VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update

A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a critical path traversal bug in the Syslog Server, to run commands as root without a normal login. The activity moved from disclosure to widespread exploitation in days. QUIRSO mapped 361 affected IP […]

This article has been indexed from Cyber Security News

Read the original article: