vCenter Flaw Exploited Just Five Days After Disclosure
A critical directory-traversal flaw in VMware vCenter’s Syslog server, rated CVSS 9.8, was already being exploited within five days of Broadcom’s disclosure, with researchers tracing 361 victim IP addresses across 47 countries. The attacker deployed an open-source reverse shell tool to maintain access to compromised systems, and while Broadcom has released patches, defenders are warned that patching alone won’t remove intruders who got in before the fix was applied.
Hackers leverage new Microsoft SharePoint exploit in attacks
A proof-of-concept exploit for a critical SharePoint authentication bypass flaw was weaponized within a day of its publication, letting unauthenticated attackers impersonate site users or administrators to access files and modify data. The bug affects SharePoint Enterprise Server 2016 and SharePoint Server 2019, was patched back in July, and thousands of internet-exposed servers remain at risk if left unpatched.
153GB of stolen credentials surface after LiteLLM supply chain attack
A massive archive of stolen secrets tied to an earlier supply chain compromise of the LiteLLM AI proxy gateway has surfaced, exposing credentials linked to roughly 2,500 corporate domains including major cloud, tech, and industrial firms. The breach originated from a poisoned version of an open-source vulnerability scanner that gave attackers access to build pipelines, and researchers are urging affected organizations to rotate cloud keys and API tokens before the data circulates more widely.
AWS key exposed in JavaScript may have lit way to Beacon’s charity data
A CRM provider serving more than 1,500 UK charities has confirmed that its customer database, including attachment files, was copied and likely downloaded in readable form during a breach traced to an AWS access key exposed in public JavaScript build artifacts. The incident lasted under 90 minutes but has triggered a wave of disclosures from affected charities, including organizations in healthcare and victim support, along with scrutiny from UK regulators.
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
A new presidential memorandum establishes a federally supervised program allowing vetted US companies to conduct offensive and intelligence-gathering cyber operations against foreign transnational criminal organizations behind ransomware, phishing, and sextortion campaigns. Participating firms must pass rigorous vetting, post a bond of at least $1 million, and get written approval before acting, with operations barred from causing loss of life or rising to the level of an armed attack under international law.