Cyber Threat Brief — August 17 2026
⚠️ This report is AI-generated. Always validate findings.
1. China-Nexus APT Chains vCenter Flaws, Deploys Babuk Ransomware — CVE-2026-59310 / CVE-2026-59309
TL;DR: QUIRSO published a full attribution report today linking the CVE-2026-59310 mass exploitation campaign (361 victims, 47 countries) to a suspected China-nexus APT, revealing CVE-2026-59309 auth bypass was chained and Babuk-derived ransomware deployed on ESXi hosts.
What’s New:
- CVE-2026-59309 (auth bypass) confirmed exploited alongside CVE-2026-59310 (directory traversal RCE) — admin account created from 146.59.252[.]178 as early as August 1
- China-nexus attribution (moderate confidence) based on Chinese-language script artifacts, UTC+08:00 activity patterns, Chinese-language tooling, and victimology excluding mainland China
- Full kill chain documented: syslog abuse for cron execution → reverse_ssh persistence → credential harvesting via vmdir → ESXi account creation → Babuk-derived ransomware (.babyk extension)
- Babuk ransomware may be a smokescreen to encrypt ESXi logs and confuse attribution rather than primary objective
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| 146.59.252[.]178 | IP (CVE-2026-59309 exploitation) | T1190 | vCenter access logs, firewall | Block and hunt |
| 5.34.177[.]38:9861 | IP:port (backdoor download) | T1105 | Network flow, proxy | Block |
| 185.144.28[.]120:3232 | IP:port (esxi.sh download) | T1105 | Network flow, proxy | Block |
| 192.255.141[.]13:8080 | IP:port (executable staging) | T1105 | Network flow | Block |
| 5.34.176[.]100:5244 | IP:port (reverse_ssh toolset, AList exposed) | T1105 | Network flow | Block |
| intel.se9ly9upbhay[.]shop | Domain (linuxFile C2 via WebSocket :8080/ws) | T1071.001 | DNS, proxy | Block |
| GoodMoodle-VCFleet/1.0 | User-Agent string (API recon) | T1592 | vCenter access logs | Hunt |
| zz-poc59310-syslog.log under /etc/cron.d/ | File (cron abuse) | T1053.003 | File integrity, auditd | Alert on non-standard files in /etc/cron.d |
| vmware-perf-update.jsp | Webshell | T1505.003 | File integrity | Hunt in vCSA web directories |
| /etc/sudoers.d/vmware-perf (perfcharts NOPASSWD) | Persistence | T1548.003 | auditd, file integrity | Alert on sudoers.d modifications |
| /tmp/.vmware-perf-upd.sh | Credential harvester | T1003 | Process monitoring | Hunt for vmdir credential extraction |
| Cron: vmware-vpxd-stats-, vmware-perf-collect-, vmware-perf-sync-* | Persistence | T1053.003 | crontab, auditd | Hunt impersonating VMware service names |
| Accounts: vcenter_admin, adminuser, vcadmin | Persistence | T1136.001 | vCenter SSO logs, vmdir | Hunt for unexpected admin accounts |
| reverse_ssh binary in /tmp/ or /var/tmp/ | Persistence/C2 | T1572 | Process monitoring, file integrity | Alert on unknown SSH binaries |
| .babyk file extension on ESXi datastores | Ransomware | T1486 | ESXi file monitoring | Incident response |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None specific to vCenter exploitation | Need vCSA cron abuse detection, vmdir credential extraction, vSphere SSO admin group changes |
| Elastic | None specific | Need vCenter directory traversal detection, ESXi Babuk ransomware file extension alert |
| Sigma | None specific | Need vCSA syslog-to-cron file write, reverse_ssh process, vmware-perf-* impersonation cron |
Sources: The Hacker News · QUIRSO Medium · BleepingComputer · SecurityWeek
Status Updates
- GeoServer jsonArrayContains SQLi: SIGNIFICANT — Patches released (3.0.1, 2.28.5, 2.27.6). GHSA-mqjf-5f49-2fjh assigned (CVSS 9.8). Still no CVE. Probing continues. Patch immediately. THN
- CVE-2026-58231 (SAP Commerce Cloud): Exploitation ongoing since Aug 14. No public PoC. No new artifacts. Original brief
- CVE-2026-68820 (Windows AFD.sys): Lazarus FudModule v3.1 rootkit. CISA KEV deadline Aug 25. No new IOCs. Original brief
- CVE-2026-72898 (Metabase): Federal deadline passed Aug 14. ~2,500 exposed instances. Active exploitation ongoing. Original brief
- CVE-2026-63520 / CVE-2026-55040 (SharePoint): Exploitation escalating per Defused honeypots. Apply both July and Aug CUs. Original brief
- CVE-2026-50656 (Windows Defender ShieldBreak): Still UNPATCHED. Microsoft acknowledged, no fix timeline. WDAC/AppLocker primary mitigation. Original brief
- CVE-2026-62878 (Windows DNS Server): Wormable CVSS 9.8. No PoC yet. Patch priority for internet-facing DNS. Original brief
- CVE-2026-6875: Active exploitation entering ninth week. Fortune 500 and CI victims. Still not on CISA KEV.
- CVE-2026-18577 (N-able N-central): Storm-1175 StormEncryptor ransomware ongoing. Federal deadline passed Aug 6. No new artifacts.
- CVE-2026-15409/15410 (SonicWall SMA): INC ransomware via UTA0533 continues. Federal deadline passed Jul 17. No new artifacts.