CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · August 13, 2026

TL;DR for CISOs: A critical VMware vCenter flaw (CVE-2026-59310) is being exploited in the wild to plant persistent access on hundreds of servers worldwide, and three more high-impact issues, a CVSS 10 Metabase zero-day, a state-backed Gunra ransomware advisory, and a Lazarus Windows kernel zero-day, all landed in the same 24 hours.

BOTTOM LINE FOR CISOS
  1. Patching your edge and management plane is necessary but not sufficient. Two of today's items involve attackers who were already inside before the fix landed, so treat exposed vCenter, Fortinet, and RMM systems as compromise-until-proven-clean.
  2. Business intelligence and automation tools are now credential vaults. The Metabase flaw shows how one internet-facing analytics box can hand over every downstream database credential it holds.
  3. Federal agencies have a August 14 deadline on the Metabase flaw. If a US government due date is measured in days, your private-sector risk window is the same.
CRITICAL · LEAD STORY

VMware vCenter flaw exploited to hold persistent access on 361 systems

CVE-2026-59310 · Broadcom VMware vCenter · Directory traversal to remote code execution

Key facts
  • CVE-2026-59310, CVSS 9.8, a directory-traversal flaw in the vCenter Syslog service that lets an unauthenticated attacker with network access run arbitrary code.
  • Researchers at German firm QUIRSO counted 361 unique victim IP addresses across 47 countries, cautioning that one IP does not always equal one organization.
  • Compromised hosts first contacted attacker infrastructure on August 3, five days after Broadcom disclosed the flaw. By August 5, roughly 95% of the victims had appeared.
  • Fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f. Broadcom has published no workaround.

What happened

Broadcom published its advisory for two critical vCenter flaws on July 29 and revised it on August 3 to add express patches. QUIRSO says it uncovered active exploitation of one of them, CVE-2026-59310, during an incident response engagement and published its analysis on August 10. The attack chain showed path-traversal activity matching the flaw, followed by a malicious cron job that used reverse_ssh, an open-source reverse-shell framework, to keep a foothold on the host.

Because reverse_ssh dials outbound to attacker-controlled infrastructure rather than accepting inbound connections, it slips past controls built to block unsolicited inbound traffic. Germany, the United States, Turkey, Iran, and France accounted for 185 of the 361 victim IPs. QUIRSO attributes the campaign to a suspected advanced persistent threat actor but has not named one. Separately, Defused Cyber reported a scanning spike against the second flaw, CVE-2026-59309, a CVSS 9.8 authentication bypass in VMware Directory Service, though QUIRSO says there is not yet enough evidence to link that scanning to the intrusion set it investigated.

Evidence

Verified against two independent sources:

What this means for your team

vCenter sits at the center of most virtualized estates, so a foothold there is a foothold over the workloads it governs. The five-day gap between disclosure and mass exploitation is the real lesson: the advisory itself appears to have been the starting gun. As Sectigo's Jason Soroko put it, there are two clocks to manage, one for closing the hole and one for evicting anyone who walked through it first. If your vCenter was internet-reachable in late July, a clean patch does not answer the second question.

Action checklist
  1. Confirm every vCenter appliance is on a fixed build (9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f) and remove any management interface from direct internet exposure.
  2. Hunt for reverse_ssh, unexpected cron jobs, and outbound connections from vCenter hosts to unfamiliar domains, treating any exposed appliance as potentially compromised before August 3.
  3. Rotate vCenter and single sign-on credentials and review SAML and vmdir authentication logs for the second flaw, CVE-2026-59309.
CRITICAL

Metabase zero-day scored a perfect 10 and had already breached five companies

CVE-2026-72898 · Metabase self-hosted · Unauthenticated SQL injection to admin takeover

Key facts
  • CVE-2026-72898, CVSS 10.0, an SQL injection in a password-reset API endpoint that lets an unauthenticated attacker with HTTP access gain administrator control of the instance.
  • Affects self-hosted Metabase versions 0.58 through 0.63.4.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 11, with a federal remediation deadline of August 14, 2026.
  • Metabase disclosed the issue on August 6. By then, according to reporting, five companies had already lost customer data.

What happened

Metabase is a widely used business-intelligence layer that stores connection strings for the databases it queries, from Snowflake and BigQuery to Oracle, MongoDB, and Amazon Redshift. An attacker who reaches administrator level can change configuration, read those stored credentials, and pivot into every connected system. Workflow-automation vendor n8n disclosed that an unauthorized party used the flaw to query its Metabase environment and obtain 136 customer records. CISA listed the flaw alongside a Cisco Secure Firewall ASA and FTD vulnerability in the same catalog update.

Evidence

What this means for your team

Analytics and automation tools rarely get the same scrutiny as the databases behind them, yet they concentrate exactly the credentials an attacker wants. A single internet-facing Metabase box with stored warehouse credentials is a master key. The federal deadline of August 14 is a useful yardstick: if the government considers this a days-not-weeks problem, so should you.

Action checklist
  1. Patch self-hosted Metabase off the 0.58 to 0.63.4 range immediately and take any internet-facing instance behind VPN or SSO.
  2. Assume credential exposure: rotate the stored credentials for every database, warehouse, LDAP, and SMTP connection your Metabase instances hold.
  3. Review Metabase and downstream database logs for unexpected admin creation, configuration changes, or bulk queries since early August.
HIGH

FBI and Korean police warn Gunra ransomware is hitting critical infrastructure through old Fortinet flaws

CVE-2024-55591 and CVE-2025-24472 · FortiOS and FortiProxy · Ransomware-as-a-service

Key facts
  • A joint advisory (AA26-222A) from the FBI, CISA, other US agencies, and the Republic of Korea National Police Agency, published August 10, details Gunra's tactics.
  • Gunra exploits two patched Fortinet authentication-bypass flaws, CVE-2024-55591 (critical) and CVE-2025-24472 (high), to gain super-admin access to internet-facing appliances.
  • Victims span healthcare, financial services, government, and critical manufacturing worldwide. Ransom demands start in the tens of millions.
  • The group, built on leaked Conti source code and also operating as "Golden Community," works between 10pm and 6am in the victim's time zone to avoid detection.

What happened

Gunra affiliates use known VPN and firewall flaws for initial access, then move laterally with stolen credentials and authentication-bypass tricks. In observed cases they abused default credentials on an SSL-VPN appliance, installed OpenSSH to tunnel out, and modified authentication files on a corporate VDI portal to bypass multi-factor authentication continuously. The group exfiltrates large volumes of data from Microsoft 365, OneDrive, and SharePoint, in one case moving tens of terabytes to the file-sharing service Mega before encrypting, then extorts victims twice, once for decryption and once to keep the stolen data offline. As iCOUNTER's Roman Sannikov noted, if detection coverage drops overnight, that is exactly the window this group is built to exploit.

Evidence

What this means for your team

The flaws Gunra favors were patched more than a year ago, which is the uncomfortable point: patch coverage without eviction leaves the door open. One expert quoted in the advisory coverage described closing a Fortinet vulnerability while an authentication backdoor sat untouched in the MFA flow. Edge devices remain the single most common ransomware entry point, and the after-hours operating pattern is a direct argument for round-the-clock detection coverage.

Action checklist
  1. Confirm FortiOS and FortiProxy appliances are patched for CVE-2024-55591 and CVE-2025-24472, and audit for backdoor admin accounts and modified authentication files.
  2. Maintain offline, immutable backups in a segmented location, and test recovery so a ransom payment is never the only path back.
  3. Extend detection and response coverage into the 10pm to 6am window and alert on OpenSSH tunneling and large outbound transfers to services like Mega.
HIGH

Lazarus used a Windows kernel zero-day to hit defense and aerospace firms

CVE-2026-68820 · Windows AFD.sys · Privilege escalation to SYSTEM

Key facts
  • CVE-2026-68820, CVSS 7.0, a use-after-free race condition in AFD.sys, the Windows Ancillary Function Driver for WinSock, that grants SYSTEM privileges.
  • Microsoft patched the flaw on August 11 after finding it exploited in the wild; evidence points to exploitation since at least early July.
  • Check Point Research attributes the activity to North Korea's Lazarus Group as part of the long-running Operation Dream Job campaign.
  • Confirmed targeting of defense, aerospace, and aviation organizations in France, Germany, Brazil, and India, with a focus on military technology, drones, and robotics.

