INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
| 2026-08-19 11:01 CRITICAL HIGHExecutive Summary AI-generated
The vulnerability affecting VMware vCenter has been exploited by a suspected China-nexus advanced persistent threat actor to deploy a backdoor and execute reverse_ssh binaries for persistent access. The activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany, the U.S., Turkey, Iran, and France.
Technical Mitigations AI-generated
* Implement a secure patching policy for all vulnerable systems, and ensure that all employees are trained on how to apply patches correctly.
* Conduct regular security audits and vulnerability assessments of all networks and systems to identify potential weaknesses before they can be exploited.
* Use multi-factor authentication (MFA) whenever possible, and require MFA for all users who access sensitive data or systems.
* Keep software and operating systems up-to-date with the latest security patches, and use a reputable antivirus solution to protect against malware.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
DenisDenisBabukBabuk
CVE-2026-59309CVE-2026-59309
CVE-2026-55040CVE-2026-55040
CVE-2026-33824CVE-2026-33824
CVE-2026-65400CVE-2026-65400
CVE-2026-59310CVE-2026-59310
Target & Sectors
DACH
DACH
Incident Timeline
July 29, 2026
The threat actors exploited a vulnerability in macOS, SharePoint, vCenter, and Microsoft IKE.
August 1, 2026
Threat actors exploited vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE to gain unauthorized access.
as early as August 1, 2026
Threat actors exploited CVE-2026-59309 on vCenter to gain administrative access.
Click on any entity below to view its context and source!
organisation
vCenter
Evidence shows malicious activity consistent with the exploitation of CVE-2026-59309 as early as August 1, 2026, followed by the creation of an administrative account on vCenter.
vulnerability
CVE-2026-59309
Evidence shows malicious activity consistent with the exploitation of CVE-2026-59309 as early as August 1, 2026, followed by the creation of an administrative account on vCenter.
August 3
Threat actors used CVE-2026-59310 to exploit a vulnerability in macOS and exploited the newly created "vcenter_admin" administrator account on vSphere.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-59310
QUIRSO said there is no overlap between this activity and the chain of events involving the abuse of CVE-2026-59310 on the same system starting August 3, adding the newly created "vcenter_admin" administrator account was not used in subsequent phases of the attack.
general_metric
59310 abuse
QUIRSO said there is no overlap between this activity and the chain of events involving the abuse of CVE-2026-59310 on the same system starting August 3, adding the newly created "vcenter_admin" administrator account was not used in subsequent phases of the attack.
organisation
vSphere
The account creation originated from the IP address 146.59.252[.]178 and also involved vSphere discovery via the REST API on August 3 using User-Agent strings like "GoodMoodle-VCFleet/1.0," in an attempt to masquerade it as VMware-related activity.
organisation
GoodMoodle-VCFleet/1.0
The account creation originated from the IP address 146.59.252[.]178 and also involved vSphere discovery via the REST API on August 3 using User-Agent strings like "GoodMoodle-VCFleet/1.0," in an attempt to masquerade it as VMware-related activity.
August 14, 2026
Threat actors exploited a known vulnerability in Microsoft IKE (Internet Key Exchange) to gain unauthorized access to the target's network.
Aug 19, 2026
Threat actors used a Microsoft Internet Key Exchange flaw to compromise 361 unique victim IP addresses across 47 countries.
Click on any entity below to view its context and source!
organisation
VMware
The vulnerability affecting VMware vCenter is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor to deploy a backdoor along with reverse_ssh binaries for persistent access to compromised instances.
organisation
APT
The vulnerability affecting VMware vCenter is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor to deploy a backdoor along with reverse_ssh binaries for persistent access to compromised instances.
organisation
IP
In all, the activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
infrastructure
361 unique victim IP
In all, the activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
infrastructure
Macos
An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
While the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner, the SharePoint vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code.
organisation
Apple
An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
organisation
PoC
While the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner, the SharePoint vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code.
organisation
KEV
The shortcomings added to the KEV catalog are listed below -
CVE-2026-65400
(CVSS score: 9.8) -
organisation
CVE-2026-59310
CVE-2026-59310
(CVSS score: 9.8) -
organisation
CVE-2026-33824
CVE-2026-33824
(CVSS score: 9.8) -
organisation
Palo Alto Networks Unit
CVE-2026-33824, per Palo Alto Networks Unit 42, has been observed being exploited by another Chinese-speaking threat actor, who is said to have simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek and conducted manual operations using known vulnerabilities, including the Microsoft Internet Key Exchange flaw.
organisation
Microsoft SharePoint
A weak authentication vulnerability impacting Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network.
organisation
Broadcom VMware
A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code.
