on their infrastructure to generate these ephemeral tunnels." Irrespective of the phishing lure used, all attack paths lead to the same destination: the installation of ScreenConnect client, which connects to a configured relay server and allows the operator to open a remote desktop session with the victim's machine. "What makes this campaign particularly notable for defenders is the observable arc of the actor's tradecraft," Securonix said. "From cautious XOR-encrypted VBScript droppers to aggressive nine-step Defender destruction sequences and then, most recently, a pivot back to stealth with anti-EDR timing and self-contained encrypted bundles, the campaign reads like a real-time arms race between attacker and defender." To counter the threat, organizations are recommended to restrict execution of untrusted MSI files, monitor when processes attempt to tamper with security products, audit legitimate use of RMM tools, check for suspicious PowerShell and "cmd.exe" processes, and enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks. Fake Xeno Roblox Cheats Deliver Java Stealer Malware The disclosure comes as Bitdefender warned of a separate campaign in which fake Xeno Executor installers promoted via gaming forums and Discord communities are used to initiate a multi-stage Java infection chain that drops an information stealer capable of credential theft, as well as stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information. The stealer, named Powercat, can also record keystrokes, access the webcam, stream the victim's desktop, manipulate files, run PowerShell commands, and grant attackers interactive control of the infected computer. "The final payload combines information theft, surveillance, persistence, remote access, file manipulation and command execution," Bitdefender researchers Janos Gergo Szeles and Silviu Stahie said. The activity is believed to have been ongoing since the start of 2026, with a surge recorded in the second half of March. Some aspects of the campaign were previously documented by ThreatLocker in late March 2026, highlighting the threat actor's use of bogus cheats for popular PC games to distribute Powercat. The so-called cheats come in the form of archives that mimic a legitimate Xeno installation using plausible file names. Victims are instructed to run a "xeno.exe," which, instead of launching the cheat, runs the first stage of the malware. The payload checks for a Java Runtime Environment, extracts one if missing, and then reads a local file ("XenoIcon.jpg") containing the keys necessary to validate its execution with the C2 server ("solthere[.]net"). Subsequently, it launches an obfuscated JAR file disguised as "decompiler.exe," which performs environment checks, registers the victim, and downloads the final malware payload. The third stage is a Java-based stealer and surveillance malware that can harvest sensitive data, collect screenshots and webcam footage, stream the victim's desktop, and monitor keyboard and mouse activity. It can also download and upload files, execute commands through PowerShell, and open an interactive shell for hands-on-keyboard access, giving the attacker full control over the host. "Personal information theft begins with the malware gathering information about potentially interesting software installed on the victim's system," Bitdefender said. "This allows the operators to adapt their strategy and prioritize which data to steal." Targeted applications include - Web browsers (Brave Browser, Chrome, Edge, Opera, Opera GX, and Vivaldi) Cryptocurrency wallets (Atomic, Cake Wallet, Exodus, Monero Wallet, SafePal, and Tron Wallet) Software development tools (Git, JetBrains tools, Microsoft Visual Studio, and Python IDLE) Game launchers (Battle.net, Epic Games Launcher, Riot Client, Rockstar Games Launcher, and Steam) VPN (ExpressVPN, Mullvad VPN, NordVPN, and Surfshark) Messengers (Discord, Snapchat, Telegram, and WhatsApp) Roblox and Minecraft installations (Feather, Lunar, Meteor, Modrinth, Prism, and the official Minecraft launcher) To target Exodus cryptocurrency wallets, the stealer checks if Exodus version 26.1.5 is installed on the system, and, if so, unpacks the "app.asar" archive and injects JavaScript code to capture valid tokens and exfiltrate them to the C2 server. "Gaming-related lures remain effective because they exploit users' interest in gaining an advantage, accessing restricted functionality, or avoiding anti-cheat detection," Bitdefender said. "The delivered malware is considerably more capable than a typical credential stealer. Its remote-access and command-execution capabilities also mean that the compromise can continue beyond the initial theft of information, which can lead to data destruction or allow operators to use the infected system in other cyber-criminal activities."
thehackernews.comAug 4, 2026extracted
Tennessee congressional hopeful accused of shooting license plate cameras
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 4, 2026extracted
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comAug 4, 2026extracted
VMware管理基盤に“認証突破”の穴 Broadcom「回避策を用意せず」
Broadcom��VMware���i�ɑ��݂���5���̐Ǝ㐫���C�������BvCenter�ɂ͔F�؉����C�ӃR�[�h���s�ɂȂ���d��Ȗ�肪�܂܂�A�S�Ă̐Ǝ㐫�ʼn����͗p�ӂ���Ă��Ȃ��B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@Broadcom��2026�N7��29���i���n���ԁj�A�uVMware ESX�v�uVMware vCenter�v�uVMware Workstation�v�uVMware Fusion�v�ɑ��݂���F�؉����C�ӃR�[�h���s�Ȃnjv5���̐Ǝ�i�������Ⴍ�j�����C������X�V�v���O���������J�����B �@�Z�L�����e�B�A�h�o�C�U���[�uVMSA-2026-0006�v�̐[���x�́u�ً}�v�iCritical�j�ŁA�ΏۂƂȂ�Ǝ㐫��CVSS v3��{�l��2.7�9.8���B�e�����鐻�i�ɂ́uVMware Cloud Foundation�v�uVMware vSphere Foundation�v�uVMware Telco Cloud Platform�v�uVMware Telco Cloud Infrastructure�v���܂܂��B�e�Ǝ㐫��Broadcom�ɔ���J�ŕ���A���Ђ͑Ώې��i�����̏C���ł�����B �@�C�����ꂽ5���̂����A3���͐[���x���u�ً}�v�iCritical�j�ƕ]������Ă���B �@CVE-2026-59309�́AvCenter�́uVMware Directory Service�v�ɑ��݂���F�؉���̐Ǝ㐫�ŁACVSS v3��{�l�͍ő�9.8���BvCenter�Ƀl�b�g���[�N�o�R�ŃA�N�Z�X�\�ȍU���҂����p�����ꍇ�A�F��������ăV�X�e���ɕs���A�N�Z�X����\��������B�����͂Ȃ��ABroadcom�̓A�h�o�C�U���[�̑Ή��\�ɋL�ڂ����C���ł̓K�p�����߂Ă���B�⑫FAQ�����J�ς݂��B �@Broadcom�ɂ��ƁA�C���v���O�����͗ݐό���Œ����BCVE-2026-59309��vCenter 9.1.0.0200�ŏ��߂ďC������Ă���A�����_�̍ŐV�łƂȂ�9.1.0.0300�ɂ��C�����e���܂܂��B�ߋ��̏C�����܂ލŐV�̏C���łɍX�V���邱�ƂŁA���̐Ǝ㐫�ɑΏ��ł���B �@CVE-2026-59310�́AvCenter��Syslog�T�[�o�ɑ��݂���f�B���N�g���g���o�[�T���̐Ǝ㐫���BCVSS v3��{�l�͍ő�9.8�ŁA�[���x�u�ً}�v�iCritical�j���BvCenter�Ƀl�b�g���[�N�o�R�ŃA�N�Z�X�\�ȍU���҂����p����ƁA�C�ӂ̃R�[�h�����s�ł���B�����͂Ȃ��ABroadcom�͑Ή��\�Ɏ������C���ł̓K�p�����߂Ă���B �@CVE-2026-47876�́AESX�̉��z�l�b�g���[�N�A�_�v�^�[�uVMXNET3�v�ɑ��݂��鋫�E�O�������݂̐Ǝ㐫�ŁACVSS v3��{�l�͍ő�9.3�A�[���x�u�ً}�v�iCritical�j���BVMXNET3���g�p���鉼�z�}�V�����ŊǗ��Ҍ������擾�����U���҂����p�����ꍇ�A�z�X�g��ŃR�[�h�����s�ł���\��������B���z�}�V������n�C�p�[�o�C�U�[�i�z�X�g�j�ɉe�����y�ԋ��ꂪ����_�ɒ��ӂ������B�Ȃ��AVMXNET3�ȊO�̉��z�l�b�g���[�N�A�_�v�^�[�͉e�����Ȃ��B�Ώ��ɂ͏C���ł̓K�p���K�v�ŁA�����͒���Ă��Ȃ��B �@�c��2���̂����ACVE-2026-41703��ESX��Workstation�AFusion�ɑ��݂���u���E�O�ǂݎ��v�̐Ǝ㐫���B�[���x�́u�d�v�v�iImportant�j�ŁACVSS v3��{�l�͍ő�7.6�B�U���҂����z�}�V�����쐬�E�z���ł��錠���������Ă���ꍇ�A���̐Ǝ㐫�����p���邱�ƂŁA�{���A�N�Z�X�ł��Ȃ��������̓��e��ǂݎ���\��������B���̌��ʁA�@����R�������鋰�ꂪ����B �@ESX�ł͏��R�����ɉ����A�z�X�g���̃v���Z�X����~����ȂǁADoS��ԂɊׂ�\��������B������Broadcom�́A���ۂɂ͏��R���������T�[�r�X���ۂ���������\���̕��������Ƃ��Ă���B����AWorkstation��Fusion�őz�肳���e���͏��R�����Ɍ����ADoS�̉e���͂Ȃ��B������̏ꍇ�������͂Ȃ��A�C���ł̓K�p���K�v�ƂȂ�B �@CVE-2026-41709�́AESX�̃��O�L�^���s�\���ȐƎ㐫�ŁA�[���x�u��v�iLow�j�ACVSS v3��{�l�͍ő�2.7���B���ӂ̂���Ǘ��҂����p�����ꍇ�A�ꕔ�̑�����č����O�֎c�������s�ł���\��������BBroadcom�͂��̖��ɂ��Ă��Ή��\�ɋL�ڂ����C���ł̓K�p�𐄏����Ă���A�����͒��Ă��Ȃ��B �@����̃A�h�o�C�U���[�ł́A�F�؉����C�ӃR�[�h���s�A�z�X�g��ł̃R�[�h���s�A���R�����ADoS�A�č����O�̌����ɂȂ���v5���̐Ǝ㐫�������Ă���B���ł�vCenter��2���́A�l�b�g���[�N�o�R�ŃA�N�Z�X�\�ȍU���҂ɂ�鈫�p��z�肵�Ă���A�������CVSS v3��{�l��9.8�Ƌɂ߂č����B�܂��AESX��VMXNET3�ɑ��݂���Ǝ㐫���A���z�}�V�����̊Ǘ��Ҍ����𑫊|����Ƀz�X�g�։e�����y�ԉ\�������邱�Ƃ���A�D��x�̍����Ή������߂���B �@Broadcom��5���S�Ăɂ��ĉ�������Ă��炸�A�C���ł̓K�p��B��̑�Ƃ��Ĉē����Ă���BVMware���i���^�p����g�D�́AVMSA-2026-0006�̑Ή��\�Ŏ��Њ����e�����邩�ǂ������m�F���A�Ώۃo�[�W�����𗘗p���Ă���ꍇ�͑��₩�ɍX�V�����{�������B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpAug 3, 2026extracted
3rd August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal officials previously posted warning regarding targeting of critical infrastructure by Iranian-affiliated threat actors. Bank of Baroda, a major Indian bank, has disclosed an email account compromise that exposed internal communications and attachments. Reports claim more than 700GB of customer files, loan documents, and audit records were leaked, although the bank has not confirmed the reported volume. Core banking systems were unaffected. Amgen, a US biotechnology company that develops medicines for serious illnesses, has confirmed a breach involving cloud environments operated by third-party providers. Attackers exfiltrated proprietary corporate information and patient health data. The company reported no disruption to manufacturing, financial reporting, products, or its ability to supply medicines. Angola’s largest telecommunications provider, Unitel, has suffered a cyberattack that disrupted voice, mobile data, and internet services for millions of customers. The outage also affected electronic payments shortly before the company’s stock market debut. Network data indicated that internal systems were disabled while external routers remained online. AI THREATS Anthropic has disclosed that Claude-based cybersecurity models gained unauthorized access to systems belonging to three outside organizations during controlled evaluations. The models moved beyond intended test environments and reached sensitive production assets. Anthropic identified the incidents while reviewing testing practices following separate autonomous AI security failures. Researchers have published details of CVE-2026-59726, a critical vulnerability in the Ruflo AI agent platform. An unauthenticated attacker could abuse its exposed Model Context Protocol bridge to execute commands, steal API keys, access conversations, and alter stored AI memory. Ruflo addressed the issue in version 3.16.3. Researchers surfaced a privacy issue in Anthropic’s Claude sharing feature that allowed publicly shared conversations and artifacts to be indexed by search engines. Indexed content reportedly included personal information, resumes, financial records, access codes, API keys, and clinical trial material that users may not have expected to become searchable. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20316, an actively exploited vulnerability in Secure Firewall Management Center. The flaw allows unauthenticated attackers to access a built-in low-privileged account and retrieve sensitive information from affected systems. Cisco released hotfixes after exploitation was identified, and the vulnerability was added to CISA’s catalog. Broadcom has released patches for five vulnerabilities affecting VMware vCenter, ESX, Workstation, and Fusion. Three critical flaws could allow authentication bypass, arbitrary code execution, or escape from a virtual machine to its host. The issues include CVE-2026-59309 and CVE-2026-59310, both carrying CVSS scores of 9.8. JetBrains has released fixes for CVE-2026-63077, a critical authentication bypass affecting all TeamCity On-Premises versions. A remote unauthenticated attacker could execute code with TeamCity server privileges and compromise connected build environments. The flaw is fixed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud was not affected. Rails maintainers have patched CVE-2026-66066, a critical Active Storage vulnerability affecting applications that use libvips. An unauthenticated attacker could read sensitive server files and, under some conditions, execute code remotely. Fixed Active Storage releases include versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. THREAT INTELLIGENCE REPORTS Check Point researchers have revealed a phishing campaign that abuses Microsoft’s legitimate login and consent process through attacker-controlled applications. More than 200 emails targeted approximately 120 organizations within one month. Successful authorization provided access to mailboxes, files, Teams, SharePoint, OneDrive, and calendar information. Researchers traced CaptiveCrunch, a campaign attributed to Russia-linked Storm-2945, also known as Midnight Blizzard. The attackers compromised hotel and conference captive portals to distribute CornFlake and ChocoShell malware. The campaign harvested Microsoft 365 and Azure AD authentication tokens, enabling account access and session takeover. Researchers profiled a Russian-linked campaign exploiting CVE-2026-42897 in Microsoft Outlook Web Access against government and industry targets in the United States and Europe. Opening a malicious email triggers installation of OWAReaper, a browser implant that steals credentials and maintains mailbox access after passwords are changed or devices reimaged. Researchers uncovered a npm supply chain campaign involving malicious packages that imitated private Alibaba modules. Layered dependencies retrieved attacker instructions from GitHub and installed operating system-specific RAT payloads. The malware enabled command execution, file theft, credential access, and movement through DingTalk and related development environments.
research.checkpoint.comAug 3, 2026extracted
Anthropic and OpenAI are competing to see whose agents can go rogue harder
DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency SYSTEMS AMD inches closer to its goal of making AI suck less ... energyHouse of Zen claims latest systems already 4x more efficient than two years ago Google pits Marvell against Broadcom as it chases AI crownAnd Marvell just offered the Chocolate Factory a $12.2B stake to sweeten the deal SYSTEMS Cerebras CS-4 rack systems juice chips for every last drop of AI performanceNext-gen systems double per-chip performance while cramming 3x as many into a rack Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comJul 31, 2026extracted
USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - RNBD block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clocksource drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Tegra memory controller driver; - Multifunction device drivers; - IBM Advanced System Management driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Ethernet bonding driver; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - MediaTek network drivers; - Near Field Communication (NFC) drivers; - NTB driver; - NVDIMM (Non-Volatile Memory Device) drivers; - NVME drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Broadcom BCM2835 power domain driver; - Power supply drivers; - RapidIO drivers; - Remote Processor subsystem; - RPMSG subsystem; - SCSI subsystem; - Freescale SoC drivers; - Texas Instruments SoC drivers; - SPI subsystem; - Greybus lights staging drivers; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - SM750 framebuffer staging driver; - TCM subsystem; - TTY drivers; - UFS subsystem; - Cadence USB3 driver; - USB Device Class drivers; - ULPI bus; - USB core drivers; - DesignWare USB2 driver; - USB Gadget drivers; - USB Host Controller drivers; - Mustek MDC800 USB digital camera driver; - USB YUREX driver; - Renesas USBHS Controller drivers; - Framebuffer layer; - Xen hypervisor drivers; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - EROFS file system; - Ext4 file system; - F2FS file system; - FAT file system; - FUSE (File system in Userspace); - GFS2 file system; - HFS+ file system; - JFS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - OCFS2 file system; - Proc file system; - Pstore file system; - Diskquota system; - SMB network file system; - SquashFS file system; - UDF file system; - XFS file system; - Audit subsystem; - RAS (Reliability, Availability, Serviceability) subsystem; - Software nodes and device properties; - Memory Management; - KVM subsystem; - Memory management; - PPP protocol drivers and compressors; - Linux Security Modules (LSM) Framework; - Network traffic control; - Bluetooth subsystem; - MAC80211 subsystem; - Netfilter; - IP tunnels definitions; - Tracing infrastructure; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Control group (cgroup); - Kernel fork() syscall; - Kernel futex primitives; - Kernel kexec() syscall; - Kernel module support; - Scheduler infrastructure; - Cryptographic library; - KASAN memory debugging framework; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - CAIF protocol; - CAN network layer; - Ceph Core library; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - Management Component Transport Protocol (MCTP); - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - NFC subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - RF switch subsystem; - Rose network layer; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - Stream parser; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - eXpress Data Path; - AppArmor security module; - Simplified Mandatory Access Control Kernel framework; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - AudioScience HPI driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - SoC audio core drivers; - STI ASoC drivers; - USB sound devices; (CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116, CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545, CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865, CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715, CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221, CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719, CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863, CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006, CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562, CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748, CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103, CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256, CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161, CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274, CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031, CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141, CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220, CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228, CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270, CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286, CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293, CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303, CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318, CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367, CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391, CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425, CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446, CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454, CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467, CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480, CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494, CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540, CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565, CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585, CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701, CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726, CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763, CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015, CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046, CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089, CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242, CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281, CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357, CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420, CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439, CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484, CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860, CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883, CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899, CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912, CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920, CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941, CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956, CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974, CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002, CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015, CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037, CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053, CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072, CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088, CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137, CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189, CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206, CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219, CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231, CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238, CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259, CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274, CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319, CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914, CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920, CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926, CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011, CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088, CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128, CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294, CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306, CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379, CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102, CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153, CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221)
ubuntu.comJul 31, 2026extracted
USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - RNBD block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clocksource drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Tegra memory controller driver; - Multifunction device drivers; - IBM Advanced System Management driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Ethernet bonding driver; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - MediaTek network drivers; - Near Field Communication (NFC) drivers; - NTB driver; - NVDIMM (Non-Volatile Memory Device) drivers; - NVME drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Broadcom BCM2835 power domain driver; - Power supply drivers; - RapidIO drivers; - Remote Processor subsystem; - RPMSG subsystem; - SCSI subsystem; - Freescale SoC drivers; - Texas Instruments SoC drivers; - SPI subsystem; - Greybus lights staging drivers; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - SM750 framebuffer staging driver; - TCM subsystem; - TTY drivers; - UFS subsystem; - Cadence USB3 driver; - USB Device Class drivers; - ULPI bus; - USB core drivers; - DesignWare USB2 driver; - USB Gadget drivers; - USB Host Controller drivers; - Mustek MDC800 USB digital camera driver; - USB YUREX driver; - Renesas USBHS Controller drivers; - Framebuffer layer; - Xen hypervisor drivers; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - EROFS file system; - Ext4 file system; - F2FS file system; - FAT file system; - FUSE (File system in Userspace); - GFS2 file system; - HFS+ file system; - JFS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - OCFS2 file system; - Proc file system; - Pstore file system; - Diskquota system; - SMB network file system; - SquashFS file system; - UDF file system; - XFS file system; - Audit subsystem; - RAS (Reliability, Availability, Serviceability) subsystem; - Software nodes and device properties; - Memory Management; - KVM subsystem; - Memory management; - PPP protocol drivers and compressors; - Linux Security Modules (LSM) Framework; - Network traffic control; - Bluetooth subsystem; - MAC80211 subsystem; - Netfilter; - IP tunnels definitions; - Tracing infrastructure; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Control group (cgroup); - Kernel fork() syscall; - Kernel futex primitives; - Kernel kexec() syscall; - Kernel module support; - Scheduler infrastructure; - Cryptographic library; - KASAN memory debugging framework; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - CAIF protocol; - CAN network layer; - Ceph Core library; - Networking core; - Distributed Switch Architecture; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - Management Component Transport Protocol (MCTP); - Multipath TCP; - NCSI (Network Controller Sideband Interface) driver; - NFC subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - RF switch subsystem; - Rose network layer; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - Stream parser; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - X.25 network layer; - eXpress Data Path; - AppArmor security module; - Simplified Mandatory Access Control Kernel framework; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - AudioScience HPI driver; - Creative Sound Blaster X-Fi driver; - AMD SoC Alsa drivers; - SoC audio core drivers; - STI ASoC drivers; - USB sound devices; (CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116, CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545, CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865, CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715, CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221, CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719, CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863, CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006, CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562, CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748, CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103, CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256, CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161, CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274, CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031, CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141, CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220, CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228, CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270, CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286, CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293, CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303, CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318, CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367, CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391, CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425, CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446, CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454, CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467, CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480, CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494, CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540, CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565, CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585, CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594, CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629, CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701, CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726, CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763, CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015, CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046, CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089, CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242, CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281, CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357, CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420, CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439, CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484, CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860, CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883, CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899, CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912, CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920, CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941, CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956, CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974, CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002, CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015, CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037, CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053, CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072, CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088, CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137, CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189, CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206, CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219, CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231, CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238, CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259, CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274, CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319, CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914, CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920, CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926, CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011, CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088, CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128, CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294, CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306, CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379, CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032, CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102, CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153, CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221)
ubuntu.comJul 31, 2026extracted
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action. The five vulnerabilities are summarized below: CVE-2026-59309: A critical authentication bypass vulnerability in the VMware Directory Service. An unauthenticated attacker with network access to vCenter can exploit the flaw to bypass authentication and gain unauthorized access to the system. CVE-2026-59310: A critical directory traversal vulnerability in the vCenter Syslog server that allows an unauthenticated attacker with network access to execute arbitrary code. CVE-2026-47876: A critical out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a virtual machine using VMXNET3 can exploit the flaw to execute code on the ESX host, resulting in a virtual machine escape. Virtual machines using other virtual network adapters are not affected. CVE-2026-41703: An out-of-bounds read vulnerability in ESX, Workstation, and Fusion. An attacker with virtual machine deployment privileges could exploit it to disclose information or cause a denial-of-service condition in the host process. On Workstation and Fusion, the impact is limited to information disclosure. CVE-2026-41709: An insufficient logging vulnerability that allows a malicious ESX administrator to perform certain operations without them being logged. The three critical vulnerabilities are the two vCenter flaws, CVE-2026-59309 and CVE-2026-59310, which have CVSS scores of 9.8, and the VMXNET3 escape flaw, CVE-2026-47876, which is rated 9.3. The remaining issues are less severe, with CVE-2026-41703 rated as Important with a score of 7.6 on ESX. On Workstation and Fusion, its impact is limited to information disclosure, and it is rated Low with a score of 2.7. CVE-2026-41709 is also rated Low at 2.7. The vCenter vulnerabilities are fixed in versions 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, while the ESX flaws are addressed in ESXi 9.1.0.0200, ESXi 9.0.2.0100, and ESXi 8.0 Update 3k. VMware Workstation and Fusion users running version 25H2 must upgrade to 26H1 to address CVE-2026-41703. VMware Cloud Foundation 5.x and the affected telco products have separate patching instructions in Broadcom's advisory. There are no workarounds for the vulnerabilities, and Broadcom says switching virtual machines away from the VMXNET3 adapter is not advisable because other virtual network adapters have also contained security flaws and may reduce performance. Broadcom is treating these as emergency fixes, prompting admins to install them as soon as possible. "These issues qualify under ITIL methodologies as an emergency change, requiring prompt action from your organization," Broadcom warned in a supplemental FAQ. However, there may be some impact to services as they are being updated. Broadcom says patching vCenter temporarily interrupts access to the vSphere Client and other management interfaces, but running virtual machines and containers will continue operating. VMware ESX updates require a server to be restarted, so Broadcom recommends admins use vMotion to move virtual machines to other hosts while clusters are updated through a rolling reboot. Virtual machines that cannot be migrated must be powered down during the restart. Supported environments can also use ESX Live Patch to reduce disruption, although the vCenter updates are not eligible for Quick Patch. Broadcom also warns that there may be a compatibility issue when upgrading VMware Cloud Foundation with the new patches. "Yes. A "back in time" restriction occurs when a patch updates a product branch that carries a newer build number than the target of a planned upgrade," explains the FAQ. "The vSphere 8.0 and 9.0 updates in this advisory block upgrades to VMware Cloud Foundation 9.x, which report a "back in time" error." The company says upgrade compatibility will be restored in later releases. Broadcom says there is no indication that the vulnerabilities in this advisory are being exploited in the wild. However, VMware servers are commonly targeted in attacks because compromising VMware vCenter or ESXi servers can provide access to large portions of an organization's servers and the data stored on them. For quite some time, many ransomware gangs have been creating dedicated encryptors that specifically target VMware virtual machines, as they have become common in the enterprise. In December 2025, CISA also warned that Chinese threat actors were compromising VMware vSphere servers to deploy BrickStorm malware, create hidden rogue virtual machines, and steal cloned virtual machine snapshots for credential theft. CrowdStrike has also observed attackers using the ESXi shell to create unregistered "ghost" virtual machines that do not appear in the ESXi or vCenter web consoles, a persistence technique the company tracks as VirtualGHOST. While Broadcom has not observed exploitation of the newly patched vulnerabilities, administrators should apply the updates as soon as possible. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 30, 2026extracted
Loading 40 more…