Close Menu
NCIJ Network NCIJ Network
    What's Hot

    James Webb captures a cosmic lion sculpted by a dying star

    August 13, 2026

    Chicago Mayor Seeks to Curb Health and Environmental Impacts of Data Centers

    August 13, 2026

    House toss-up dashboard: Following the money in the 19 races that matter most • OpenSecrets

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • James Webb captures a cosmic lion sculpted by a dying star
    • Chicago Mayor Seeks to Curb Health and Environmental Impacts of Data Centers
    • House toss-up dashboard: Following the money in the 19 races that matter most • OpenSecrets
    • I got married in the Vegas of Europe. It was the most romantic 20 minutes of my life | Jules Darmanin
    • Search efforts in Colombia enter ‘final phase’ as quake toll reaches 265 | Earthquakes News
    • How Russian attacks, European protectionism and drought are trapping Ukraine’s vital grain – POLITICO
    • Trump Administration Lets Parts of the National Firearms Act Lapse
    • US justice department shifts focus to government programme fraud
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Vulnerability / Threat Intelligence

    Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.

    The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were released by Broadcom late last month.

    The German cybersecurity company said it discovered the activity following an incident response engagement. The attack chain is said to have exhibited path traversal activity consistent with the flaw, followed by the deployment of a malicious cron job to establish persistence on the host using reverse_ssh, an open-source tool used for setting up SSH connections to threat actor-controlled infrastructure.

    Compromised systems identified by QUIRSO were found to first establish contact with the attacker’s domains on August 3, five days after Broadcom publicly disclosed the flaw. In all, there are as many as 361 unique victim IP addresses located across 47 countries. Most of them are located in Germany, the U.S., Turkey, Iran, and France.

    Cybersecurity

    “While the attacker might have had prior knowledge of the vulnerability, the strong correlation between the time of disclosure and exploitation suggests the disclosure as the initial starting point for the campaign,” QUIRSO added.

    It’s not clear who is behind the exploitation campaign, but it’s believed to be the work of a suspected advanced persistent threat (APT) actor.

    It’s worth pointing out that VMware appliances have been a lucrative target for Chinese threat actors like UNC5174, who have weaponized security flaws impacting VMware Tools and VMware vCenter in various espionage campaigns.

    In April 2025, SentinelOne disclosed details of a China-nexus threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.

    The use of reverse_ssh is notable as it allows the attacker to establish an outbound connection to an endpoint under their control, effectively bypassing security controls designed to prevent suspicious inbound requests.

    “The presence of reverse_ssh should not, by itself, be treated as proof of malicious activity,” QUIRSO noted. “In combination with unauthorized installation, unexpected outbound connections or execution on a vulnerable vCenter appliance, however, it is a high-priority indicator requiring investigation.”

    The disclosure comes as Defused Cyber said it’s observing a spike in scanning against VMware vCenter that is indicative of potential exploitation efforts targeting CVE-2026-59309 (CVSS score: 9.8).

    Cybersecurity

    “Our honeypots are logging increased fingerprinting – such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow – coinciding with Broadcom’s VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8),” the cybersecurity company said.

    Denis Szadkowski, COO and co-founder of QUIRSO GmbH, told The Hacker News that there is not enough evidence at this stage to correlate exploitation and scanning efforts using CVE-2026-59309 with the intrusion set or the attacker infrastructure associated with CVE-2026-59310.

    “What we can say with much higher confidence is that the activity we investigated represents a successful compromise rather than merely exploitation attempts, and the forensic evidence strongly points toward CVE-2026-59310 as the initial access vector,” Szadkowski added.

    access Attackers exploit gain Persistent remote vCenter VMware Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Ceva Logistics Operations Disrupted by Cyberattack

    Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    ‘Inner Thoughts’ of Every Major AI Model Exposed in Massive Exploit

    WhatsApp Unveils New Scam Alert Feature

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    James Webb captures a cosmic lion sculpted by a dying star

    August 13, 2026

    Chicago Mayor Seeks to Curb Health and Environmental Impacts of Data Centers

    August 13, 2026

    House toss-up dashboard: Following the money in the 19 races that matter most • OpenSecrets

    August 13, 2026

    I got married in the Vegas of Europe. It was the most romantic 20 minutes of my life | Jules Darmanin

    August 13, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    James Webb captures a cosmic lion sculpted by a dying star

    August 13, 2026

    Chicago Mayor Seeks to Curb Health and Environmental Impacts of Data Centers

    August 13, 2026

    House toss-up dashboard: Following the money in the 19 races that matter most • OpenSecrets

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.