AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 18 Aug, 16:13

Suspected China-linked hackers exploited a critical VMware vCenter flaw, breaching 361 networks across 47 countries

A suspected China-nexus threat actor exploited a critical VMware vCenter flaw (CVE-2026-59310, CVSS 9.8) to compromise at least 361 networks across 47 countries, deploying Babuk-derived ransomware on at least one system. Per The Hacker News and Security Boulevard.

Cybersecurity researchers at German incident-response firm QUIRSO say a suspected China-nexus threat actor, assessed with moderate confidence to be a Chinese-speaking group operating in the UTC+8 time zone, has been exploiting CVE-2026-59310, a directory-traversal flaw in Broadcom's $AVGO VMware vCenter Server (CVSS score 9.8). Broadcom released a patch on July 29, 2026, but the attack campaign began just five days later. QUIRSO estimates at least 361 unique victim IP addresses were compromised across 47 countries, with Germany (55), the United States (41), Turkey (38), Iran (26) and France (25) hit hardest. On at least one analyzed system, the intrusion chain ended with ransomware encrypting files with the '.babyk' extension, associated with Babuk-derived ransomware. Researchers say it is unclear if the ransomware was the campaign's main goal, or a smokescreen deployed to destroy log evidence and hinder forensic analysis. Sources: The Hacker News, Security Boulevard.

#cyber
Published on