< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-08-17T13:06:19+05:30

China-Nexus APT Exploits VMware vCenter Vulnerability with Babuk Ransomware

A suspected China-nexus APT exploited a critical VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware, targeting 361 global victims. The attack involved cron jobs, backdoors, and credential theft, with evidence linking the activity to Chinese-speaking threat actors.

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).

The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

Read original article

*** END OF TRANSMISSION ***