# Threat Intel Brief — August 15, 2026
TL;DR
- Critical vulnerabilities under active exploitation: VMware vCenter (CVE-2026-59310), Microsoft SharePoint (CVE-2026-55040), SAP Commerce Cloud (CVE: see source), macOS Screen Sharing (CVE-2026-65400), Cisco Secure Firewall, and Metabase SQL injection—all require immediate patching.
- SonicWall GMS unauthenticated RCE flaws (CVE-2026-66145, CVE-2026-66147) demand urgent remediation; no workarounds available.
- Ransomware and extortion activity: Clop claims Shell breach via PTC exploit; ShinyHunters leaks RingCentral data; Akira uses Safe Mode to evade EDR.
- Supply chain attacks: €30M Commerzbank fraud via service provider flaw; Trezor breach through logistics partner ShipMonk.
- Espionage meets fraud: Jewelbug APT targets government webmail while running parallel cryptocurrency scams.
---
Critical Threats
VMware vCenter RCE Exploited for Persistent Access
What happened: Threat actors are actively exploiting CVE-2026-59310, a critical remote code execution vulnerability in VMware vCenter Syslog Server. The campaign began August 3, five days after patch release, and has compromised systems across 47 countries. Attackers deploy reverse SSH frameworks to establish persistent command-and-control channels.
Impact: VMware vCenter provides centralized management of virtualized infrastructure. Successful exploitation grants unauthenticated remote code execution, enabling attackers to pivot to managed ESXi hosts, virtual machines, and access control systems. The rapid weaponization and suspected APT involvement indicate high risk of data theft, operational disruption, and lateral movement across enterprise environments.
Recommendations: Apply vCenter patches immediately (versions 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f). Hunt for reverse_ssh binaries using published YARA rules. Review Syslog Server logs from August 3 onward for unauthorized access. Isolate unpatched instances from network access until remediation is complete.
---
Microsoft SharePoint Authentication Bypass Exploited in Wild
What happened: CVE-2026-55040, a CVSS 9.1 authentication bypass vulnerability in Microsoft SharePoint, is being actively exploited following public proof-of-concept release on August 11. Attackers forge JWT tokens to impersonate administrators without credentials. Telemetry shows exploitation attempts from multiple countries including Hong Kong, Japan, Netherlands, Taiwan, and the United States.
Impact: Unauthenticated attackers can impersonate SharePoint site administrators, enabling unauthorized file disclosure and data modification. This is the fifth actively exploited SharePoint vulnerability in 2026. Organizations face severe confidentiality and integrity compromise, with attackers able to enumerate domain users and auto-locate administrative accounts.
Recommendations: Apply Microsoft July 2026 Patch Tuesday updates immediately. Audit SharePoint access logs for suspicious JWT authentication and anomalous user impersonation since July 19. Monitor network traffic for connections from known malicious IPs. Review administrator accounts for unauthorized privilege escalation. Implement network segmentation to restrict SharePoint exposure.
---
SAP Commerce Cloud Maximum-Severity RCE Under Attack
What happened: A CVSS 10.0 critical remote code execution vulnerability in SAP Commerce Cloud (CVE: see source) is being actively exploited as of August 14, just three days after patch release. The flaw affects the Data Hub Adapter extension and allows unauthenticated, low-complexity attacks. No public proof-of-concept is available yet, but honeypot telemetry confirms active targeting.
Impact: Complete compromise of Commerce Cloud instances used by major retailers and global brands. Successful exploitation enables arbitrary code execution with high impact on confidentiality, integrity, and availability. The 72-hour exploitation window indicates organized threat actor interest. Organizations running unpatched SAP Commerce Cloud face immediate risk of full application compromise.
Recommendations: Apply SAP Security Note 3771065 immediately, prioritizing internet-facing deployments. Audit authentication configurations in Data Hub Adapter and disable unused default authentication clients. Monitor web application logs for suspicious POST requests targeting Commerce Cloud endpoints. Conduct threat hunting for indicators of compromise from August 11 onward. Implement network segmentation to isolate Commerce Cloud instances.
---
SonicWall GMS Unauthenticated RCE Vulnerabilities
What happened: Multiple critical vulnerabilities in SonicWall Global Management System enable unauthenticated remote code execution. CVE-2026-66145 and CVE-2026-66147 allow attackers to gain complete control of GMS instances without credentials. Exploitation status is unknown, but the unauthenticated RCE nature suggests high likelihood of imminent targeting.
Impact: GMS is a centralized management platform for SonicWall firewalls, making compromise a potential pivot point to managed security infrastructure. Organizations face immediate risk of full system compromise, lateral movement to managed devices, and potential network-wide breach. No workarounds are available.
Recommendations: Identify all SonicWall GMS instances and verify current versions immediately. Apply vendor patches as soon as released. Restrict network access to GMS management interfaces via firewall rules. Monitor GMS logs for suspicious authentication attempts and unusual outbound connections. If patching cannot be completed within 24 hours, temporarily isolate GMS instances from internet access.
---
macOS Screen Sharing Authentication Bypass Exploited for Cryptomining
What happened: CVE-2026-65400, an authentication bypass in macOS Screen Sharing, is being actively exploited to deploy Monero cryptocurrency miners. The Netherlands NCSC confirmed exploitation with public exploit code available. Attackers gain root access on systems with TCP port 5900 exposed to the internet.
Impact: Remote attackers can access macOS systems without authentication, execute applications, access files, modify security settings, and gain root privileges. While current attacks focus on cryptomining, full system compromise enables data theft, lateral movement, and persistent access. Organizations with macOS endpoints exposing Screen Sharing to the internet face immediate risk.
Recommendations: Update all macOS systems to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 immediately. Scan network perimeter for systems exposing TCP port 5900 and block external access. Disable Screen Sharing where not required. Hunt for Monero miner indicators including unusual CPU usage and connections to mining pools. Review VNC authentication logs for suspicious access attempts.
---
Threat Actor Activity
Clop Ransomware Exploits PTC Windchill in Mass Campaign
Clop ransomware gang claims to have stolen 89GB of data from Shell as part of a broader campaign exploiting CVE-2026-12569 in PTC Windchill and FlexPLM platforms. The operation compromised 43 organizations across aerospace, defense, automotive, and energy sectors, including General Electric and Philips. Attackers deployed JSP webshells for persistence and exfiltrated sensitive engineering data including blueprints, facility testing reports, and project plans. The campaign began after PTC's June 17 patch release, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a three-day remediation deadline.
Defensive priority: Patch CVE-2026-12569 immediately. Hunt for JSP webshells in PLM platform webroot directories. Implement network segmentation to isolate engineering systems from direct internet exposure.
---
ShinyHunters Extorts RingCentral, Leaks 1.6M Account Records
ShinyHunters extortion group breached RingCentral in July, stealing personal information from 1.6 million accounts. The group exfiltrated 623GB of compressed data through a social engineering campaign targeting RingCentral personnel. When ransom demands were refused, ShinyHunters published the stolen data via their dark web leak site. The group has conducted multiple high-profile campaigns over the past year, including breaches at Salesforce customers, Snowflake customers, and over 100 organizations via Oracle PeopleSoft exploitation.
Defensive priority: Implement phishing-resistant multi-factor authentication. Monitor for anomalous data exfiltration patterns using DLP solutions. Conduct security assessments of third-party integrations with Salesforce, Snowflake, and Oracle platforms.
---
Akira Ransomware Uses Safe Mode to Evade EDR
Akira ransomware affiliates successfully disabled endpoint detection and response solutions by restarting systems into Safe Mode with Networking. The attack began via an exposed SonicWall VPN without MFA, followed by RDP lateral movement and data exfiltration to S3 buckets using WinRAR and s5cmd. While the group successfully stole data within five hours, they ultimately failed to encrypt the victim's systems. This represents the first documented case of Akira using Safe Mode boot manipulation, a technique previously associated with Snatch and AvosLocker ransomware families.
Defensive priority: Enforce MFA on all VPN and remote access solutions. Monitor for Safe Mode boot configuration changes via registry modifications. Deploy behavioral monitoring for data staging tools and AWS CLI usage to external S3 buckets.
---
Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraud
Jewelbug (also tracked as Earth Alux and REF7707), a China-based threat actor, is conducting parallel espionage and financially-motivated operations. The group compromised webmail accounts for 15 government tenants in a Middle Eastern country by injecting malicious JavaScript into shared hosting platforms. Simultaneously, Jewelbug operates industrial-scale cryptocurrency fraud using AI-generated content, fake exchange sites impersonating OKX and Binance, and a 44-server content-management fleet. The actor's infrastructure reveals over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated email bodies.
