HackMyIP
← Back to News
2026-08-17 The Hacker News

Weekly Cybersecurity Recap: VMware Exploits, Windows 0-Day, macOS Crypto Mining

APTVulnerabilityZero-Day

Cybersecurity defenses absorbed multiple blows this week as attackers weaponized unpatched enterprise software, exploited newly disclosed operating-system flaws, and turned exposed network services into crypto-mining footholds. From a suspected China-nexus APT abusing VMware vCenter to North Korea-linked Lazarus exploiting a fresh Windows zero-day, the recurring theme was simple: access already granted and monitoring that fell short of the mark.

The most alarming incident involved CVE-2026-59310, a directory-traversal vulnerability in VMware vCenter rated 9.8 on the CVSS scale. Tracked by researchers, the flaw allowed unauthenticated remote code execution on exposed management servers. In at least one confirmed compromise, attackers deployed a backdoor alongside a reverse SSH binary before unleashing Babuk-derived ransomware. Investigators believe the ransomware served as a smokescreen, encrypting evidence to obscure deeper espionage activity. Organizations running public-facing vCenter instances should patch immediately and verify that management interfaces are not exposed to the open internet—a quick port scanner check can confirm whether critical services like the vCenter web port are reachable from outside the perimeter.

Apple's macOS ecosystem also came under active attack this week. CVE-2026-65400, a critical authentication-bypass flaw in the Screen Sharing component (CVSS 9.8), was exploited in the wild to deploy a Monero cryptocurrency miner. The Netherlands' National Cyber Security Center (NCSC-NL) reported multiple cases where attackers gained root access on systems with port 5900 exposed, then planted mining payloads. Apple shipped emergency fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users who haven't yet updated should audit remote-desktop exposure immediately and verify credential integrity with a password checker, since the flaw allowed unauthorized authentication without valid credentials.

Beyond exploitation chains, SANS published new survey data showing that 78% of practitioners have integrated AI into their cybersecurity strategy, up from 50% last year—yet only 36% have a formal AI risk program. The governance gap mirrors the same pattern observed in exposed services: powerful capabilities deployed without sufficient guardrails. A weekly privacy checkup across endpoints, exposed ports, and credential hygiene remains one of the most effective ways to close the small openings that keep escalating into major incidents.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Open ports explained →What is port forwarding? →