Generated · Archived snapshot 14 findings · 4 CVEs
On this page

Exploitation Report

Executive Summary

A global exploitation campaign targeting CVE-2026-59310 in VMware vCenter Server has emerged as the most critical active threat, with multiple threat intelligence sources confirming widespread exploitation for reverse SSH persistence and remote code execution since early August. The vulnerability carries a CVSS 9.8 rating and affects the vCenter Syslog Server component, with evidence indicating that patching alone may not fully mitigate risk due to potential pre-compromise persistence. Simultaneously, North Korean state-sponsored actor Lazarus Group is actively exploiting an unpatched Windows zero-day vulnerability to deploy a novel backdoor across defense and aerospace targets in France, Germany, Brazil, and India as part of the long-running Operation Dream Job campaign.

Microsoft's July 2026 Patch Tuesday addressed several actively exploited flaws, including the LegacyHive Windows zero-day and CVE-2026-55040 (CVSS 9.1), a SharePoint authentication bypass now under active exploitation following public proof-of-concept release. Adobe Commerce platforms face exploitation attempts against CVE-2026-71362 for customer account hijacking, while a long-running "City-Forum" data theft campaign continues harvesting exposed data from Salesforce Experience Cloud and ServiceNow portals using custom tooling. The threat landscape also shows increasing abuse of legitimate system features—including Windows Safe Mode for EDR evasion by Akira ransomware affiliates, Plug and Play for SYSTEM privilege escalation, and malicious Chrome extensions at massive scale (737 identified)—alongside supply chain compromises affecting Trezor customers via ShipMonk and over 2,100 organizations through trojanized LiteLLM packages on PyPI.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-59310#

  • Description: A critical directory-traversal vulnerability in VMware vCenter Server's Syslog Server component that allows unauthenticated attackers with network access to execute arbitrary code. Multiple independent sources confirm active exploitation campaigns deploying reverse SSH tunnels for persistent remote access.
  • Impact: Full remote code execution on vCenter Server, enabling persistent administrative access, lateral movement across virtualized infrastructure, and potential compromise of all managed ESXi hosts and virtual machines.
  • Status: Actively exploited in the wild since early August 2026. Patches are available from Broadcom/VMware, but security researchers warn patching may not remove established persistence mechanisms such as reverse SSH tunnels.

CriticalActive exploitationPatchCVE-2026-55040#

  • Description: A critical security feature bypass vulnerability stemming from weak authentication in Microsoft SharePoint. The flaw allows attackers to bypass authentication controls entirely. A public proof-of-concept exploit was released following the July 2026 Patch Tuesday, triggering immediate active exploitation.
  • Impact: Unauthenticated attackers can bypass SharePoint authentication, potentially accessing sensitive documents, escalating privileges, and moving laterally within Microsoft 365 and on-premises SharePoint environments.
  • Status: Patched in July 2026 Patch Tuesday. Active exploitation confirmed following public PoC release.

CriticalActive exploitationPatchCVE-2026-71362#

  • Description: A critical vulnerability in Adobe Commerce and Magento e-commerce platforms that enables attackers to hijack customer accounts. Exploitation attempts have been detected in the wild.
  • Impact: Attackers can take over customer accounts on affected e-commerce sites, accessing personal data, order history, payment information, and potentially making fraudulent purchases.
  • Status: Exploitation attempts actively detected. Adobe has released patches for affected versions.

CriticalActive exploitationPatch#

  • Description: A Windows zero-day vulnerability codenamed "LegacyHive" that was disclosed and patched during the July 2026 Patch Tuesday. The vulnerability was actively exploited prior to patch release.
  • Impact: Specific technical details were not disclosed in the source article, but as a patched zero-day, it enabled privilege escalation or remote code execution on affected Windows versions.
  • Status: Patched in July 2026 Patch Tuesday. Was actively exploited as a zero-day prior to patch availability.

CriticalActive exploitationPatch#

  • Description: The North Korean Lazarus Group is exploiting a newly patched Windows zero-day vulnerability to gain SYSTEM-level access and deploy a previously unseen backdoor. This activity is part of Operation Dream Job, a long-running cyber espionage campaign targeting defense and aerospace sectors.
  • Impact: SYSTEM-level compromise of target systems, deployment of custom backdoor for persistent espionage access, targeting defense and aerospace companies in France, Germany, Brazil, and India.
  • Status: Active exploitation by a sophisticated nation-state actor. Microsoft has released a patch for the underlying vulnerability.

