<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vmware-Vcenter on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vmware-vcenter/</link><description>Recent content in Vmware-Vcenter on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 11:37:07 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vmware-vcenter/index.xml" rel="self" type="application/rss+xml"/><item><title>China-Nexus APT Exploits VMware vCenter CVE-2026-59310, Drops Babuk Ransomware</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-dep/</link><pubDate>Mon, 17 Aug 2026 11:37:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-dep/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVE-2026-59310 (CVSS 9.8) is under active APT exploitation with a public PoC; patch VMware vCenter to the vendor-released fixed version immediately — do not wait for a maintenance window given confirmed in-the-wild exploitation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Assume-breach posture for any vCenter environment: hunt for signs of post-exploitation activity and Babuk-derived ransomware staging since the patch release date, and build detections around directory-traversal followed by unusual process spawning from vCenter services.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A China-nexus APT is actively deploying ransomware via a critical vCenter flaw — confirm whether your environment runs vCenter, verify patch status with your engineering team this week, and prepare a brief for leadership given the ransomware and nation-state dimensions.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>VMware vCenter RCE flaw CVE-2026-59310 exploited for reverse SSH backdoor</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-a/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> vCenter is core infrastructure for most enterprise estates and active exploitation is deploying persistent reverse SSH tunnels — patch CVE-2026-59310 immediately and audit vCenter hosts for unexpected outbound SSH connections or new SSH tunnel processes.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> The campaign&amp;rsquo;s TTP is specific and huntable: sweep for outbound SSH sessions originating from vCenter server hosts, flag any reverse tunnel tools (socat, plink, autossh) running on hypervisor management nodes since the vulnerability&amp;rsquo;s disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Active exploitation of a critical vCenter RCE means full-estate exposure for organizations running VMware — confirm with engineering this sprint that patching is complete and request a status update before this surfaces in a customer security questionnaire.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Attackers Exploiting VMware vCenter RCE Flaw CVE-2026-59310</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-attackers-exploit-vmware-vcenter-vulnerability-to-gain-persi/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-attackers-exploit-vmware-vcenter-vulnerability-to-gain-persi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> vCenter is core infrastructure and a CVSS 9.8 directory-traversal-to-RCE with reported active exploitation warrants immediate patching despite weak enrichment signals (not KEV, EPSS 0.01). Apply Broadcom&amp;rsquo;s patch for CVE-2026-59310 and audit vCenter network access controls to reduce exposure while rolling out.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Active exploitation is reported by a single vendor (QUIRSO) but no IOCs or ATT&amp;amp;CK-mapped TTPs are published yet, leaving no sweep surface today. Build or tune detections for post-exploitation behavior originating from vCenter hosts (unusual process spawning, outbound connections from vCenter management IPs) in anticipation of broader disclosure.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A 9.8-severity RCE in widely deployed VMware vCenter with reported exploitation is worth a prompt check-in with the engineering team to confirm patch status, but the single-source report and absence of a KEV listing mean this does not yet require board escalation or a customer-facing statement.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, no public PoC found&lt;/li>
&lt;/ul></description></item></channel></rss>