[Cybersecurity Digest] Your VMware box is a ransomware target
A hypervisor bug just became a ransomware delivery pipeline for a suspected Chinese state-linked crew, and it is not even the strangest story this week. A shipping label leak may have just handed criminals a target list of crypto wallet owners.
The Big 3
A China-Linked Crew Turned One VMware Bug Into a Ransomware Pipeline
Security researchers have attributed active exploitation of CVE-2026-59310, a severe directory traversal flaw in VMware vCenter Server, to a suspected China-nexus advanced persistent threat group. The attacks surfaced on Monday 17 August 2026 (BST), and the payload at the end of the chain is a Babuk-derived ransomware strain. It is the second vCenter flaw exploited this month, after a separate authentication bypass, CVE-2026-59309, patched on 3 August.
Why it matters: compromising vCenter compromises everything it manages, and using leaked Babuk code as the final payload muddies attribution while the real goal may be espionage rather than ransom.
Self-Spreading Worms Are Loose Inside npm, and They Are Doing the Hacking Themselves
Two self-propagating worms, tracked as Shai-Hulud and ChainDrop, are tearing through the npm registry. They steal maintainer credentials from compromised machines and CI pipelines, then automatically republish infected versions of every package that maintainer controls. No human attacker has to pick the next target. The malicious code does it, at internet speed, across a registry hundreds of thousands of projects depend on.
Why it matters: small utility packages buried three or four layers deep in your dependency tree are exactly what gets trusted by default, and that is exactly what is getting hit hardest.
A Shipping Label Leak Just Handed Out a Target List of Crypto Wallet Owners
Trezor has confirmed a breach, but the fault sits with ShipMonk, the fulfilment partner that packs and ships its hardware wallets. Around 13,689 buyers had data exposed, with 11,742 facing full exposure: name, email, phone number and shipping address. Affected orders span 10 May to 8 August 2026 across seven countries, including the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Why it matters: a list of people who recently bought a device built to secure cryptocurrency, complete with home address and phone number, is close to a ready-made target list for SIM-swap attacks and fake "verify your wallet" phishing.
Quick Hits
Framework got breached too: the laptop maker told customers hackers accessed names, emails, phone numbers and physical addresses, another reminder that hardware brands hold real personal data even when they never touch your files.
44 zero-days hit in a single week: researchers called the week of 17 August one of the most intense exploitation periods on record, with flaws landing in Microsoft Defender, VMware vCenter and SAP Commerce Cloud all at once.
A healthcare ransomware crew claims 114GB stolen: the Krybit group hit ProHealth Medical Group, the latest in a steady drumbeat of ransomware pressure on healthcare providers this year.
OpenAI shipped a hacking-focused AI model: GPT-5.6-Cyber, offered through a new "Daybreak Red" tier for authorised researchers, is built to find zero-days and chain exploits together. AI-enabled attacker activity is already up 89% this year, and this cuts both ways for defenders and criminals alike.
Tool of the Week
YubiKey 5C NFC is a physical hardware security key that replaces SMS codes and authenticator apps with a tap or a plug-in touch. It is built for anyone with a crypto exchange account, an email inbox tied to financial logins, or, after this week's Trezor story, anyone who wants their account recovery process to survive a SIM-swap attempt.
Protect Yourself
Bought a Trezor between 10 May and 8 August 2026? Treat any email, text or call referencing your order as suspicious by default, especially anything asking you to "verify" your wallet by entering a recovery phrase, PIN or seed words anywhere outside the physical device itself. No legitimate hardware wallet company will ever ask for that. If you use SMS codes for any financial account, this is a good week to switch to an authenticator app or a hardware key instead, since SMS is exactly what a SIM-swap attack is built to intercept.
Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter
Stay safe out there. Nath, Future Technology
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.