hacker-news · Crawled Aug 12, 2026
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
2 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 7 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1053.003 Cron · Execution T1059.001 PowerShell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1190 Exploit Public-Facing Application · Initial Access