
Suspected Chinese Hackers Turn VMware vCenter RCE Into Root Backdoors and ESXi Ransomware
A suspected Chinese-speaking threat actor has exploited a critical VMware vCenter Server vulnerability to gain root-level access, establish several backdoors, steal directory credentials, and deploy Babuk-derived ransomware on ESXi hypervisors. The campaign targeted CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter’s Syslog Server that can allow remote code execution. Broadcom assigned the bug a CVSS […]
The post Suspected Chinese Hackers Turn VMware vCenter RCE Into Root Backdoors and ESXi Ransomware appeared first on Cyber Security News.