China-Linked APT Breached 361 Networks in Five Days via VMware vCenter; CISA Sets August 21 Patch Deadline Under BOD 26-04
A China-nexus APT compromised 361 organizations across 47 countries within five days of a VMware vCenter patch release, while CISA added four critical vulnerabilities to its KEV catalog on August 18 and set an August 21 patch deadline for Federal Civilian Executive Branch agencies. The combined campaigns collapse the historical patch grace period to days rather than weeks.