Today’s lead:CISA ransomware flag turns vCenter patching into incident triageCisco email-gateway zero-day gives attackers root through email parsingGemStuffer package count expands as OpenAI attribution remains…NIST finalises token-protection controls for agencies and cloud…
Front page · Daily intelligence
CISA ransomware flag turns vCenter patching into incident triage
CISA’s ransomware designation for CVE-2026-59310 changes the VMware vCenter response from emergency patching alone to control-plane compromise assessment and recovery validation.
By Security.io Intelligence Desk · Executive analysis
CISA has marked VMware vCenter vulnerability CVE-2026-59310 as used in ransomware campaigns. Broadcom patched the unauthenticated vCenter Syslog server code-execution flaw on July 29, 2026, but the ransomware update means enterprises can no longer close the issue with patch status alone.
Why today: This ranked first because the materially new ransomware designation changes an already exploited July vulnerability from urgent maintenance into a potential enterprise-wide recovery event. vCenter’s privileged control-plane position, the absence of a workaround and the lack of ransomware-specific…
“Inventory every vCenter instance, fixed release, owner and management-network exposure.”
Decision owner: Infrastructure and platform security leadership, jointly with incident response and resilience owners.
Decision horizon: Begin compromise triage immediately and resolve patch or isolation exceptions before the next production change window.
CISA has marked VMware vCenter vulnerability CVE-2026-59310 as used in ransomware campaigns. Broadcom patched the unauthenticated vCenter Syslog server code-execution flaw on July 29, 2026, but…
Today’s action: Inventory every vCenter instance, fixed release, owner and management-network exposure.
Cisco has confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Cisco Secure Email Gateway that can lead to root command execution.
Today’s action: Identify every physical, virtual and cloud-managed Cisco Secure Email Gateway instance.
JFrog Security Research identified 3,022 GemStuffer-associated RubyGems packages covering 3,315 name/version pairs and described payloads that used RubyDoc documentation workers for web retrieval, metadata injection and…
Today’s action: Search registries, caches and build logs for slnleaker5 0.0.1 and oaifetchmde1778385544.
Specialist reporting on Hunt.io's findings describes an attacker-controlled staging server containing 298 files and evidence of active root-level access inside 3BB.
Today’s action: Search network and endpoint telemetry for the published IP, domain, group and…
NIST published final IR 8587 on September 15, 2026, providing implementation guidance for protecting identity tokens, access tokens and assertions used in single sign-on, federation, APIs…
Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.
Security.io scores each dimension from 0–100 using evidenced reachability, exploitation state, privileged placement, remediation constraints and credible operational impact. These are editorial decision scores, not externally reported measurements.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.