VYPR
advisoryPublished Aug 17, 2026· 2 sources

VMware vCenter, Windows 0-Day, and macOS Flaws Among This Week's Top Cyber Threats

This week's security landscape was dominated by active exploitation of critical vulnerabilities in VMware vCenter, a Windows 0-day used by Lazarus Group, and a macOS flaw enabling cryptomining.

This week's cybersecurity recap highlights a series of significant threats, underscoring that sophisticated attacks are not always the most damaging. Exposed services, the reuse of older vulnerabilities, and compromised browser sessions were common attack vectors, alongside persistent supply-chain issues. Many incidents exploited existing access and overlooked defenses, suggesting a reliance on basic security oversights rather than advanced techniques.

A suspected China-nexus Advanced Persistent Threat (APT) group has been linked to the exploitation of a newly patched security flaw in VMware vCenter Server. The attacks leverage CVE-2026-59310, a severe directory-traversal vulnerability with a CVSS score of 9.8. This flaw allows malicious actors to execute arbitrary code, and in at least one observed case, led to the deployment of a backdoor and a reverse SSH binary. The ultimate goal appeared to be the deployment of Babuk-derived ransomware, though researchers suggest this may have served as a "smoke screen" to hinder forensic analysis by encrypting evidence, rather than being the primary objective.

In parallel, a critical authentication flaw in Apple's macOS Screen Sharing component, CVE-2026-65400 (CVSS 9.8), has been actively exploited in the wild. Threat actors are using this vulnerability to gain root access and deploy Monero cryptocurrency miners on affected systems. The issue, patched in an emergency update for macOS Tahoe, Sequoia, and Sonoma, allowed attackers on the network to authenticate to the remote desktop feature without valid credentials, particularly impacting systems with port 5900 accessible from the internet.

The notorious North Korean threat actor Lazarus Group has been attributed to the zero-day exploitation of a new Microsoft Windows vulnerability as part of its long-running 'Operation Dream Job' campaign. The attackers are targeting professionals in the defense and aerospace sectors with sophisticated social engineering tactics, using fake job offers to deliver malware. The exploited flaw, CVE-2026-68820 (CVSS 7.0), is a privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), which was patched in Microsoft's August 2026 Patch Tuesday updates. This campaign aims to steal sensitive data and install new backdoors, including one named Troy.

GeoServer, a popular open-source software for publishing geospatial data, has also released patches for a critical SQL injection vulnerability that enables remote code execution (RCE). Although not yet assigned a CVE identifier, the flaw saw active exploitation within hours of its public disclosure, with hundreds of attempts originating from a small pool of IP addresses. The vulnerability was patched in versions 3.0.1, 2.28.5, and 2.27.6.

Adding to the macOS threat landscape, a new information-stealer family named Amnesia Stealer has emerged, targeting macOS users through deceptive tactics like fake GitHub download pages. Beyond stealing data from numerous Chromium-based browsers and other sensitive information like cryptocurrency wallets and iCloud Keychain data, Amnesia Stealer features a unique streaming module. This module allows attackers to interactively control the victim's web browser by cloning their Chromium profile, including authentication states, and using the Chrome DevTools Protocol (CDP) to establish a real-time remote control channel.

These incidents collectively highlight a diverse range of threats, from nation-state sponsored espionage and ransomware deployment to opportunistic cryptomining and sophisticated data theft. The reliance on exploiting unpatched or misconfigured systems, coupled with novel attack vectors like browser session hijacking and interactive remote control, underscores the persistent need for robust security practices and rapid patching.

The SANS Internet Storm Center article provides further technical detail on the macOS Screen Sharing vulnerabilities, explaining how Apple's modifications to the VNC protocol, particularly concerning authentication and privilege escalation, have created exploitable weaknesses. It also offers specific command-line instructions for hardening macOS systems against these threats, complementing the existing report's focus on active exploitation.

Synthesized by Vypr AI