hacker-news · Crawled Aug 12, 2026

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

2 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain reverse_ssh Details →
Filename reverse_ssh Details →

MITRE ATT&CK TTPs 7 techniques