{"id":242827,"date":"2026-08-18T01:23:40","date_gmt":"2026-08-18T06:23:40","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/suspected-chinanexus-actor-exploits-vmware-vcenter-flaw-deploys-babukderived-ransomware"},"modified":"2026-08-18T01:23:40","modified_gmt":"2026-08-18T06:23:40","slug":"suspected-chinanexus-actor-exploits-vmware-vcenter-flaw-deploys-babukderived-ransomware","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/suspected-chinanexus-actor-exploits-vmware-vcenter-flaw-deploys-babukderived-ransomware","title":{"rendered":"Suspected ChinaNexus Actor Exploits VMware vCenter Flaw, Deploys BabukDerived Ransomware"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/suspected-chinanexus-actor-exploits-vmware-vcenter-flaw-deploys-babukderived-ransomware.jpg\"><\/a><\/p>\n<p>Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).<\/p>\n<p>The attacks involve the exploitation of <a href=\"https:\/\/thehackernews.com\/2026\/07\/three-critical-vmware-flaws-allow-auth.html\" target=\"_blank\">CVE-2026\u201359310<\/a> (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. A fix for the flaw was released by Broadcom on July 29, 2026.<\/p>\n<p>German incident response company QUIRSO assessed with moderate confidence that the exploitation campaign aimed at CVE-2026\u201359310 is operated by a Chinese-speaking threat actor, likely working in the UTC+08:00 time zone, which is predominantly used in Chinese-speaking regions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026\u201359310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-242827","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242827"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242827\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}