Critical VMware vCenter Flaw (CVE-2026-59310) Exploited by Suspected China-Nexus APT

A severe directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310), which was patched on July 29, 2026, is now being actively exploited by a suspected China-nexus advanced persistent threat (APT) actor. The attacks involve the deployment of Babuk-derived ransomware, with cybersecurity researchers assessing moderate confidence in the Chinese-speaking origin of the threat actor.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai