Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence

1 min read
Source: BleepingComputer
Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence
Photo: BleepingComputer
TL;DR Summary

A critical vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to install the open-source reverse_ssh tool, establishing a persistent outbound C2 channel for remote access. Across 47 countries, 361 victim IPs have been identified, with Germany, the U.S., Turkey, Iran, and France most affected. VMware released an emergency patch; there are no official workarounds. Researchers from QUIRSO suspect an advanced persistent threat behind the campaign and note the attackers' activity began days after the vulnerability disclosure.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

89%

70479 words

Want the full story? Read the original article

Read on BleepingComputer