CISA Warns Ransomware Gangs Exploiting Critical VMware vCenter Vulnerability

Original image source: bleepstatic.com The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that ransomware gangs are now actively exploiting a critical VMware vCenter vulnerability, identified as CVE-2026-59310, which was patched in July. This development comes after an initial wave of attacks suspected to be from advanced persistent threat (APT) actors. Detalles de la Vulnerabilidad y su Explotación Broadcom, the company behind VMware, addressed CVE-2026-59310 on July 29, classifying it as a critical directory traversal flaw within the vCenter Syslog server. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems. At the time of the patch release, Broadcom urged customers to prioritize its remediation, emphasizing the urgency of applying updates. ...

September 15, 2026 · Comfidentia

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Chaotic Eclipse Unveils FalconFlank Zero-Day for Crowdstrike Falcon Security researcher Chaotic Eclipse, also known by aliases like INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, has publicly released “FalconFlank,” a proof-of-concept (PoC) exploit for a zero-day privilege escalation vulnerability affecting the Crowdstrike Falcon cybersecurity platform. Details of FalconFlank Exploit FalconFlank exploits Falcon’s “Microsoft Office file malicious macro removal” feature. This remediation function, which operates with high privileges, can be abused to escalate privileges from a low-privileged local user to a more powerful system context. ...

September 3, 2026 · Comfidentia
Español English