Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
VMware vCenter Vulnerability Exploited by Hackers

VMware vCenter Vulnerability Exploited by Hackers

Posted on August 13, 2026 By CWS

Cyber attackers have begun leveraging a critical vulnerability in VMware vCenter, as reported by the cybersecurity firm Quirso. This flaw, identified as CVE-2026-59310, was initially addressed by Broadcom on July 29, alongside other security issues in various VMware products.

Details of the Vulnerability

The vulnerability, with a CVSS score of 9.8, is a directory traversal bug in the Syslog server that could be exploited for remote code execution. According to Broadcom, attackers with network access to vCenter can potentially execute arbitrary code by exploiting this flaw.

Quirso observed that an advanced persistent threat (APT) group is actively targeting web-accessible VMware vCenter servers that remain susceptible to CVE-2026-59310. The attackers utilize a reverse shell to gain persistent access to these systems.

Global Impact and Exploitation

Quirso’s analysis revealed that more than 360 victim IP addresses, spanning 47 countries, have been compromised. Notably, half of these IPs are concentrated in Germany, the United States, Turkey, Iran, and France. However, the cybersecurity firm notes that IP addresses might not directly map to specific organizations since they often represent shared infrastructure or cloud networks.

The exploitation campaign began shortly after the vulnerability was disclosed, with over 340 IP addresses engaging with the attackers’ infrastructure by August 5. Quirso suggests that the public disclosure of the vulnerability likely triggered the campaign’s initiation.

Mitigation and Recommendations

Post-compromise, attackers have been deploying the open-source SSH reverse shell framework, reverse_ssh, to maintain communication with infected systems. This tactic helps them circumvent security measures that typically block inbound connections.

To aid in identifying these attacks, Quirso released a generic YARA rule designed to detect reverse_ssh builds. Organizations with exposed vCenter systems are advised to verify any detections by checking for unauthorized installations and unexpected outbound connections or activity.

The ongoing situation underscores the critical need for organizations to promptly apply security patches and monitor their systems for any signs of compromise to mitigate the risks associated with such vulnerabilities.

Security Week News Tags:APT, Broadcom, CVE-2026-59310, Cybersecurity, Quirso, remote code execution, reverse shell, Security, vCenter, VMware, Vulnerability, YARA rule

Post navigation

Previous Post: Akira Ransomware Exploits Safe Mode to Bypass Security
Next Post: Phantom Stealer Conceals in PNG Files, Targets Data

Related Posts

Nullify Gains .5M to Enhance AI Cybersecurity Solutions Nullify Gains $12.5M to Enhance AI Cybersecurity Solutions Security Week News
Trustifi Raises  Million for AI-Powered Email Security Trustifi Raises $25 Million for AI-Powered Email Security Security Week News
Dragos Expands with NetRise and runZero Acquisitions Dragos Expands with NetRise and runZero Acquisitions Security Week News
Chipmaker Patch Tuesday: Many Vulnerabilities Addressed by Intel, AMD, Nvidia Chipmaker Patch Tuesday: Many Vulnerabilities Addressed by Intel, AMD, Nvidia Security Week News
New Malware ClickLock Stealer Exploits macOS Vulnerabilities New Malware ClickLock Stealer Exploits macOS Vulnerabilities Security Week News
Booking.com Alerts Users to Data Breach Risk Booking.com Alerts Users to Data Breach Risk Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark