A suspected China-nexus actor reportedly exploited CVE-2026-59310 only 5 days after disclosure, compromising an estimated 361 IPs across 47 countries.

The attack chain reportedly went from:

vCenter → Root Access → Credential Theft → ESXi → Babuk-derived ransomware

The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.

I broke down the full attack chain, persistence mechanisms, credential harvesting, ESXi lateral movement, and ransomware deployment.

  • Onomatopoeia@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 days ago

    The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.

    Not really, that’s the management layer - it has authority over everything.

    It’s why we secure access to such stuff.