INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

| 2026-08-19 11:01 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability affecting VMware vCenter has been exploited by a suspected China-nexus advanced persistent threat actor to deploy a backdoor and execute reverse_ssh binaries for persistent access. The activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany, the U.S., Turkey, Iran, and France.
Technical Mitigations AI-generated
* Implement a secure patching policy for all vulnerable systems, and ensure that all employees are trained on how to apply patches correctly. * Conduct regular security audits and vulnerability assessments of all networks and systems to identify potential weaknesses before they can be exploited. * Use multi-factor authentication (MFA) whenever possible, and require MFA for all users who access sensitive data or systems. * Keep software and operating systems up-to-date with the latest security patches, and use a reputable antivirus solution to protect against malware.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
DenisDenisBabukBabuk CVE-2026-59309CVE-2026-59309 CVE-2026-55040CVE-2026-55040 CVE-2026-33824CVE-2026-33824 CVE-2026-65400CVE-2026-65400 CVE-2026-59310CVE-2026-59310
Target & Sectors
DACH DACH
Incident Timeline
‎July 29, 2026
The threat actors exploited a vulnerability in macOS, SharePoint, vCenter, and Microsoft IKE.
‎August 1, 2026
Threat actors exploited vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE to gain unauthorized access.
‎as early as August 1, 2026
Threat actors exploited CVE-2026-59309 on vCenter to gain administrative access.
organisation vCenter
vulnerability CVE-2026-59309
‎August 3
Threat actors used CVE-2026-59310 to exploit a vulnerability in macOS and exploited the newly created "vcenter_admin" administrator account on vSphere.
vulnerability CVE-2026-59310
general_metric 59310 abuse
organisation vSphere
organisation GoodMoodle-VCFleet/1.0
‎August 14, 2026
Threat actors exploited a known vulnerability in Microsoft IKE (Internet Key Exchange) to gain unauthorized access to the target's network.
‎Aug 19, 2026
Threat actors used a Microsoft Internet Key Exchange flaw to compromise 361 unique victim IP addresses across 47 countries.
organisation VMware
organisation APT
organisation IP
infrastructure 361 unique victim IP
infrastructure Macos
organisation Apple
organisation PoC
organisation KEV
organisation CVE-2026-59310
organisation CVE-2026-33824
organisation Palo Alto Networks Unit
organisation Microsoft SharePoint
organisation Broadcom VMware
‎2026/08/19
The threat actor exploited a severe directory-traversal vulnerability in VMware vCenter server CVE-2026-59310, using it to execute arbitrary code on compromised systems.
organisation Suspected China-Nexus Actor
organisation APT
organisation Broadcom VMware
organisation VMware
organisation IP
infrastructure 361 unique victim IP
organisation CVE-2026-59310
infrastructure Macos
organisation SharePoint
organisation vCenter
organisation Microsoft
organisation PoC
organisation CVE
infrastructure 9.0
organisation VCF Fleet
organisation Broadcom
organisation VMware Cloud Foundation
organisation VCF
organisation Using vSphere API
organisation JSP
organisation the vSphere SSO Administrators
infrastructure Linux
organisation Update In
organisation GitHub
infrastructure 0.0
organisation VCF Operations
organisation VCF Automation
organisation vSphere Cluster
organisation WebSocket
organisation XOR
organisation SSH
organisation AList
organisation VMware Directory Service
organisation vmdir
organisation Administrators
organisation CROND
organisation The Hacker News
‎August 21, 2026
Threat actors exploited vulnerabilities in macOS, SharePoint, vCenter and Microsoft IKE systems to gain unauthorized access.
general_metric 26 Iran
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
361
Unique Victim Ip
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎0.0
Software Version