Connect with us

Infosecurity

VMware vCenter Vulnerability Exploited Just Five Days After Patch Release

Published

on

vCenter flaw exploited

Critical vCenter Flaw Exploited Within Days of Disclosure

Attackers wasted no time. A critical VMware vCenter vulnerability was exploited just five days after Broadcom published its advisory. The campaign used an open-source reverse shell to keep access to compromised systems.

German digital forensics firm Quirso uncovered the activity during an incident response engagement. Its findings, released on August 10, point to a suspected advanced persistent threat (APT) actor. Quirso counted 361 victim IP addresses across 47 countries, though it cautioned that an IP address doesn’t always equal a single organization.

The vulnerability, tracked as CVE-2026-59310, is a critical directory traversal flaw in the vCenter Syslog server. It carries a CVSS score of 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code. That turns a service built to collect logs into a direct route into the operating system.

For more on VMware-related threats, see Play Ransomware Expands to Target VMware ESXi Environments.

Five Days From Advisory to Compromise

Broadcom released its advisory on July 29. At that point, it said it had not observed any exploitation. The advisory was revised on August 3 to include 8.0 U2f express patches.

Quirso’s team first noticed compromised systems contacting attacker infrastructure on August 3. The next day brought 151 more victim IPs. By August 5, roughly 95% of the total 361 had appeared. Germany, the United States, Turkey, Iran, and France accounted for 185 of them.

The correlation between disclosure and exploitation is striking. While the attacker may have had prior knowledge of the flaw, Quirso believes the advisory likely served as the campaign’s starting point.

Two Clocks to Manage

For persistence, the attackers deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing. Because it dials outward rather than accepting inbound connections, it can bypass controls designed to block unsolicited inbound access. Quirso stressed that its presence alone does not prove compromise.

Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo, said patching alone won’t resolve the incident. “There are therefore two clocks to manage,” he said. One for closing the vulnerability, and another for evicting anyone who entered before the patch was applied.

What to Check Right Now

  • Look for outbound SSH connections from vCenter servers to unknown IPs.
  • Review logs for unusual activity around August 3–5, 2026.
  • Check for the presence of reverse_ssh binaries or related processes.
  • Assume compromise if any indicators are found, and initiate incident response immediately.

Patch Availability and Workarounds

Broadcom has not published a workaround. Fixed vCenter releases are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the deployed branch. These address both critical flaws in the advisory: the exploited directory traversal and an authentication bypass in VMware Directory Service.

If you haven’t patched yet, do it now. The window between disclosure and exploitation is shrinking, and this campaign shows how quickly attackers move.

For more on securing your infrastructure, read about VMware vCenter vulnerability remediation steps and how to detect reverse shells in your environment.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

White House Opens Door for Private Firms to Join Offensive Cyber Strikes

Published

on

offensive cyber operations

A New Era for US Cyber Policy

The White House has quietly changed the rules of engagement in cyberspace. A new National Security Presidential Memorandum (NSPM), signed by President Donald Trump on August 12, now allows federal law enforcement to team up with private companies for offensive cyber strikes against foreign threat actors targeting the US.

This isn’t a small tweak. It’s a structural shift that brings Silicon Valley and other private firms directly into the business of hacking back — something the US government has long avoided.

The memorandum builds on an Executive Order from March that told agencies to take “rigorous actions” against cyber-enabled crime. Now, the private sector gets a formal seat at the table.

Why the Private Sector? The Rationale Behind the NSPM

The White House argues that American companies are the most innovative in the world, but their capabilities have been “historically underutilized” in the fight against cybercriminals. That’s a fair point. Many private firms already possess world-class threat intelligence and offensive capabilities — they just haven’t been allowed to use them against adversaries.

The numbers make the case compelling. American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. Nearly three-quarters of US adults (73%) have experienced some form of online scam or attack. The status quo isn’t working.

So the NSPM creates a framework where private companies can enter into agreements with other firms and government bodies — federal, state, and local — to gather threat intelligence and propose cyber operations designed to disrupt transnational crime groups.

How the Program Will Work

The Homeland Security Task Force’s National Coordination Center (NCC) will run the show. Two Executive Directors — one from the Department of Justice, one from the Department of Homeland Security — will oversee operations.

The memorandum promises “rigorous procedures” for reviewing and conducting “limited” cyber operations. These won’t be free-for-alls. All operations will be directed by the US government, and the program must comply with the Constitution, US laws, and international agreements.

Still, the language is deliberately broad. “Every available tool” should be deployed against transnational cyber threats, the White House insists.

Industry Reactions: Welcome, Caution, and Fear

The cybersecurity community is split. Some see this as a long-overdue evolution. Others see a recipe for disaster.

Chris Wysopal, co-founder of Veracode, called the policy a “big shift” on X. His take: “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”

That’s the optimistic read. The pessimistic one comes from people who’ve actually done this work.

The Attribution Problem

Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) and a former chief technical analyst at CISA, knows the terrain better than most. He ran the global cybercrime and ransomware intelligence team for almost four years.

His warning is blunt: attribution in criminal operations is extremely difficult. “Few organizations can repeatably do it right (including certain gov agencies),” he wrote on X. “People are regularly and willingly wrong on pretty important incidents.”

That’s a chilling thought when private firms are about to get a license to strike.

Escalation Risks

Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, raised another red flag. He warned that authorizing private firms to destroy cyber-controlled infrastructure could hit state-linked systems. That raises the risk of interstate escalation — a cyber skirmish turning into a diplomatic crisis or worse.

The line between criminal groups and state actors is blurry. Ransomware gangs often operate with tacit state approval. A private company aiming at a criminal server might accidentally take down something connected to a foreign government. Then what?

Global Context: The UK’s Playbook

The US isn’t alone in this direction. The UK created its National Cyber Force (NCF) in 2020, and in 2023 published principles on how it uses offensive capabilities. The UK’s stance: these tools are rarely deployed, and only when other responses aren’t better suited.

That’s a more cautious approach than what the NSPM describes. The American version leans harder into private sector involvement, which is a distinctly US twist on the model.

What This Means for Businesses and Individuals

For everyday Americans, the practical impact is unclear — for now. The program is still being set up. The NCC has to establish procedures, and companies need to opt in.

But the direction is unmistakable. The US government is signaling that cybercrime is a national security threat worthy of offensive action, and that private companies will be part of the solution.

If you’re a business owner, this could mean new opportunities to collaborate with federal agencies on threat intel. It could also mean new risks if your company gets drawn into operations with unclear legal boundaries.

For the broader cybersecurity landscape, this is a paradigm shift. The question isn’t whether private sector offensive action will happen — it’s whether the guardrails will hold.

Related: how to protect yourself from cybercrime and the latest ransomware trends.

Continue Reading

Infosecurity

Europe revives CSAM scanning law for big tech: what now?

Published

on

CSAM scanning law

A controversial rule is back

The European Parliament has voted to bring back a rule that lets big tech companies scan users’ private messages for child sexual abuse material (CSAM). The decision, made on July 10th, 2026, came just before summer recess and has reignited a fierce privacy debate.

Critics call the process “Chat Control.” Supporters say it’s a necessary tool to protect children. The law, which first took effect in 2021, expired in April after Parliament failed to agree on a path forward amid widespread privacy concerns.

Now, with Thursday’s vote, companies like Google, Microsoft, and Meta have legal cover to continue scanning until 2028. But the way the vote happened has many people worried.

How did the vote pass?

The vote used an unusual legislative procedure. It required an absolute majority to kill the provision. That means all lawmakers who weren’t present in the chamber were counted as “yes” votes. So even though more present members opposed the measure than supported it, the rule passed.

Parliament President Roberta Metsola had pushed hard for renewing the rule. She and other officials argued it was urgent. The rule doesn’t allow scanning on encrypted platforms like Signal, but critics say the broader implications are still troubling.

This isn’t the first time Parliament considered the measure. Three months ago, under normal voting conditions, lawmakers rejected it. The procedural maneuver this time felt like an end-run around that decision.

What critics are saying

Privacy advocates are furious. Rand Hammoud of Europe’s Center for Democracy and Technology called the tactics “highly politicised procedural efforts” in a blog post. He accused lawmakers of “overstepping Parliament’s own mandate and previous vote.”

Simeon de Brouwer, a policy adviser at European Digital Rights, put it more bluntly. He said Chat Control allows tech companies to “snoop without a warrant, with little to no oversight, and with no legal basis, on millions of conversations.”

That’s a strong claim. But it reflects the deep unease many feel about giving corporations the power to inspect private messages.

The bigger battle: Chat Control 2.0

Thursday’s vote is just the opening skirmish. A much larger fight is brewing over what insiders call Chat Control 2.0.

In its most extreme form, 2.0 could force service providers to scan conversations and hosted content, including end-to-end encrypted communications. That would be a massive shift from the voluntary, limited scanning allowed under the current rule.

Lawmakers have been negotiating a permanent framework since November 2023. Progress has been slow. Law enforcement agencies, however, are pushing hard for a permanent solution.

Europol’s position

When the law lapsed in April, Catherine De Bolle, the executive director of Europol, issued a statement. She said that “enabling online service providers to continue detecting and reporting suspected CSAM to the competent authorities is vital for the protection of children.”

That’s a powerful argument. No one wants to make it easier for predators to operate. But de Brouwer and others say the tradeoffs are too high.

What happens next?

The renewed rule gives big tech legal protection to continue scans until 2028. But the debate over Chat Control 2.0 is far from over.

If you care about digital privacy rights, this is a story to watch. The outcome could reshape how European governments balance child protection against surveillance concerns.

For now, the scans continue. The legal cover is in place. And the critics are watching closely.

Continue Reading

Infosecurity

Google Cloud Sets 2027 Deadline for First Post-Quantum Security Milestone

Published

on

post-quantum security roadmap

Google Cloud’s Three-Stage Quantum Migration Plan

Google Cloud has broken its post-quantum security roadmap into three distinct risk domains, each with its own deadline. The first major milestone—mitigating store-now-decrypt-later (SNDL) risk—is set for the end of 2027.

The roadmap, published on August 12, draws directly from Google’s internal quantum threat model. It’s a pragmatic approach that acknowledges the uneven pace of quantum readiness across different parts of the cloud stack.

What’s Already Shipped

Some pieces are already live. Google Cloud API endpoints, including google.com and *.googleapis.com, now support quantum-safe key exchange using the NIST-standardized ML-KEM in hybrid mode.

Application and proxy load balancers offer hybrid key exchange for TLS 1.3, initially opt-in so customers can validate the change without breaking existing applications. Cloud KMS has reached general availability for ML-KEM, ML-DSA, and SLH-DSA, and quantum-confidential ALTS—Google’s internal traffic protocol—completed in 2025.

Still on the horizon: Cloud VPN and Interconnect in 2026 and 2027, Private CA in 2027, and quantum-safe Cloud IAM and Cloud HSM in 2028.

The Certificate Problem

Certificates present a unique constraint. Post-quantum signatures are large enough to slow down certificate chain validation. Google’s answer is Merkle Tree Certificates.

Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo, explains the approach replaces multiple large signatures with one compact inclusion proof, keeping overhead near current levels.

It also folds transparency logging into issuance itself. As Soroko puts it: “If a certificate is not in the tree, it simply does not exist.”

Customers Carry Part of the Load

Google is explicit that this isn’t a purely server-side fix. Customers must update client-side software to negotiate post-quantum handshakes and manage their own asymmetric key lifecycles.

Hardware is another variable. The company says some physical components may not be fully transitioned until after 2029, since the shift depends partly on natural equipment replacement cycles.

That timeline matters. In March, Google warned that a cryptographically relevant quantum computer could arrive as early as 2029.

What This Means for Your Organization

If you’re running workloads on Google Cloud, the practical takeaway is to start inventorying your cryptographic assets now. The SNDL risk is the most urgent—data encrypted today could be decrypted by a future quantum machine.

For a deeper look at how the broader industry is preparing, check out our analysis of how cybersecurity vendors are preparing for the post-quantum era. You might also want to review lessons from Singapore’s quantum future planning for a government perspective.

The key question isn’t whether quantum computers will arrive. It’s whether your data will still be safe when they do. Google’s roadmap gives you a clear window to act—2027 for SNDL, 2028 for signatures and key management.

Use that time wisely. The clock is already ticking.

Continue Reading

Trending