<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VMware vCenter Exploit Turns Into Babuk Ransomware Attack on ESXi]]></title><description><![CDATA[<p dir="auto">A suspected China-nexus actor reportedly exploited CVE-2026-59310 only 5 days after disclosure, compromising an estimated 361 IPs across 47 countries.</p>
<p dir="auto">The attack chain reportedly went from:</p>
<p dir="auto">vCenter → Root Access → Credential Theft → ESXi → Babuk-derived ransomware</p>
<p dir="auto">The interesting part is how the attackers turned a vCenter compromise into control of the underlying virtualization infrastructure.</p>
<p dir="auto">I broke down the full attack chain, persistence mechanisms, credential harvesting, ESXi lateral movement, and ransomware deployment.</p>
]]></description><link>https://forum.ieu.app/topic/2fd063f9-a97c-4496-825a-aa89b965febd/vmware-vcenter-exploit-turns-into-babuk-ransomware-attack-on-esxi</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 18:16:13 GMT</lastBuildDate><atom:link href="https://forum.ieu.app/topic/2fd063f9-a97c-4496-825a-aa89b965febd.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 17 Aug 2026 08:37:41 GMT</pubDate><ttl>60</ttl></channel></rss>