CVE Tools

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The Hacker NewsBy The Hacker News

Reported exploitedLazarus Group

Our summary

This week's security landscape was dominated by active exploitation of critical vulnerabilities, including a severe directory traversal flaw in VMware vCenter identified as CVE-2026-59310. A suspected China-linked APT group leveraged this bug to deploy backdoors and Babuk-derived ransomware, which researchers assess served primarily as a distraction for forensic evasion rather than the final objective.

Concurrently, North Korea’s Lazarus Group targeted defense and aerospace sectors across Europe, South America, and Asia using a zero-day privilege escalation vulnerability in Microsoft Windows, tracked as CVE-2026-68820. The actor delivered new malware strains, ForestTiger and Troy, under the guise of their long-running “Dream Job” social engineering campaign. Additional notable developments include the release of patches for a critical SQL injection issue in GeoServer (fixed in versions 3.0.1, 2.28.5, and 2.27.6), the discovery of GhostSplice, an attack technique that fragments malicious prompts to evade AI coding assistant guardrails, and the emergence of Amnesia Stealer, a macOS tool capable of live-controlling victim browsers via the Chrome DevTools Protocol.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store