What happened

Operation Dream Job lures targets with fake recruitment offers. In this wave, once a system was compromised, the attackers used the AFD.sys zero-day to escalate to SYSTEM and deploy a new version of the FudModule kernel-mode rootkit, which is built to disable security tooling from below the operating system. The campaign is a reminder that a mid-scored privilege-escalation bug becomes a strategic weapon when it is chained behind a convincing social-engineering front and used to plant a rootkit.

Evidence

What this means for your team

If your organization touches defense, aerospace, or advanced manufacturing, the recruitment lure is aimed at your people, not just your perimeter. The August Patch Tuesday fix closes the escalation path, but the initial access depends on an employee opening a weaponized file. Pair rapid kernel patching with hiring-adjacent phishing awareness for engineering and research staff.

Action checklist
  1. Deploy the August 11 Windows updates that fix CVE-2026-68820, prioritizing endpoints used by engineering, R&D, and defense-program staff.
  2. Hunt for FudModule rootkit indicators and unexplained SYSTEM-level activity on recently targeted hosts.
  3. Brief technical staff on the fake-job-offer lure and route unsolicited recruitment attachments through a sandbox.

Also notable

  • N-able N-central authentication bypass (CVE-2026-18577, CVSS 8.2): attackers took over RMM servers after an incomplete first patch, reached managed endpoints via Take Control, and persisted with Cloudflare tunnels. Upgrade to build 2026.3.1.7. The Hacker News
  • Cisco Secure Firewall ASA and FTD heap-inspection flaw (CVE-2026-20349) was added to the CISA KEV catalog on August 11 in the same update as the Metabase flaw. CISA
  • Adobe Commerce and Magento (CVE-2026-71362): first exploitation attempts appeared shortly after patches, with a risk of customer account hijack. BleepingComputer
  • Microsoft SharePoint security-feature bypass (CVE-2026-55040): exploitation began after proof-of-concept code was published; the flaw was patched in July. SecurityWeek
  • CERT.PL reported Russian-linked hackers reached a Polish power plant OT network through a private APN. Infosecurity Magazine

FAQ

Is CVE-2026-59310 being actively exploited?

Yes. Researchers at QUIRSO documented active exploitation across 361 victim IP addresses in 47 countries, with the first compromises appearing on August 3, five days after Broadcom disclosed the flaw.

Which Metabase versions are affected by CVE-2026-72898?

Self-hosted Metabase versions 0.58 through 0.63.4. The flaw carries a CVSS score of 10.0 and CISA set a federal remediation deadline of August 14, 2026.

Why does patching alone not close out these incidents?

In the vCenter, Fortinet, and N-able cases, attackers established persistence before or despite the patch. A fix removes the entry point but does not evict an intruder who is already inside or remove backdoors planted on other systems.

Who is behind the Gunra ransomware campaign?

Gunra is a ransomware-as-a-service operation built on leaked Conti source code, also operating under the alias "Golden Community." The joint US and Republic of Korea advisory details its tactics but does not attribute it to a single nation-state.

What is the fastest way to prioritize today's items?

Start with anything internet-facing: vCenter, Metabase, and Fortinet appliances first, then apply the August 11 Windows kernel patch to high-value engineering and defense endpoints.

CISO Platform Breach Intelligence Team
Explore more in the CISO Platform Breach Intelligence hub, and related community coverage on ransomware, vulnerability management, and threat intelligence.
Stay ahead of the next breach
Join the CISO Platform community (free) to compare notes with 6,000+ security leaders.
Subscribe to the weekly newsletter for the breach and AI-risk roundup.
Visit the Breach Intelligence hub for the full archive.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion