CARDS
CARDS
BleepingComputer reports that QUIRSO observed exploitation of VMware vCenter CVE-2026-59310 beginning August 3, 2026. By August 7, QUIRSO reportedly identified 361 compromised IP addresses across 47 countries and deployment of reverse_ssh for outbound persistent access. Broadcom confirms the critical unauthenticated RCE but has not publicly confirmed these campaign details; CISA had not added the CVE to KEV as of August 16.
Last updated Aug 16, 2026, 4:00 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Campaign Chronology
29 Jul 2026
VMSA-2026-0006 identifies the critical vCenter Syslog RCE and no workaround.[1]
3 Aug 2026
7 Aug 2026
QUIRSO reportedly observes reverse_ssh deployment and international spread.[2]
13 Aug 2026
BleepingComputer publishes the QUIRSO findings; Broadcom confirmation remains absent.[2]
16 Aug 2026
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
A compromised IP count is not an organization count. No named victim, reliable actor identity, ransomware link, or public complete IOC set is retained. Internet exposure is not required if another foothold can reach the management network, and internal placement alone does not prove isolation.
Evidence Controls
IntelliOS
Citations