VMware vCenter Is Being Exploited Right Now, Colombia's Justice Ministry Just Got Ransomed, and Defenses Quietly Had Their Best Year Yet
A look at the last 24 hours in cybersecurity: an actively exploited vCenter RCE, a ransomware hit on Colombia's Justice Ministry days before a presidential transition, Scattered Spider members plead guilty, Intel discloses a fresh batch of high-severity flaws, and a 338-million-simulation study says defenders are finally winning quietly instead of loudly.
Patch your vCenter. Right now, not after lunch. German incident responders at QUIRSO confirmed active exploitation of CVE-2026-59310, a directory-traversal flaw in VMware vCenter Server carrying a 9.8 CVSS score. Broadcom shipped the fix late last month. Attackers didn't wait long to catch up: QUIRSO traced compromised systems calling home to attacker infrastructure starting August 3, five days after the patch dropped. The playbook is straightforward and ugly — path traversal to get a foothold, then a malicious cron job using reverse_ssh, an open-source tool, to keep a persistent tunnel back to the attacker. A malicious actor with network access to vCenter and no authentication gets arbitrary code execution. If vCenter sits anywhere near your management network, this is a today problem, not a this-sprint problem.
Colombia's Ministry of Justice got hit with ransomware days before a presidential transition — the kind of timing that isn't coincidence so much as it's the point. Government transitions are attractive windows: institutional attention is split, incident response chains of command are in flux, and public messaging discipline is harder to hold. Expect more of this pattern globally as 2026 election and transition calendars fill up. If your organization touches government infrastructure or works adjacent to a political transition, tighten change-control and elevate monitoring around the transition date itself, not just around the technical footprint.
Angola's Unitel, the country's dominant mobile carrier with north of 21 million subscribers, is still climbing out of the cyberattack that knocked out voice, data, and internet access nationwide on July 28 — the same day the company priced Angola's largest-ever IPO. Core voice and messaging came back within days; 4G, 5G, and a handful of digital services were still limping as of this week. Unitel has called it a "deliberate and malicious cyberattack" and has not published a technical breakdown of how it happened. The IPO proceeded anyway and the stock popped on debut, which tells you something about how disconnected market enthusiasm and operational reality can get in the middle of a live incident. The bigger lesson for critical infrastructure operators: your breach doesn't pause for your calendar, and neither should your response plan be built around the assumption that it will.
Accountability caught up with two members of Scattered Spider this week. Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in a UK court to charges tied to the August 2024 attack that crippled Transport for London's systems — a case that was set to go to a six-week trial before both entered pleas on day one. Scattered Spider has spent the past two years running social-engineering-led intrusions against major enterprises with a level of operational fluency that outpaced a lot of the defenses built to stop them. Guilty pleas from core members are a real dent, not just a headline. Attribution and prosecution take years; when they land, they're worth noting, because they're one of the few costs these groups actually pay.
On the vulnerability side, Intel disclosed a fresh batch of high-severity flaws this week spanning privilege escalation and code execution. Nothing here is exotic — it's the routine grind of firmware and driver-level bugs that quietly widen an attacker's blast radius once they've got a foothold, which is exactly why they don't get the attention CVEs with catchy names do. Get these into your normal patch cadence and move on; they're not a headline vulnerability, they're a hygiene one, and hygiene vulnerabilities are the ones that turn a contained incident into a bad week.
The AI angle this week runs through the software supply chain instead of an agent going rogue. LiteLLM, a widely used open-source gateway for routing calls across different AI model providers, got compromised through a separate breach of Trivy, the open-source vulnerability scanner, and was used to distribute infostealer malware to LiteLLM's own users. If your AI infrastructure pulls in LiteLLM or Trivy anywhere in the chain, treat this like any other supply-chain compromise: audit what versions you're actually running, rotate anything those tools had access to, and don't assume "it's just a scanner" or "it's just a routing layer" means it wasn't a real foothold. The tools defenders use to secure their pipeline are themselves part of the attack surface now, and expect this pattern to keep repeating as AI tooling gets bolted onto more of the software supply chain without the same scrutiny applied to the rest of it.
Separately, OpenAI put out a warning that autonomous AI-driven hacking represents what it called a watershed moment for computer security — language strong enough that it's worth reading as a genuine signal rather than marketing copy, especially coming from a company with a direct commercial interest in agentic AI adoption.
And here's the one number from this week actually worth sitting with: Picus Labs' Blue Report 2026, built on more than 338 million real attack simulations run against actual production environments in the first half of the year, found average prevention effectiveness climbed from 62% to 69%, tying its 2024 peak, with logging hitting a four-year high. Defenses are quietly having one of their best years. The catch, and it's a real one: enterprise detection is tuned to catch attacks that make noise, and this year's attackers are increasingly winning by making none. Prevention numbers going up doesn't mean the fight is easier — it means the attackers who are still getting through are the ones who've learned exactly what your tooling is listening for, and are staying under it. Tune your detections for the quiet stuff. That's where 2026's damage is actually landing.
- The Hacker News — VMware vCenter Flaw CVE-2026-59310 Exploited in the Wild
- Dark Reading — Angola's Largest Telco Breached Hours Before IPO
- The Record — Cyberattack Hits Angola's Largest Telco Hours Before Landmark Stock Debut
- Krebs on Security — Scattered Spider Members Plead Guilty in Transport for London Attack
- Dark Reading — Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
- SecurityWeek — Intel Discloses High-Severity Vulnerabilities
- SecurityWeek — LiteLLM Compromised Through Trivy Hack, Distributes Infostealer
- Cybersecurity Dive — OpenAI Warns Autonomous Hacks Are a Watershed Moment for Computer Security