CriticalStatus unknownPatchCVE-2026-48362#

  • Description: An operating system command injection vulnerability in Adobe ColdFusion rated CVSS 10.0, the maximum severity score. This was among three critical flaws patched by Adobe across ColdFusion, Commerce, and Campaign Classic.
  • Impact: Unauthenticated remote code execution with the privileges of the ColdFusion service, potentially leading to full server compromise.
  • Status: Patched by Adobe in August 2026 updates. Exploitation status in the wild not explicitly confirmed in source articles.

CriticalStatus unknownInvestigate#

  • Description: Severe vulnerabilities in a key browser extension used for Belgium's electronic ID (eID) authentication system, fully compromising the trust framework underlying citizen authentication. The flaws enable remote code execution.
  • Impact: Complete compromise of citizen authentication for Belgian eID system, enabling identity theft, unauthorized access to government services, and potential RCE on user systems.
  • Status: Vulnerabilities disclosed. Remediation status of the browser extension not specified in source.

HighActive exploitationMitigate#

  • Description: Akira ransomware affiliates are disabling Endpoint Detection and Response (EDR) solutions by restarting compromised systems into Safe Mode with Networking, where EDR drivers and services typically do not load.
  • Impact: Bypass of advanced endpoint protection, enabling unimpeded ransomware execution, data theft, and encryption attempts. In the observed case, data was stolen but encryption failed.
  • Status: Active technique in use by Akira affiliates. No patch available—this is a defense evasion technique abusing a legitimate Windows feature.

HighPotentialMonitor#

  • Description: A novel attack technique abusing the Windows Plug and Play feature to trigger automatic installation of vulnerable or insecure vendor-signed drivers/software, resulting in SYSTEM-level privilege escalation.
  • Impact: Local privilege escalation to SYSTEM without exploiting a traditional vulnerability, leveraging legitimate Windows driver installation mechanisms and vulnerable vendor software.
  • Status: Proof-of-concept/research disclosure. Active exploitation in the wild not explicitly confirmed.

HighActive exploitationInvestigate#

  • Description: A combination of WindRelay NFC relay malware and SpyNote remote administration tool (RAT) that steals live credit card data via NFC relay and exfiltrates it in real time, while also enabling full device control.
  • Impact: Real-time theft of physical credit card data via NFC relay attacks, full device compromise via RAT capabilities, fraudulent loan applications initiated on victim devices.
  • Status: Active malware campaign observed in the wild.

HighActive exploitationInvestigate#

  • Description: A long-running campaign active since at least March 2025 using custom tooling to enumerate and extract data exposed to anonymous users through Salesforce Experience Cloud sites and ServiceNow customer portals.
  • Impact: Large-scale data theft from misconfigured cloud portals, potentially exposing customer PII, support tickets, internal documents, and business data across multiple sectors.
  • Status: Active ongoing campaign with custom tooling. Not a vulnerability in the platforms themselves but exploitation of misconfigurations.

HighActive exploitationInvestigate#

  • Description: Over 737 malicious Chrome Web Store extensions impersonating legitimate VPN and proxy services, routing user traffic through attacker-controlled SOCKS5 proxy infrastructure. Published across 40+ developer accounts with 75,000+ combined installs, primarily targeting Russian-speaking users.
  • Impact: Full interception of browser traffic, credential harvesting, session hijacking, and potential injection of malicious content. 274 extensions impersonated 66 legitimate VPN brands.
  • Status: Active on Chrome Web Store until discovery. Google has been notified; removal status ongoing.

CriticalObservedInvestigate#

  • Description: Two malicious LiteLLM releases published on PyPI for approximately 40 minutes in March 2026, containing credential-stealing code that harvested cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets. Linked to a compromise of the Trivy security scanner project.
  • Impact: Potential exposure of 2,100+ organizations that may have installed the malicious packages. Attackers captured approximately 434,000 files containing secrets and credentials.
  • Status: Packages removed from PyPI. Incident response ongoing for potentially affected organizations.

MediumObservedMonitor#

  • Description: Hardware wallet manufacturer Trezor disclosed a breach affecting nearly 14,000 customers after its shipping and logistics provider ShipMonk was compromised.
  • Impact: Exposure of customer shipping information (names, addresses, emails, phone numbers) for cryptocurrency hardware wallet users, enabling targeted physical and phishing attacks.
  • Status: Breach disclosed. ShipMonk compromise confirmed.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities