CiberLATAMbywhalemate

Ransomware Targets VMware vCenter in Latin America

CISA said ransomware is exploiting a critical VMware vCenter flaw, while reports point to victims and active campaigns in Latin America.

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA updated its KEV catalog to say ransomware operators are exploiting CVE-2026-59310 in VMware vCenter, while BleepingComputer reported U.S. federal agencies had three days to secure their systems. Separately, reports surfaced of victims in Brazil and active campaigns against organizations in Latin America.

CISA updated its KEV catalog to say ransomware operators are exploiting CVE-2026-59310 in VMware vCenter, a critical traversal flaw in the Syslog server that Broadcom had patched on July 29. BleepingComputer also reported that the agency ordered U.S. federal agencies to secure their vCenter systems within three days. At the same time, reports pointed to active campaigns in Latin America, victims in Brazil, and a new group with TTPs already seen in the United States, Germany, the United Kingdom, and Canada.

What happened with VMware vCenter?

CISA added CVE-2026-59310 to the KEV catalog because, according to its update, it is being exploited by ransomware operators. The flaw affects VMware vCenter's Syslog server, and Broadcom had patched it on July 29, according to BleepingComputer's coverage.

BleepingComputer's report, based on CISA's notice, also said U.S. federal agencies had to secure their vCenter instances within three days. CyberExperts.com described the vulnerability as a critical directory traversal flaw in the Syslog server, exploitable by an unauthenticated attacker with network access to run arbitrary code.

What was seen in Latin America?

The Hacker News cited Unit 42 on two ongoing intrusion and exfiltration campaigns against organizations in Latin America. According to that coverage, the attackers combined living off the land techniques, iterative batch scripts, resume-themed phishing, custom RATs, and tunneling tools.

Infobae, meanwhile, reported that BlackCat directed part of its attacks in Latin America at critical infrastructure, public agencies, and high-value companies. That adds to the list of exposed sectors in the region and shows the pressure was not limited to a single type of target.

What is known about the new groups and techniques?

Security Arsenal reported that VEXY posted three new victims on its leak site between September 9 and 12, 2026, and that one of them was Logar Network Solutions, a Brazilian technology company. On another front, RST Cloud said Settra was first observed in June 2026 and had targets in the United States, Germany, the United Kingdom, and Canada.

RST Cloud also mentioned TTPs extracted by LLM with T1005, T1486, and T1490. CyPro UK later added that Settra operators used MeshAgent as remote administration software and a BYOVD technique before encryption, adding more technical detail to the group's initial profile.

Taken together, the reports show activity crossing regions and target sets, with an emphasis on technology, critical infrastructure, government, and high-value services, and with techniques ranging from phishing and tunneling to exploitation of VMware vCenter.

Sources

View all