A suspected China-nexus actor reportedly exploited CVE-2026-59310 only 5 days after disclosure, compromising an estimated 361 IPs across 47 countries.

The attack chain reportedly went from:

vCenter → Root Access → Credential Theft → ESXi → Babuk-derived ransomware

The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.

I broke down the full attack chain, persistence mechanisms, credential harvesting, ESXi lateral movement, and ransomware deployment.