Global Threat Campaign Hits Critical VMware vCenter Flaw
ID: fa7b93ba-419b-523b-96ae-39d9c51eaab4
STIX ID: report--fa7b93ba-419b-523b-96ae-39d9c51eaab4
Feed Name: Dark Reading
A critical directory traversal/RCE in VMware vCenter (CVE-2026-59310, CVSS 9.8) was rapidly weaponized by a suspected APT within days of disclosure; QUIRSO observed a global campaign spanning 47 countries and 361 unique IPs, with attackers deploying reverse_ssh to achieve persistent outbound control channels. Organizations are advised to perform forensic investigations, apply patches, isolate management interfaces, restrict outbound connectivity, and use the published YARA rule to detect reverse_ssh builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
