This weekly threat intelligence bulletin covers multiple critical vulnerabilities, active exploitation campaigns, and supply chain attacks. Key items include critical VMware vCenter/ESX flaws (CVSS 9.8) enabling VM escape, a TeamCity On-Premises unauthenticated RCE, and Russia-linked Storm-2945 compromising hotel captive portals to distribute malware harvesting M365/Azure AD tokens. A separate Russian campaign exploited CVE-2026-42897 in Microsoft OWA to deploy the OWAReaper browser implant, and an npm supply chain attack delivered OS-specific RATs via packages mimicking private Alibaba modules.
CVE-2026-59309
1 post
3rd August – Threat Intelligence Report