2026/08/19
The threat actor exploited a severe directory-traversal vulnerability in VMware vCenter server CVE-2026-59310, using it to execute arbitrary code on compromised systems.
Click on any entity below to view its context and source!
organisation
Suspected China-Nexus Actor
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware.
organisation
APT
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).
organisation
Broadcom VMware
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).
organisation
VMware
The attacks involve the exploitation of
CVE-2026-59310
(CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code.
organisation
IP
The activity, which commenced five calendar days after public disclosure of the flaw, is estimated to have
compromised 361 unique victim IP addresses
across 47 countries, with most of the infections scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
infrastructure
361 unique victim IP
The activity, which commenced five calendar days after public disclosure of the flaw, is estimated to have
compromised 361 unique victim IP addresses
across 47 countries, with most of the infections scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
organisation
CVE-2026-59310
German incident response company QUIRSO assessed with moderate confidence that the exploitation campaign aimed at CVE-2026-59310 is operated by a Chinese-speaking threat actor, likely working in the UTC+08:00 time zone, which is predominantly used in Chinese-speaking regions.
infrastructure
Macos
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation.
organisation
SharePoint
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation.
organisation
vCenter
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation.
organisation
Microsoft
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation.
organisation
PoC
The naming convention of the log file is significant as it is a direct reference to the CVE identifier and that it was a proof-of-concept (PoC) devised after details of the flaw became public knowledge.
organisation
CVE
The naming convention of the log file is significant as it is a direct reference to the CVE identifier and that it was a proof-of-concept (PoC) devised after details of the flaw became public knowledge.
infrastructure
9.0
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
organisation
VCF Fleet
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
organisation
Broadcom
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
organisation
VMware Cloud Foundation
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
organisation
VCF
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
organisation
Using vSphere API
Using vSphere API to perform discovery operations and "esxi.sh" to deploy the reverse_ssh client.
organisation
JSP
Setting three cronjobs impersonating legitimate VMware services: vmware-vpxd-stats-* (facilitates an SSH-based remote access channel by adding the attacker's SSH public key to the authorized keys file), vmware-perf-collect-* (drops a JSP web shell named "vmware-perf-update.jsp"), and vmware-perf-sync-* (drops the same web shell and runs a Base64-encoded script that performs credential access and sets up a new account called "adminuser," which is then added to the vSphere SSO Administrators group.
organisation
the vSphere SSO Administrators
Setting three cronjobs impersonating legitimate VMware services: vmware-vpxd-stats-* (facilitates an SSH-based remote access channel by adding the attacker's SSH public key to the authorized keys file), vmware-perf-collect-* (drops a JSP web shell named "vmware-perf-update.jsp"), and vmware-perf-sync-* (drops the same web shell and runs a Base64-encoded script that performs credential access and sets up a new account called "adminuser," which is then added to the vSphere SSO Administrators group.
infrastructure
Linux
"
Update
In a follow-up analysis, QUIRSO
said
it identified a GitHub repository ("
pikpak0066/tmpclean
") linked to the same threat actor that, at first blush, appears to be a Go-based program to automatically remove old files from Linux temporary directories.
It carries the description "Automatic /tmp cleaner daemon for Linux (Go).
"
Present in the repository is a Linux systemd service that scans the "/tmp" directory and deletes from it any entries, such as files, symlinks, sockets, and others, whose modification time is at least 24 hours old, and repeats it every hour.
organisation
Update
In
"
Update
In a follow-up analysis, QUIRSO
said
it identified a GitHub repository ("
pikpak0066/tmpclean
") linked to the same threat actor that, at first blush, appears to be a Go-based program to automatically remove old files from Linux temporary directories.
organisation
GitHub
"
Update
In a follow-up analysis, QUIRSO
said
it identified a GitHub repository ("
pikpak0066/tmpclean
") linked to the same threat actor that, at first blush, appears to be a Go-based program to automatically remove old files from Linux temporary directories.
infrastructure
0.0
What's more, a release version named "tmpclean v3.0.0" has been found to include updated "reverse_ssh" binaries, suggesting an attempt to distribute additional compiled payloads through the GitHub-based vector.
organisation
VCF Operations
It encompasses multiple components, including VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains.
organisation
VCF Automation
It encompasses multiple components, including VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains.
organisation
vSphere Cluster
It encompasses multiple components, including VCF Operations, VCF Automation, vCenter, NSX Manager, vSphere Cluster, and workload domains.
