Critical VMware and Windows Vulnerabilities Exploited in Recent Attacks

Recent cybersecurity incidents have highlighted the exploitation of critical vulnerabilities in VMware products and Microsoft Windows systems, underscoring the persistent threats posed by advanced persistent threat (APT) groups and the importance of timely patching.

VMware vCenter Server Exploited by Suspected Chinese APT

A suspected China-linked APT group has been identified exploiting a severe directory-traversal vulnerability in VMware vCenter Server, designated as CVE-2026-59310 with a CVSS score of 9.8. This flaw allows attackers to execute arbitrary code on affected systems. In at least one instance, the exploitation led to the deployment of a backdoor and a reverse SSH binary, culminating in the installation of Babuk-derived ransomware. However, the ransomware deployment appears to serve as a diversion, potentially hindering forensic analysis and masking the primary objectives of the intrusion.

Windows Zero-Day Vulnerability Targeted by Lazarus Group

The North Korean state-sponsored Lazarus Group has been linked to the exploitation of a newly patched zero-day vulnerability in Microsoft Windows, identified as CVE-2026-68820 with a CVSS score of 7.0. This privilege escalation flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) has been leveraged to deliver novel backdoors, including ForestTiger and Troy, targeting defense and aerospace sectors across France, Germany, Brazil, and India. These attacks are part of the ongoing Operation Dream Job campaign, which uses fake job offers to infiltrate organizations and exfiltrate sensitive data.

These incidents underscore the critical need for organizations to maintain robust patch management practices and remain vigilant against sophisticated cyber threats. The exploitation of high-severity vulnerabilities by APT groups highlights the importance of proactive security measures and the continuous monitoring of systems to detect and mitigate potential intrusions.