DAILY BRIEFING
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Today's briefing covers active VMware vCenter exploitation, unpatched Unisoc Android kernel flaws, MCP secret exposure risks, and ransomware investigations.
5 stories2 min read

At the same time, enterprise adoption of AI integrations introduces hidden risk surfaces through Model Context Protocol servers. Security teams must prioritize patching core virtualization assets and auditing exposed credentials in automated integrations to maintain perimeter control.
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
A weekly security recap highlights active exploitation of a VMware vCenter directory-traversal vulnerability (CVE-2026-59310) by a suspected China-nexus APT, alongside broader trends involving Windows zero-days, MCP attacks, browser session hijacking, and supply-chain compromises.
- Why it matters
- Organizations running unpatched VMware vCenter servers face remote code execution risks and potential backdoor deployments from nation-state threat actors.
- What to do
- Patch VMware vCenter against CVE-2026-59310 and audit exposed infrastructure for unauthorized backdoors and reverse SSH sessions.
How MCP Servers Can Expose Enterprise Secrets
Model Context Protocol (MCP) servers integrated with AI agents can expose sensitive enterprise secrets such as credentials, service account keys, and API tokens through plaintext configuration files, broad access permissions, and prompt injection attacks.
- Why it matters
- Security teams adopting AI agents risk covert credential leakage and unauthorized access to cloud infrastructure and internal data stores via exposed MCP servers.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Researchers published a two-stage exploit chain targeting Unisoc modem firmware via malformed VoLTE video calls, allowing attackers with a private 4G network to achieve full Android kernel access if the victim answers. The chipset vendor has not responded or released a fix.
- Why it matters
- Users with devices powered by affected Unisoc chipsets are exposed to full kernel compromise without vendor patches currently available.
Philips and GE investigating Clop ransomware data theft claims
General Electric (GE) and Philips are actively investigating claims made by the Clop ransomware group regarding system breaches and data theft.
Windows Server 2022 reaches end of mainstream support in 60 days
Microsoft reminded IT administrators that Windows Server 2022 will reach its mainstream end of support in October 2026, transitioning to extended support.
- Why it matters
- Administrators relying on mainstream support feature updates and standard servicing must prepare for transition to extended support phase planning.
- What to do
- Review lifecycle roadmaps for Windows Server 2022 environments and plan for extended support requirements.
Key takeaways
- Patch VMware vCenter immediately to address CVE-2026-59310 and block active directory traversal attacks.
- Windows Server 2022 reaches its end of mainstream support in 60 days before transitioning to extended support.
- An unpatched Unisoc VoLTE video call exploit chain permits full Android kernel access via malicious cellular networks.