Skip to main content
Emerging ThreatsMalware & Ransomware

China APT Exploits VMware Flaw in Targeted Attacks

Server room interior with technicians in background and highlighted server components.

"Based on the case we investigated, however, we do not believe ransomware was necessarily the primary objective," QUIRSO said.

VMware vCenter: CVE-2026-59310 and a likely China-nexus APT

Security teams this week tracked active exploitation of CVE-2026-59310, a directory‑traversal vulnerability in VMware vCenter server assigned a CVSS score of 9.8. The exploits, attributed to a suspected China‑nexus advanced persistent threat, allowed attackers to execute arbitrary code. In at least one compromised instance investigators observed the deployment of a backdoor and a reverse SSH binary, followed by the appearance of Babuk‑derived ransomware. QUIRSO assessed that the ransomware looked "more like a smoke screen intended to distract from the underlying intrusion and, importantly, hinder subsequent forensic analysis by encrypting evidence."

Lazarus Group, CVE-2026-68820, and Operation Dream Job

The North Korean threat actor known as Lazarus Group was attributed to zero‑day exploitation of CVE-2026-68820 (CVSS 7.0), a privilege escalation flaw in Windows Ancillary Function Driver for WinSock (AFD.sys) patched by Microsoft in August 2026. The activity—part of the long‑running Operation Dream Job social engineering campaign—delivered ForestTiger and a newly observed backdoor named Troy against defense and aerospace companies in France, Germany, Brazil, and India. The reporting describes the campaign as using convincing fake job offers to steal data and install malware.

Browser hijacks and the Chrome DevTools Protocol

Two separate lines of research this week show authenticated browser sessions and remote browser control are increasingly powerful post‑compromise tools. Jamf detailed Amnesia Stealer, a macOS stealer family distributed via ClickFix attacks that can copy a victim's Chromium profile (including authentication state) and load it into a headless browser on the infected host. Its streaming module uses the Chrome DevTools Protocol (CDP) to create a WebSocket channel to an operator relay and send live commands. Jamf described the remote_stream command as turning "an infected host into a live, operator‑driven browser running the victim's authenticated sessions."

SpecterOps separately outlined how a post‑exploit technique can enable CDP inside a live Chrome or Edge process on Windows, allowing an operator with code execution to sidestep cookie protections and access authenticated applications and saved data. SpecterOps warned that "Cookie protections like ABE and device‑bound session cookies make it harder to steal and replay session material, but they do not remove the value of an authenticated browser to adversaries."

Supply‑chain, exposed services and commodity opportunism

The week also underscored repeat patterns: attackers exploiting exposed services and third‑party trust. SOCRadar's analysis of the LiteLLM supply‑chain incident found that 95% of organizations impacted were already exposed, tied to a Trivy scanner compromise and attributed to a threat actor dubbed TeamPCP. A separate Azure exfiltration campaign driven by an actor called "TheHatman" reportedly downloaded enterprise employee databases directly from Azure/Entra portals using compromised credentials; Hudson Rock said the leak hit large enterprises including McDonald's, TCS, Vodafone, HCL Technologies, Kyndryl, Gap, Hexaware, and Wyndham Hotels.

GeoServer released emergency patches for a critical SQL‑injection flaw after watchTowr reported active exploitation within hours of public disclosure, with hundreds of attempts from a small pool of IP addresses. And BitSight observed a 55% drop in internet‑exposed Automatic Tank Gauge systems in the U.S. from March to June, a reminder that exposure changes can be rapid when defenders act.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: Prioritize patching high‑severity, actively exploited CVEs (for example CVE-2026-59310 and CVE-2026-68820) and audit internet‑exposed services—many incidents began with public ports or misconfigurations rather than exotic zero days.
  • Affected enterprises and procurement leaders: Supply‑chain exposure spread through commonly used tools (Trivy, LiteLLM frameworks) and misconfigured portals; procurement and vendor risk evaluations should include how quickly a vendor can detect and remediate a compromise that cascades through widely deployed tooling.
  • End users and general public: Browser session theft and malware like Amnesia Stealer illustrate that login state can be converted into long‑lasting access; treating authenticated browser profiles as high‑risk artifacts and protecting endpoints from code‑execution vectors matters.

Two final, concrete takeaways emerge from the week’s reporting. First, exploitation now mixes high‑end zero‑days with low‑effort gains derived from exposed services and misconfigurations; defenders must address both. Second, tools and protocols designed for convenience—CDP, developer scanners, developer memories—are being repurposed by attackers who stitch small, benign‑looking elements into a capable intrusion. As the newsletter concluded: patch what matters, close what should not be public, and keep an eye on the boring stuff. The boring stuff is, increasingly, the thing that wins.

Source: The Hacker News — Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More