Security1 distinct publisher3 min readUpdated
QUIRSO says a suspected China-nexus actor turned CVE-2026-59310 into a backdoor, a reverse SSH binary and Babuk-derived ransomware, with 361 victim IPs across 47 countries.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Broadcom released a fix for CVE-2026-59310 on July 29, 2026, and German incident response firm QUIRSO has since documented the flaw being chained on live vCenter appliances into a backdoor, a reverse SSH binary and Babuk-derived ransomware [1][2]. QUIRSO estimates the campaign has already compromised 361 unique victim IP addresses across 47 countries, which moves an unpatched, reachable vCenter out of the patch queue and into incident response [3].
The vulnerability itself is a directory traversal in vCenter Server carrying a CVSS score of 9.8 that can be used to execute arbitrary code [1]. QUIRSO says exploitation began five calendar days after public disclosure [4]. Infections are concentrated in Germany (55), the United States (41), Turkey (38), Iran (26) and France (25) [5]; those five countries account for roughly 51 percent of the observed victim IPs [6]. QUIRSO assesses with moderate confidence that the campaign is run by a Chinese-speaking actor likely working in the UTC+08:00 time zone [7], citing Chinese-language artifacts in attacker scripts, apparent reuse of research from a Chinese security publication, Chinese-language tooling, victimology that excludes mainland China, and working-hours patterns [8].
The mechanics matter more than the attribution, because they are what defenders can search for. On the appliance QUIRSO analyzed, the first sign was the cron daemon logging a malformed cron file named "zz-poc59310-syslog.log", followed by a curl or wget command that pulled a backdoor from 5.34.177.38:9861, ran it, and deleted the log file [9]. QUIRSO reads the filename as a direct reference to the CVE and evidence of a proof-of-concept built after the details went public [10]. The suffix mimics vCSA remote syslog naming, but the file landed in /etc/cron.d rather than the configured syslog output directory, which QUIRSO says indicates the appliance's syslog server was abused to write into a privileged execution location; at least one such file executed and dropped the "linuxFile" backdoor [11]. That implant takes commands over a WebSocket channel, runs them through /bin/sh and returns output [12]. According to QUIRSO's Denis Szadkowski, its command-and-control address is XOR-obfuscated and decoded at runtime, traffic is protected by the malware's own application-layer cryptography over an unencrypted ws:// transport, and it reconnects automatically and carries persistence routines [13].
The same appliance was also hit by CVE-2026-59309, an authentication bypass that has drawn active scanning, with activity consistent with exploitation as early as August 1, 2026 [14]. That path produced a new administrative account, "vcenter_admin", created from 146.59.252.178, with no login events recorded for the legitimate administrative account credited with creating it [15]. On August 3 the same activity performed vSphere discovery via the REST API using User-Agent strings such as "GoodMoodle-VCFleet/1.0", which QUIRSO reads as an attempt to look like VMware traffic [16]; VCF Fleet is a genuine Broadcom management capability introduced in VMware Cloud Foundation 9.0 [17]. QUIRSO found no overlap between that intrusion and the CVE-2026-59310 chain that began on the same system on August 3, and says the new account was not used in later phases [18]. If disclosure coincided with the July 29 fix, five days later is August 3 [19].
QUIRSO does not think the ransomware was the point: it describes the deployment as looking more like a smoke screen to distract from the underlying intrusion and to hinder forensics by encrypting evidence [20].
Worth watching: whether the CVE-2026-59309 scanning converts into exploitation at the scale seen for 59310 [14], and whether victim counts move past 361 IPs [3]. Worth checking now: files in /etc/cron.d on vCenter appliances, outbound ws:// sessions, privileged account creation with no preceding login for the creating account [15], and VCF-flavored user agents on REST API calls you did not initiate [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CVE-2026-59310 is a directory-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8 that could be weaponized to execute arbitrary code; Broadcom released a fix on July 29, 2026.
QUIRSO, a German incident response company, assessed with moderate confidence that the CVE-2026-59310 exploitation campaign is operated by a Chinese-speaking threat actor likely working in the UTC+08:00 time zone, predominantly used in Chinese-speaking regions.
QUIRSO researchers said the assessment rests on Chinese-language artifacts in attacker-created scripts, apparent reuse of research from a Chinese security publication, repeated operational use of Chinese-language tools and management software, victimology excluding mainland China, and activity patterns compatible with UTC+08:00 working hours.
In at least one compromised instance, exploitation of CVE-2026-59310 led to deployment of a backdoor and a reverse SSH binary, ultimately leading to the deployment of Babuk-derived ransomware.
The activity is estimated to have compromised 361 unique victim IP addresses across 47 countries.
The exploitation activity commenced five calendar days after public disclosure of the flaw.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor incident-response forensics, reported by one outlet
The technical record is unusually specific for a fresh exploitation story: named QUIRSO researchers, a reconstructed kill chain, file and cron artifact names, C2 hosts and ports, implant internals confirmed by direct email quote, and per-country victim counts. But every claim traces to one incident-response firm relayed through one publisher (two duplicate copies of the same article plus its weekly recap). There is no Broadcom advisory text, no second vendor's telemetry and no CERT confirmation in the supplied material, and the attribution is explicitly moderate confidence.
Real-world exploitation at scale within days of the patch
Read as in-the-wild uptake of the exploit rather than product adoption: a patch on July 29, exploitation starting five days later, 361 unique victim IPs across 47 countries, a second vCenter CVE under active scanning and exploited on the same appliance, and ransomware actually deployed in at least one case. The main constraints are that victim counts are estimated, are IP-based rather than organization-based, and come from a single firm's visibility.
Slightly overstated: nation-state framing outruns moderate-confidence evidence
The substance is well matched to the evidence — patch date, exploitation timeline, artifacts and ransomware outcome are all concretely reported, and the publisher preserves QUIRSO's hedges. The overshoot is in framing: 'China-nexus APT' headlines a moderate-confidence, indicator-convergence assessment; 361 victim IPs is presented as an estimate but reads as a census; and the ransomware and smoke-screen narrative rests on a single investigated case. Nothing here is inflated by much, but the certainty implied by the framing exceeds what one vendor's caveated telemetry can carry.
Commercial IR-firm research amplified by a single security outlet
The sole primary source is QUIRSO, a commercial German incident response company publishing attribution research and supplying an on-the-record email quote — visibility-building activity that typically favours confident, named-adversary framing. The publisher's incentive is speed and threat-of-the-week salience, evidenced by the same article being republished and then recapped. Offsetting factors: the research names its analysts, states its confidence level, publishes falsifiable indicators, and no product or service pitch appears in the supplied text.
Moderate: technically credible, structurally single-sourced
Confidence is held down by source structure rather than by weak reporting. The mechanism, indicators and timeline are internally consistent and specific enough to be verified by defenders, and the derived arithmetic (five days to August 3; 185 of 361 victims in five countries) checks out. But one vendor, one publisher, no Broadcom or government confirmation, an estimated victim count and a self-declared moderate-confidence attribution mean the actor identity and campaign scale should be treated as provisional even where the intrusion mechanics look solid.
build
Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite1 distinct publisher
invest
One Anthropic order, six times the price: Fractile's $6.5B mark arrives two years before its chips3 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
product
Marvell's $12.2bn warrant pays Google in Marvell stock, one $500m order at a time2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
3 articles · August 17, 2026