As cited
Copy frozen at (site build).
ransomware
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Researchers have attributed exploitation of CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter (CVSS 9.8), to a suspected China-linked APT group. The attackers are deploying a Babuk-derived ransomware variant against affected organizations.
Why it matters: VMware vCenter administrators and organizations running vulnerable instances face immediate risk of code execution and ransomware deployment; patching CVE-2026-59310 is a priority given active exploitation by a sophisticated threat actor.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Researchers have attributed exploitation of CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter (CVSS 9.8), to a suspected China-linked APT group. The attackers are deploying a Babuk-derived ransomware variant against affected organizations.
Why it matters: VMware vCenter administrators and organizations running vulnerable instances face immediate risk of code execution and ransomware deployment; patching CVE-2026-59310 is a priority given active exploitation by a sophisticated threat actor.
- Source published
- First seen by Cybersecurity Tracker