HeadFlash

Security

vCenter zero-day chain lets attackers forge admin logins without a password

Two CVSS 9.8 vCenter flaws, one exploited in the wild, plus 474 still-valid leaked GitHub App keys and a Gemini-powered malware implant.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Critical vCenter pre-auth flaws patched after one hits active exploitation

Broadcom fixed two CVSS 9.8 pre-authentication bugs in vCenter Server Appliance under VMSA-2026-0006, with one already flagged as exploited in the wild. CVE-2026-59309 is an authentication bypass in VMware Directory Service: sending A = N collapses the SRP shared secret to zero, letting an attacker bind as [email protected] without a password. CVE-2026-59310 is a directory traversal in the vCenter Syslog receiver that enables arbitrary file write and remote code execution. Affected builds are 8.0.3.00900 and earlier 8.0.3.x; the fix ships in 8.0.3.01000. Mitigations include restricting syslog and vmdird LDAP ports to trusted networks.

vCenter pre-auth RCE: CVE-2026-59309/59310 | Mobeta →

474 leaked GitHub App private keys still authenticate, GitGuardian finds

GitGuardian extracted over 500,000 RSA private keys from its leaked-secret dataset, narrowed them to 4,802 used in GitHub App contexts, and found 474 keys, roughly 10 percent, still authenticated against the /app API, spanning 440 distinct Apps. Seventy-two percent of those Apps held content permissions for private repositories, 207 could write repository content, 44 had organization admin rights, and 98 could control workflows. Keys never expire. Notable cases include GitHub Actions Access Tokens, leaked in January 2024 with 304 installations, and BuildBuddy, whose App was taken down with no malicious exploitation found. A CDC-linked App was revoked on September 18 after disclosure.

GitHub App Private Keys: 474 Leaked Keys Still Work →

ClosedQuorum malware lets AI models pick its next move

Cisco Talos documented ClosedQuorum, a Go-based Windows implant that uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously choose post-compromise actions via a voting system, with DeepSeek breaking ties. Decisions are limited to a predefined set: steal, which runs LSASS credential dumping, browser credential theft, and crypto-wallet extraction; inject, generating shellcode for process hollowing or Early Bird APC injection; and persist. A move option exists but has no handler in the analyzed build. Stolen data goes to operators through a Discord webhook. Talos calls it the first publicly documented Windows implant delegating tactical command-and-control to AI models.

New ClosedQuorum Windows malware uses AI for attack decisions →

SpyCloud: stolen credentials expose 1,787 US water providers

SpyCloud built a database of more than 66,000 public-facing systems registered with the EPA, covering 10,000 organizations, and found password-stealing malware had swiped credentials from 1,787 water and wastewater providers, nearly two in ten. At least 250 had credentials that appeared to grant access to operational networks and remote-access systems controlling pumps and water flows. One unnamed metering tech provider breach exposed passwords for 167 utility companies. Infostealers also capture session tokens that can bypass multi-factor authentication. The findings follow hacks on US water providers privately tied by the government to Iran-backed hackers, though SpyCloud found no evidence those relied on stolen passwords.

Stolen passwords are exposing America’s water providers to hackers →

D-Link disclosed a maximum-severity zero-day, CVE-2026-86296, in legacy DIR-822A dual-band Wi-Fi routers: a stack-based buffer overflow in the DHCP server component exploitable without authentication or user interaction by attackers on the same local network sending crafted DHCP packets. No patch exists and public proof-of-concept code has been released. D-Link is also investigating CVE-2026-86510, a critical out-of-bounds write in the L2TP control message parser reported by the same researcher. The company advised keeping the routers off the internet, restricting remote management, and limiting administrative access. CISA tracks 26 D-Link flaws exploited in attacks, two abused by ransomware gangs.

D-Link warns of max severity zero-day bug in DIR-822A routers →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches