Show notes
This briefing examines a critical exploitation campaign targeting VMware vCenter via CVE-2026–59310, a directory traversal flaw with a CVSS score of 9.8. Just days after its July 29 disclosure, a single threat actor began targeting instances across 47 countries, establishing persistence through reverse_ssh that survives patching. We also detail Shell's investigation into a potential security incident following claims by the Clop ransomware group. This incident appears linked to a broader campaign exploiting a vulnerability in PTC Windchill and FlexPLM platforms, which has also reportedly impacted GE and Philips. Finally, we cover Apple's latest batch of high-confidence threat notifications regarding mercenary spyware attacks targeting specific users globally. Our analysis focuses on the rapid turnaround from disclosure to exploitation and why traditional patching must be supplemented by forensic auditing and strict network micro-segmentation in modern virtualized environments.



