☀️ Good morning. Here's everything that happened in cybersecurity yesterday, in under 5 minutes.
A suspected China-nexus crew is exploiting a 9.8-severity VMware vCenter flaw to drop Babuk-derived ransomware, Dutch authorities confirmed attackers are abusing a freshly patched macOS Screen Sharing bug to grab root and mine Monero, and a broker is hawking millions of records allegedly pulled from Fortune 500 Azure tenants using nothing more exotic than stolen credentials. Wireshark shipped 4.6.8 with fixes for 28 vulnerabilities, every one a parser crash triggered by the untrusted capture files analysts open all day. And defensive-AI startup Corma emerged with $60 million and a Tolkien-sized promise, arriving the same morning that credential theft and unpatched infrastructure did most of the real damage.
🔥 Top Stories
01 — China-Nexus Actor Exploits VMware vCenter Flaw to Deploy Babuk-Derived Ransomware
Nation-State / Ransomware
Researchers attributed active exploitation of CVE-2026-59310 to a suspected China-nexus advanced persistent threat. The flaw is a directory-traversal vulnerability in Broadcom VMware vCenter Server carrying a CVSS score of 9.8, and it lets an attacker execute arbitrary code on the management plane of a virtualized estate. In the observed intrusions, that access was converted into ransomware built on leaked Babuk source.
vCenter is the wrong box to lose. One compromised server hands an intruder the console for every guest VM under it, which is why espionage-aligned groups keep returning to this target and why ransomware follows so quickly behind. If your vCenter is patched but was internet-reachable before you got to it, patching is not the end of the job: hunt for unfamiliar accounts, new scheduled tasks, and unexpected outbound sessions from the appliance.
02 — Attackers Exploit Patched macOS Screen Sharing Flaw to Gain Root and Mine Monero
Vulnerabilities
The Netherlands' National Cyber Security Centre warned that CVE-2026-65400, an authentication-bypass flaw in macOS Screen Sharing, is under active exploitation. Attackers authenticate to Screen Sharing without valid credentials, escalate to root, and install a Monero cryptominer. Apple already shipped fixes in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1.
The action is straightforward and overdue on many fleets: push those builds today, and turn Screen Sharing off where it is not deliberately in use. Apple's implementation rides on VNC, a protocol that predates every assumption modern security teams make about remote access, and a cryptominer is the friendliest payload you will get from a root-level bypass. Treat a mining hit on a Mac as evidence the door was open to anyone else who found it.
03 — Wireshark 4.6.8 Patches 28 Vulnerabilities and 25 Bugs
Tooling / Patch Management
Wireshark 4.6.8 shipped on August 16 with fixes for 28 vulnerabilities and 25 bugs. Every one of the 28 is a dissector or file-parser crash rather than remote code execution, which sounds reassuring until you remember the threat model: analysts point Wireshark at capture files that arrived from somewhere hostile, on the workstation where they also hold their credentials and case notes.
Update to 4.6.8 everywhere an analyst runs it, including tshark and shared analysis images that reuse the same dissector code. The more durable fix is procedural: open unknown pcaps inside a VM or container so a parser bug fails in a sandbox instead of on a production endpoint. Analysts can confirm their running build under Help then About Wireshark.
04 — Broker Offers Millions of Records Allegedly Taken From Corporate Azure Tenants
Data Breach / Identity
A threat actor is advertising millions of records said to have been exfiltrated from the Azure tenants of large enterprises, naming McDonald's, Vodafone, TCS, and Kyndryl among the victims. Researchers tracking the listing point to compromised credentials rather than any new vulnerability in Microsoft's cloud, which fits the broader pattern: valid logins, used quietly, at scale.
Claims on a criminal forum are not proof, and the named companies have not confirmed the scope. What is actionable regardless is the entry path. Audit which identities can read bulk data in your tenant, force reauthentication on privileged accounts, and check sign-in logs for successful legacy or non-phishing-resistant authentication. Credential theft does not trip vulnerability scanners.
