This day 02:06 06:06 10:06 14:07 18:07 22:07
⚠ exploit status: CVE-2026-59310 · KEV·R
Info  2026-08-13 22:07Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-08-13 — EDR Evasion and Patch-Resistant vCenter Exploitation

Executive summary: The active exploitation campaign against VMware vCenter CVE-2026-59310KEV·R has evolved—researchers now warn that patching alone may not fully remediate compromised environments, implying persistence mechanisms survive the fix. Separately, an Akira ransomware affiliate demonstrated a practical EDR-disabling technique by forcing Windows into Safe Mode with Networking, exfiltrating data before encryption failed. A peculiar legal case out of Russia highlights how Telegram's paid "reactions" can carry criminal liability.

Top items

Themes

EDR evasion is moving to the OS layer. The Akira Safe Mode technique joins a growing pattern of attackers abusing built-in OS mechanisms (Safe Mode, USB Plug-and-Play auto-install, driver signing) rather than deploying custom bypass tooling—making detection harder for tooling that assumes a normal boot environment.

Patching ≠ remediation. The vCenter development reinforces that high-privilege RCE flaws in infrastructure appliances frequently result in persistence that outlives the patch. Incident responders should treat patching as the start, not the end, of containment.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db