Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Summary

Cybersecurity researchers have linked a suspected China-nexus APT to the exploitation of a recently patched VMware vCenter vulnerability. The attacks leveraged CVE-2026-59310, a severe directory-traversal flaw, to enable arbitrary code execution.

IFF Assessment

FOE

The exploitation of a severe vulnerability by a suspected nation-state actor represents a significant threat to organizations using the affected software.

Severity

9.8 Critical

Defender Context

Organizations using VMware vCenter should ensure they have applied the latest patches to mitigate the risk of exploitation. This incident highlights the ongoing threat posed by APT groups targeting critical infrastructure and enterprise software.

Read Full Story →