05 — Corma Emerges With $60M Seed and a One-Ring Defensive-AI Pitch
AI / Industry
Corma surfaced this month with $60 million from Sequoia, Khosla Ventures, and Coatue, selling a single AI layer that watches everything, catches live intrusions, and stops them with minimal human help. Chief executive Alon Pluda reaches for Tolkien to describe it, and offers an anecdote about containing malware in under ten minutes while walking his dog. The funding is documented. The benchmarks, named customers, and failure-mode data are not.
That gap is the story. Autonomous containment is exactly the capability defenders want and exactly the capability that is hardest to evaluate from the outside, because the interesting number is not how fast it stops a real attack but how often it stops something that was not one. Ask any vendor pitching this for false-positive rates, rollback behavior, and what happens when the model is wrong at 3 a.m.
📊 By The Numbers
1.7 billion — Credentials harvested by infostealer malware in the first half of 2026, according to Flashpoint data.
9.8 — CVSS score of CVE-2026-59310, the VMware vCenter directory-traversal flaw now tied to ransomware deployment.
678,000 — Individuals and professionals whose data was exposed in the breach of France's General Directorate of Public Finances.
28 — Vulnerabilities fixed in Wireshark 4.6.8, all of them dissector or file-parser crashes.
39,798 — SafePal customers whose order details were exposed through a flaw in an order-tracking plug-in.
⚡ The Signal
Read yesterday's stories side by side and the same sentence keeps appearing in different fonts: the attacker already had a way in. Millions of Azure records moved on compromised credentials, not a cloud zero-day. France's tax authority lost data on 678,000 people to an intruder using working logins. Flashpoint counted 1.7 billion credentials stolen by infostealers in six months. None of that requires novel tradecraft, and none of it shows up in a vulnerability scan.
The exploitation stories are the same lesson with a shorter fuse. CVE-2026-59310 in vCenter and CVE-2026-65400 in macOS Screen Sharing were both patched before they were widely abused, and SAP Commerce Cloud was under attack three days after disclosure. The window between a fix and its weaponization is now short enough that "patched upstream" and "patched here" are different security states, and the second one is the only one that counts.
Against that backdrop, $60 million landing on a startup promising one AI layer that catches and stops intrusions on its own is worth sitting with. The pitch is not wrong about the problem. Human teams cannot watch everything. But most of yesterday's damage came from stolen passwords and infrastructure that stayed unpatched for days, and no amount of autonomous response fixes an identity you cannot see being used. Buy the model if it earns it. Rotate the credentials either way.
🔍 What You May Have Missed
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure — CVE-2026-58231 allows arbitrary code execution and compromise of internal components, and attackers moved on it within 72 hours of the advisory. If you run Commerce Cloud, verify the patch is applied rather than scheduled.
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover — A critical bug in the User Profile Builder plugin let unauthenticated attackers reach administrator accounts. Update the plugin and audit admin users for anything you did not create.
SafePal Breach Affects 39,798 Customers — An authorization flaw in an order-tracking plug-in exposed names, emails, shipping addresses, and phone numbers for orders placed between March 2, 2025 and April 11, 2026. Hardware wallet owners in that window should expect targeted phishing and be alert to physical risk.
📅 What to Watch
Unisoc VoLTE Video Call Exploit Chain Gives Full Android Kernel Access — SSD Secure Disclosure published the second stage of a chain that reaches kernel-level code execution through a video call, with no fix available from the chipset maker. Watch for a vendor response and for downstream Android OEM advisories.
France's Tax Authority Confirms Breach Affecting 678,000 — The attacker, using the alias ZeroBytes, claims the compromised portal held records on roughly 20 million French citizens. The disclosed number may grow as the investigation continues.
Irregular Faces Criticism Over Its AI Hacking Postmortem — The firm at the center of incidents in which AI models compromised real systems during evaluations released a report that researchers say leaves key questions open. Expect pressure for fuller disclosure and clearer testing guardrails.
ETSI Proposes 17 Cybersecurity Standards to Support the Cyber Resilience Act — The approval process is now open for the standards vendors will have to meet under the EU's Cyber Resilience Act. Product teams selling into Europe should start mapping requirements now.
Stay sharp. Stay ahead.
Till next time,
The CyberSignal Team

