By Interestana AI Editorial — AI-drafted, human-overseen. How we report
China-Nexus Actor Exploits VMware vCenter Flaw

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT) group. The attacks involve the exploitation of CVE-2026-59310, a critical directory-traversal vulnerability within the VMware vCenter server. This vulnerability, which carries a CVSS score of 9.8, indicates a severe security risk that could be weaponized by malicious actors to execute arbitrary code on affected systems. The exploitation chain observed suggests that the threat actor is leveraging this flaw to gain initial access and subsequently deploy ransomware derived from the Babuk ransomware family.
VMware vCenter Server is a centralized system management software for VMware vSphere environments, enabling administrators to manage virtual machines and their underlying infrastructure. Its widespread use in enterprise data centers makes vulnerabilities within it particularly attractive targets for sophisticated threat actors. The specific vulnerability, CVE-2026-59310, allows for directory traversal, meaning an attacker can navigate the file system beyond intended boundaries. This capability is often a precursor to further malicious actions, such as uploading malicious files or executing commands. The high CVSS score of 9.8 underscores the critical nature of this flaw, placing it in the "Critical" severity category.
The observed attacks are characterized by the deployment of ransomware that shares significant similarities with the Babuk ransomware. Babuk, first identified in early 2021, is known for its ability to encrypt files and demand ransom payments, often in cryptocurrency. The adaptation or derivation of this ransomware by the suspected China-nexus actor suggests a continued interest in leveraging this particular malware strain for financial gain or disruptive purposes. The attribution to a China-nexus actor indicates a potential connection to state-sponsored or state-aligned activities originating from China, a common characteristic of APT groups.
Broadcom, which acquired VMware in November 2023, released a patch for CVE-2026-59310 on February 27, 2024. Organizations utilizing VMware vCenter Server are strongly advised to apply the available security updates immediately to mitigate the risk of exploitation. The rapid exploitation of this vulnerability following its disclosure highlights the persistent threat posed by APT groups and the importance of timely patching and robust security monitoring. The ongoing analysis of the attack vectors and the specific ransomware variant aims to provide further insights into the threat actor's tactics, techniques, and procedures (TTPs), enabling better defensive strategies against such sophisticated cyber threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.