Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
VMware vCenter Vulnerability Exploited by Hackers

VMware vCenter Vulnerability Exploited by Hackers

Posted on August 13, 2026 By CWS

Cyber attackers have begun leveraging a critical vulnerability in VMware vCenter, as reported by the cybersecurity firm Quirso. This flaw, identified as CVE-2026-59310, was initially addressed by Broadcom on July 29, alongside other security issues in various VMware products.

Details of the Vulnerability

The vulnerability, with a CVSS score of 9.8, is a directory traversal bug in the Syslog server that could be exploited for remote code execution. According to Broadcom, attackers with network access to vCenter can potentially execute arbitrary code by exploiting this flaw.

Quirso observed that an advanced persistent threat (APT) group is actively targeting web-accessible VMware vCenter servers that remain susceptible to CVE-2026-59310. The attackers utilize a reverse shell to gain persistent access to these systems.

Global Impact and Exploitation

Quirso’s analysis revealed that more than 360 victim IP addresses, spanning 47 countries, have been compromised. Notably, half of these IPs are concentrated in Germany, the United States, Turkey, Iran, and France. However, the cybersecurity firm notes that IP addresses might not directly map to specific organizations since they often represent shared infrastructure or cloud networks.

The exploitation campaign began shortly after the vulnerability was disclosed, with over 340 IP addresses engaging with the attackers’ infrastructure by August 5. Quirso suggests that the public disclosure of the vulnerability likely triggered the campaign’s initiation.

Mitigation and Recommendations

Post-compromise, attackers have been deploying the open-source SSH reverse shell framework, reverse_ssh, to maintain communication with infected systems. This tactic helps them circumvent security measures that typically block inbound connections.

To aid in identifying these attacks, Quirso released a generic YARA rule designed to detect reverse_ssh builds. Organizations with exposed vCenter systems are advised to verify any detections by checking for unauthorized installations and unexpected outbound connections or activity.

The ongoing situation underscores the critical need for organizations to promptly apply security patches and monitor their systems for any signs of compromise to mitigate the risks associated with such vulnerabilities.

Security Week News Tags:APT, Broadcom, CVE-2026-59310, Cybersecurity, Quirso, remote code execution, reverse shell, Security, vCenter, VMware, Vulnerability, YARA rule

Post navigation

Previous Post: Akira Ransomware Exploits Safe Mode to Bypass Security
Next Post: Phantom Stealer Conceals in PNG Files, Targets Data

Related Posts

Police in Brazil Arrest a Suspect Over 0M Banking Hack Police in Brazil Arrest a Suspect Over $100M Banking Hack Security Week News
Critical Flowise Vulnerability Exploit Code Released Critical Flowise Vulnerability Exploit Code Released Security Week News
Critical Flowise Vulnerability Exploit Code Released Three Charged in AI Technology Smuggling to China Security Week News
Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild Security Week News
RSAC 2026 Day 1: Key Cybersecurity Announcements RSAC 2026 Day 1: Key Cybersecurity Announcements Security Week News
Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Memo Allows Private Firms in Cyber Operations
  • White House Enlists Private Firms to Combat Cybercrime
  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Memo Allows Private Firms in Cyber Operations
  • White House Enlists Private Firms to Combat Cybercrime
  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark