A suspected China-nexus actor reportedly exploited CVE-2026-59310 only 5 days after disclosure, compromising an estimated 361 IPs across 47 countries.
The attack chain reportedly went from:
vCenter → Root Access → Credential Theft → ESXi → Babuk-derived ransomware
The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.
I broke down the full attack chain, persistence mechanisms, credential harvesting, ESXi lateral movement, and ransomware deployment.