Defensive priority: Monitor for unauthorized modifications to shared web-hosting platforms and webmail templates. Implement browser extension allowlisting. Detect malicious HTA file execution and fake software installer activity.
---
Geopolitical Context
European Cybersecurity Coordination Intensifies
Belgium's CERT issued multiple urgent advisories this week, reflecting heightened threat activity targeting European infrastructure. Warnings cover Plesk privilege escalation, Cisco Secure Firewall denial-of-service exploitation, Metabase SQL injection, and SonicWall GMS vulnerabilities. Belgium's role as host to EU and NATO headquarters amplifies the strategic sensitivity of network security vulnerabilities within its jurisdiction. The advisories align with broader EU efforts to enhance collective cyber resilience under the NIS2 Directive and ENISA coordination mechanisms.
---
Cross-Border Financial Cybercrime Enforcement
Four cybercriminals were arrested in Brazil and three charged in Europe for exploiting a service provider vulnerability to conduct €30M in bank fraud against Commerzbank customers. The case demonstrates growing operational coordination between law enforcement agencies in Latin America and Europe, aligning with Interpol and Europol frameworks for combating transnational cybercrime. The incident underscores persistent supply chain risk in the banking sector and may accelerate bilateral information-sharing agreements between European and Latin American financial regulators.
---
Recommended Actions
Immediate (0-24 hours)
- Patch critical vulnerabilities: VMware vCenter (CVE-2026-59310), Microsoft SharePoint (CVE-2026-55040), SAP Commerce Cloud, macOS Screen Sharing (CVE-2026-65400), SonicWall GMS (CVE-2026-66145, CVE-2026-66147).
- Hunt for active exploitation: Search for reverse_ssh binaries on vCenter systems, JSP webshells on PTC Windchill/FlexPLM, and Monero miner processes on macOS endpoints.
- Block internet exposure: Restrict access to TCP port 5900 (macOS Screen Sharing), SonicWall GMS management interfaces, and unpatched vCenter instances.
- Review access logs: Audit SharePoint JWT authentication, vCenter Syslog Server access, and SAP Commerce Cloud endpoints for suspicious activity since early August.
Within 24-72 hours
- Apply Microsoft August 2026 Patch Tuesday updates to remediate CVE-2026-62832 (LegacyHive Windows zero-day) on all Windows 10 (2004+) and Windows Server 2022+ systems.
- Patch Cisco Secure Firewall, Metabase, and Plesk per vendor advisories; prioritize internet-facing and critical perimeter appliances.
- Enforce MFA on all VPN and remote access solutions, particularly SonicWall and similar perimeter devices.
- Conduct threat hunting for Safe Mode boot configuration changes, data exfiltration to S3 buckets, and browser extension anomalies.
This week
- Audit third-party integrations: Review security posture of service providers with access to financial systems, PLM platforms, and customer data.
- Implement network segmentation: Isolate PLM systems, SharePoint instances, and Commerce Cloud deployments from direct internet exposure.
- Deploy behavioral analytics: Monitor for credential abuse, anomalous data access patterns, and bulk data queries against engineering repositories.
- Review incident response procedures for extortion scenarios, including pre-determined communication strategies for ransom demands and data leak threats.
---
Watch List
- PTC Windchill/FlexPLM exploitation: Monitor for additional Clop victims and secondary exploitation by other ransomware groups.
- Windows zero-days: Track related vulnerabilities from the same researcher (ShieldBreak, BlueHammer, RedSun, UnDefend) that remain unpatched and may be chained with LegacyHive.
- Supply chain breaches: Trezor disclosed a breach affecting nearly 14,000 customers through logistics provider ShipMonk; expect additional third-party compromise disclosures.
- Cryptocurrency fraud infrastructure: Jewelbug's 44-server content-management fleet hosting fake exchange sites may expand targeting beyond current victims.
---
Sources
- BleepingComputer: VMware vCenter RCE, SharePoint exploitation, SAP Commerce Cloud, macOS Screen Sharing, Clop/Shell, RingCentral breach, Akira Safe Mode, Jewelbug APT, LegacyHive zero-day, Commerzbank fraud, Trezor breach
- CERT.BE (Belgium): SonicWall GMS, Plesk privilege escalation, Cisco Secure Firewall DoS, Metabase SQL injection
- The Hacker News: SharePoint CVE-2026-55040 exploitation telemetry
