Out-of-bounds write vulnerability in VMXNET3 virtual network adapter of VMware ESXi with CVSS score 9.3. Allows malicious actor with local administrative privileges on a virtual machine to execute code on the ESXi host, enabling VM escape.
Apply VMware patches to all ESXi hosts immediately. Review virtual machine administrator access controls and implement principle of least privilege. Monitor ESXi hosts for unusual activity from guest VMs. Consider disabling VMXNET3 adapter on untrusted VMs until patching is complete.
Source: NVD • Published: 2026-07-30
Sophisticated supply chain compromise of Trivy vulnerability scanner on March 19, 2026. Threat actor used compromised credentials to publish malicious v0.69.4-0.69.6 releases, force-push 76 of 77 version tags in trivy-action to credential-stealing malware, and replace all setup-trivy tags. Attack exposed CI/CD secrets, planted backdoors on developer machines, and propagated worm across npm packages. European Commission AWS credentials compromised.
Immediately remove Trivy versions 0.69.4, 0.69.5, and 0.69.6. Downgrade to 0.69.3 or upgrade to verified clean version. Review all CI/CD pipelines using aquasecurity/trivy-action or aquasecurity/setup-trivy between March 19-22, 2026 for compromise. Rotate all secrets and credentials accessible to affected pipelines. Scan developer machines that ran compromised Trivy versions for persistent backdoors. EC organizations: review AWS account activity for unauthorized access.
Source: GTIG • Published: 2026-03-19
Qilin ransomware gang actively exploiting CVE-2026-0257 (PAN-OS GlobalProtect authentication bypass) and CVE-2026-50751 (Check Point VPN authentication bypass) to breach corporate networks. PAN-OS exploitation began May 17, 2026 following Palo Alto patch release May 13. Check Point attacks started May 7, surged in June, affecting dozens of organizations worldwide.
Immediately patch PAN-OS GlobalProtect (CVE-2026-0257) and Check Point Remote Access VPN (CVE-2026-50751). Conduct forensic investigation of VPN access logs since May 7, 2026 for unauthorized access. Reset VPN user credentials and enable MFA if not already deployed. Isolate and investigate any systems accessed via VPN during exploitation window. Deploy Qilin ransomware IOCs and hunting queries. Ensure offline, immutable backups are available. Organizations using these VPN products should assume elevated risk of Qilin targeting.
Source: GTIG • Published: 2026-05-17
Russia-linked APT28 (UAC-0001) Operation Neusploit campaign exploiting CVE-2026-21509, a security feature bypass in Microsoft Office with CVSS 7.8. Weaponized on January 29, 2026 targeting users in Ukraine, Slovakia, and Romania. Part of broader APT28 campaign leveraging Office vulnerabilities for initial access.
Apply Microsoft patches for CVE-2026-21509 immediately. Deploy Office security baselines and enable Attack Surface Reduction rules. Implement email security controls to block malicious Office documents. Monitor for APT28 TTPs including spearphishing with malicious attachments. Organizations in Ukraine, Slovakia, and Romania should prioritize threat hunting for compromise indicators since January 29, 2026.
Source: GTIG • Published: 2026-01-29
Russia-linked APT28 (Forest Blizzard) FrostArmada campaign compromising insecure MikroTik and TP-Link routers since May 2025. Modified router settings to turn devices into malicious infrastructure for DNS redirection. At peak in December 2025, over 18,000 unique IPs from 120+ countries communicated with APT28 infrastructure. Large-scale exploitation continued through 2026.
Immediately update MikroTik and TP-Link router firmware to latest versions. Change default credentials and implement strong authentication. Disable remote management interfaces or restrict to trusted IPs. Review DNS settings for unauthorized modifications. Check router logs for connections to known APT28 infrastructure. Factory reset and reconfigure routers if compromise suspected. Implement network monitoring for DNS hijacking attempts.
Source: GTIG • Published: 2026-05-01
CVE-2026-47876: Out-of-bounds write vulnerability in VMXNET3 virtual network adapter of VMware ESXi with CVSS score 9.3. Allows malicious actor with local administrative privileges on a virtual machine to execute code on the ESXi host, enabling VM escape.