This week has seen a range of cybersecurity incidents, highlighting vulnerabilities across various platforms and the exploitation of existing flaws. Notably, these incidents underscore the importance of timely patching and awareness of emerging threats.
VMware Vulnerability Exploited
A new security flaw in VMware vCenter has been actively exploited, linked to a suspected advanced persistent threat (APT) group from China. The vulnerability, identified as CVE-2026-59310 with a CVSS score of 9.8, is a severe directory-traversal issue that could allow attackers to execute arbitrary code. In one instance, the exploitation led to the deployment of a backdoor and a reverse SSH binary, culminating in the use of Babuk-derived ransomware. However, experts suggest that the ransomware may have been a distraction from the primary intrusion, aimed at complicating forensic investigations.
Exploitation of macOS Flaw
Another critical incident involves a recently patched flaw in Apple macOS, designated as CVE-2026-65400 (CVSS score: 9.8). This authentication vulnerability affects the Screen Sharing component, enabling attackers on the same network to authenticate without valid credentials. Reports indicate active exploitation of this flaw, particularly on systems where port 5900 is exposed to the internet, resulting in the installation of a Monero cryptocurrency miner.
Windows Zero-Day Targeted by Lazarus Group
The North Korean threat actor known as the Lazarus Group has been linked to the exploitation of a zero-day vulnerability in Microsoft Windows, specifically CVE-2026-68820 (CVSS score: 7.0). This privilege escalation flaw affects the Windows Ancillary Function Driver for WinSock and was patched in Microsoft’s August 2026 updates. The attacks are part of a broader espionage campaign targeting defense and aerospace sectors across multiple countries, utilizing social engineering tactics to deliver malware.
GeoServer Vulnerability Under Active Exploitation
Additionally, GeoServer has addressed a critical SQL injection vulnerability that can lead to remote code execution. While this flaw has not yet been assigned a CVE identifier, it has been reported to have been actively exploited shortly after its disclosure. Patches have been released for versions 3.0.1, 2.28.5, and 2.27.6.
These incidents highlight the ongoing challenges in cybersecurity, where vulnerabilities can be exploited rapidly, underscoring the need for organizations to maintain vigilance and apply patches promptly.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








