Cyber Threat Brief — August 17 2026

⚠️ This report is AI-generated. Always validate findings.

1. China-Nexus APT Chains vCenter Flaws, Deploys Babuk Ransomware — CVE-2026-59310 / CVE-2026-59309

TL;DR: QUIRSO published a full attribution report today linking the CVE-2026-59310 mass exploitation campaign (361 victims, 47 countries) to a suspected China-nexus APT, revealing CVE-2026-59309 auth bypass was chained and Babuk-derived ransomware deployed on ESXi hosts.

What’s New:

  • CVE-2026-59309 (auth bypass) confirmed exploited alongside CVE-2026-59310 (directory traversal RCE) — admin account created from 146.59.252[.]178 as early as August 1
  • China-nexus attribution (moderate confidence) based on Chinese-language script artifacts, UTC+08:00 activity patterns, Chinese-language tooling, and victimology excluding mainland China
  • Full kill chain documented: syslog abuse for cron execution → reverse_ssh persistence → credential harvesting via vmdir → ESXi account creation → Babuk-derived ransomware (.babyk extension)
  • Babuk ransomware may be a smokescreen to encrypt ESXi logs and confuse attribution rather than primary objective

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
146.59.252[.]178IP (CVE-2026-59309 exploitation)T1190vCenter access logs, firewallBlock and hunt
5.34.177[.]38:9861IP:port (backdoor download)T1105Network flow, proxyBlock
185.144.28[.]120:3232IP:port (esxi.sh download)T1105Network flow, proxyBlock
192.255.141[.]13:8080IP:port (executable staging)T1105Network flowBlock
5.34.176[.]100:5244IP:port (reverse_ssh toolset, AList exposed)T1105Network flowBlock
intel.se9ly9upbhay[.]shopDomain (linuxFile C2 via WebSocket :8080/ws)T1071.001DNS, proxyBlock
GoodMoodle-VCFleet/1.0User-Agent string (API recon)T1592vCenter access logsHunt
zz-poc59310-syslog.log under /etc/cron.d/File (cron abuse)T1053.003File integrity, auditdAlert on non-standard files in /etc/cron.d
vmware-perf-update.jspWebshellT1505.003File integrityHunt in vCSA web directories
/etc/sudoers.d/vmware-perf (perfcharts NOPASSWD)PersistenceT1548.003auditd, file integrityAlert on sudoers.d modifications
/tmp/.vmware-perf-upd.shCredential harvesterT1003Process monitoringHunt for vmdir credential extraction
Cron: vmware-vpxd-stats-, vmware-perf-collect-, vmware-perf-sync-*PersistenceT1053.003crontab, auditdHunt impersonating VMware service names
Accounts: vcenter_admin, adminuser, vcadminPersistenceT1136.001vCenter SSO logs, vmdirHunt for unexpected admin accounts
reverse_ssh binary in /tmp/ or /var/tmp/Persistence/C2T1572Process monitoring, file integrityAlert on unknown SSH binaries
.babyk file extension on ESXi datastoresRansomwareT1486ESXi file monitoringIncident response

Detection

SourceRuleGap
Splunk ESCUNone specific to vCenter exploitationNeed vCSA cron abuse detection, vmdir credential extraction, vSphere SSO admin group changes
ElasticNone specificNeed vCenter directory traversal detection, ESXi Babuk ransomware file extension alert
SigmaNone specificNeed vCSA syslog-to-cron file write, reverse_ssh process, vmware-perf-* impersonation cron

Sources: The Hacker News · QUIRSO Medium · BleepingComputer · SecurityWeek


Status Updates

  • GeoServer jsonArrayContains SQLi: SIGNIFICANT — Patches released (3.0.1, 2.28.5, 2.27.6). GHSA-mqjf-5f49-2fjh assigned (CVSS 9.8). Still no CVE. Probing continues. Patch immediately. THN
  • CVE-2026-58231 (SAP Commerce Cloud): Exploitation ongoing since Aug 14. No public PoC. No new artifacts. Original brief
  • CVE-2026-68820 (Windows AFD.sys): Lazarus FudModule v3.1 rootkit. CISA KEV deadline Aug 25. No new IOCs. Original brief
  • CVE-2026-72898 (Metabase): Federal deadline passed Aug 14. ~2,500 exposed instances. Active exploitation ongoing. Original brief
  • CVE-2026-63520 / CVE-2026-55040 (SharePoint): Exploitation escalating per Defused honeypots. Apply both July and Aug CUs. Original brief
  • CVE-2026-50656 (Windows Defender ShieldBreak): Still UNPATCHED. Microsoft acknowledged, no fix timeline. WDAC/AppLocker primary mitigation. Original brief
  • CVE-2026-62878 (Windows DNS Server): Wormable CVSS 9.8. No PoC yet. Patch priority for internet-facing DNS. Original brief
  • CVE-2026-6875: Active exploitation entering ninth week. Fortune 500 and CI victims. Still not on CISA KEV.
  • CVE-2026-18577 (N-able N-central): Storm-1175 StormEncryptor ransomware ongoing. Federal deadline passed Aug 6. No new artifacts.
  • CVE-2026-15409/15410 (SonicWall SMA): INC ransomware via UTA0533 continues. Federal deadline passed Jul 17. No new artifacts.