organisation
WebSocket
It establishes a connection to its controller over a WebSocket channel to receive instructions, executes them through /bin/sh, and transmits the results back to the attacker.
organisation
XOR
"The C2 [command-and-control] address is XOR-obfuscated and decoded at run-time, while communications are protected using the malware's own application-layer cryptography despite using an unencrypted ws:// transport," Szadkowski told The Hacker News via email.
organisation
SSH
The shell script then serves as a downloader and persistence installer for an architecture-specific reverse SSH ("reverse_ssh") binary that's retrieved from the same infrastructure.
organisation
AList
In what appears to be an operational security blunder, the latter has been found to expose the reverse SSH binaries toolset via an AList directory listing.
organisation
VMware Directory Service
Creating two additional accounts: adding "vcadmin" to vSphere with a Base64-encoded Python script dropped on disk via bash commands run in a cronjob and creating a vSphere admin account via an external LDAP "Add" operation against vCenter's VMware Directory Service (vmdir) from a remote client by using a pre-existing but compromised administrative account.
organisation
vmdir
Creating two additional accounts: adding "vcadmin" to vSphere with a Base64-encoded Python script dropped on disk via bash commands run in a cronjob and creating a vSphere admin account via an external LDAP "Add" operation against vCenter's VMware Directory Service (vmdir) from a remote client by using a pre-existing but compromised administrative account.
organisation
Administrators
The stolen credentials are used to conduct privileged directory modifications, including adding the aforementioned "adminuser" identity to the Administrators group.
organisation
CROND
"Subsequent commands recorded by CROND were therefore already being executed as root, giving the actor unrestricted access to the underlying VCSA without first having to compromise an unprivileged local account and escalate from it.
organisation
The Hacker News
"
"We initially discovered the GitHub repository because we observed the attacker setting it up through the link command of the existing reverse_ssh infrastructure we were monitoring," Szadkowski told The Hacker News.
August 21, 2026
Threat actors exploited vulnerabilities in macOS, SharePoint, vCenter and Microsoft IKE systems to gain unauthorized access.
Click on any entity below to view its context and source!
general_metric
26 Iran
Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.
Tactical Metrics
Metrics
infrastructure
361
Unique Victim Ip
Click for context!
In all, the activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
The activity, which commenced five calendar days after public disclosure of the flaw, is estimated to have
compromised 361 unique victim IP addresses
across 47 countries, with most of the infections scattered across Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
Metrics
infrastructure
Macos
Affected Product
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation.
An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
While the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner, the SharePoint vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code.
Metrics
infrastructure
9.0
Software Version
It's worth noting that VCF Fleet is a centralized management capability introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 to deploy, scale, patch, and operate multiple VCF instances.
Metrics
infrastructure
Linux
Affected Product
"
Update
In a follow-up analysis, QUIRSO
said
it identified a GitHub repository ("
pikpak0066/tmpclean
") linked to the same threat actor that, at first blush, appears to be a Go-based program to automatically remove old files from Linux temporary directories.
It carries the description "Automatic /tmp cleaner daemon for Linux (Go).
"
Present in the repository is a Linux systemd service that scans the "/tmp" directory and deletes from it any entries, such as files, symlinks, sockets, and others, whose modification time is at least 24 hours old, and repeats it every hour.
Metrics
infrastructure
0.0
Software Version
What's more, a release version named "tmpclean v3.0.0" has been found to include updated "reverse_ssh" binaries, suggesting an attempt to distribute additional compiled payloads through the GitHub-based vector.
Intelligence Sources
The Hacker News
2026-08-17
The Hacker News
2026-08-19
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-20T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
39x
organisation
Identified Entity
VMware
entity
7x
timeline
Temporal Reference
Aug 19, 2026
date
6x
attribution
Attributing Entity
Vulnerability / Ransomware
authority
5x
vulnerability
Exploited CVE
CVE-2026-65400
cve
4x
target region
Target Country
Germany
country
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
malware
Malware Payload
Babuk
tool
2x
infrastructure
Affected Product
Macos
software
2x
general metric
Aug
19
aug
2x
infrastructure
Software Version
9.0
version
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Country
China
country
infrastructure
Unique Victim Ip
361
unique victim ip
general metric
Countries
47
countries
general metric
Germany
55
germany
general metric
U.S.
41
u.s.
general metric
Turkey
38
turkey
general metric
Iran
26
iran
general metric
France
25
france
tactic
Cyber Operation Type
Ransomware
tactic
general metric
Score
10
score
general metric
Version
9
version
general metric
Abuse
59,310
abuse
general metric
Hours
24
hours
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.