CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Today's briefing covers active VMware vCenter exploitation, unpatched Unisoc Android kernel flaws, MCP secret exposure risks, and ransomware investigations.

At the same time, enterprise adoption of AI integrations introduces hidden risk surfaces through Model Context Protocol servers. Security teams must prioritize patching core virtualization assets and auditing exposed credentials in automated integrations to maintain perimeter control.

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

A weekly security recap highlights active exploitation of a VMware vCenter directory-traversal vulnerability (CVE-2026-59310) by a suspected China-nexus APT, alongside broader trends involving Windows zero-days, MCP attacks, browser session hijacking, and supply-chain compromises.

Why it matters
Organizations running unpatched VMware vCenter servers face remote code execution risks and potential backdoor deployments from nation-state threat actors.
What to do
Patch VMware vCenter against CVE-2026-59310 and audit exposed infrastructure for unauthorized backdoors and reverse SSH sessions.
  • vmware
  • vcenter
  • apt
  • exploitation
Read the original

How MCP Servers Can Expose Enterprise Secrets

Model Context Protocol (MCP) servers integrated with AI agents can expose sensitive enterprise secrets such as credentials, service account keys, and API tokens through plaintext configuration files, broad access permissions, and prompt injection attacks.

Why it matters
Security teams adopting AI agents risk covert credential leakage and unauthorized access to cloud infrastructure and internal data stores via exposed MCP servers.
  • mcp
  • ai
  • credentials
  • exposure
Read the original

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Researchers published a two-stage exploit chain targeting Unisoc modem firmware via malformed VoLTE video calls, allowing attackers with a private 4G network to achieve full Android kernel access if the victim answers. The chipset vendor has not responded or released a fix.

Why it matters
Users with devices powered by affected Unisoc chipsets are exposed to full kernel compromise without vendor patches currently available.
  • unisoc
  • android
  • kernel
  • firmware
Read the original

Philips and GE investigating Clop ransomware data theft claims

General Electric (GE) and Philips are actively investigating claims made by the Clop ransomware group regarding system breaches and data theft.

  • clop
  • ransomware
  • breach
Read the original

Windows Server 2022 reaches end of mainstream support in 60 days

Microsoft reminded IT administrators that Windows Server 2022 will reach its mainstream end of support in October 2026, transitioning to extended support.

Why it matters
Administrators relying on mainstream support feature updates and standard servicing must prepare for transition to extended support phase planning.
What to do
Review lifecycle roadmaps for Windows Server 2022 environments and plan for extended support requirements.
  • microsoft
Read the original

Key takeaways

  • Patch VMware vCenter immediately to address CVE-2026-59310 and block active directory traversal attacks.
  • Windows Server 2022 reaches its end of mainstream support in 60 days before transitioning to extended support.
  • An unpatched Unisoc VoLTE video call exploit chain permits full Android kernel access via malicious cellular networks.
  • VMware
  • MCP
  • Clop
  • Unisoc
  • WindowsServer2022