IC Technology & Cyber — 2026-08-21
China-Nexus APT Compromises 361 Organizations Across 47 Countries Within Five Days of VMware Patch as CISA Sets Emergency Deadline
BLUFWeaponization of CVE-2026-59310 within five days of disclosure confirms that patch-testing cycles for internet-facing vCenter now lag behind adversary timelines, though cumulative confirmed victims are unlikely to exceed 400 within six weeks given the front-loaded exploitation curve.
German incident response firm QUIRSO reported that a suspected China-nexus APT compromised 361 victim IP addresses across 47 countries within five calendar days of Broadcom's July 29 disclosure of CVE-2026-59310, a maximum-severity directory-traversal flaw in VMware vCenter's Syslog server for which no workaround exists 1. Exploitation began August 3, and QUIRSO recorded 151 additional victims in a single 24-hour window on August 4, with roughly 95 percent of identified victims compromised by August 5 1. Germany, the United States, Turkey, Iran, and France accounted for the largest shares of victim infrastructure, and QUIRSO said the attackers deployed reverse_ssh binaries for persistent access, with at least one intrusion culminating in Babuk-derived ransomware renaming files with the .babyk extension on ESXi hosts 12. CISA added the vCenter flaw along with three other actively exploited vulnerabilities in Apple macOS, Microsoft SharePoint Server, and Windows IKE to its Known Exploited Vulnerabilities catalog on August 18, setting an August 21 patch deadline for federal civilian agencies under Binding Operational Directive 26-04 23.
AnalysisThe five-day window from Broadcom's disclosure to 361 confirmed victims confirms weaponization now outpaces routine patch-testing cycles for internet-facing vCenter infrastructure, forcing organizations to treat the August 21 deadline as a floor rather than a target. Persistence via reverse_ssh and at least one Babuk-derived ransomware deployment indicate operators are retaining access beyond initial compromise, so remediation requires compromise assessment alongside patching. It is
unlikely that a security firm or independent tracker will publicly report the cumulative victim count exceeding 400 within the next six weeks, since QUIRSO's own data shows the campaign's growth curve front-loaded almost entirely into the first three days after exploitation began. Analytic confidence in that judgment is high, reflecting the tight correlation QUIRSO documented between disclosure date and the exploitation spike.
3 sources
- Active exploitation of CVE-2026-59310: 361 victim IPs across 47 countries - QUIRSO GmbH
- China Hackers Breached 361 Networks in 5 Days; CISA Sets 3-Day Patch Window for Enterprise Flaws - TechTimes
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities - SecurityWeek
View in full brief →