logo

Global Threat Campaign Hits Critical VMware vCenter Flaw

ID: fa7b93ba-419b-523b-96ae-39d9c51eaab4

STIX ID: report--fa7b93ba-419b-523b-96ae-39d9c51eaab4

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-08-13

Date Updated: 2026-08-14

Author: Rob Wright

...
...

A critical directory traversal/RCE in VMware vCenter (CVE-2026-59310, CVSS 9.8) was rapidly weaponized by a suspected APT within days of disclosure; QUIRSO observed a global campaign spanning 47 countries and 361 unique IPs, with attackers deploying reverse_ssh to achieve persistent outbound control channels. Organizations are advised to perform forensic investigations, apply patches, isolate management interfaces, restrict outbound connectivity, and use the published YARA rule to detect reverse_ssh builds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.