# Threat Intel Brief — August 16, 2026

TL;DR

  • Critical RCE vulnerabilities in SonicWall GMS (CVE-2026-66145, CVE-2026-66147) and SAP Commerce Cloud (CVE-2026-58231) require immediate patching; SAP flaw already exploited within 72 hours of patch release.
  • Active exploitation of macOS Screen Sharing authentication bypass (CVE-2026-65400) deploying Monero cryptominers on internet-exposed systems; public exploit code available.
  • Clop ransomware gang claims theft of data from Shell and 42 other organizations via PTC Windchill zero-day; ShinyHunters breached RingCentral, exposing 1.6 million accounts.
  • Evooo1Bot botnet targeting Linux gateway devices to establish SOCKS5 proxy infrastructure for malicious traffic relay operations.
  • Law enforcement action: Seven arrests across Brazil and Europe for €30M Commerzbank fraud; former Brightly Software contractor sentenced to two years for $2.5M extortion scheme.

Critical Threats

SonicWall GMS Unauthenticated RCE Vulnerabilities

What happened
CERT.BE issued an urgent advisory for multiple critical vulnerabilities in SonicWall Global Management System, including CVE-2026-66145 and CVE-2026-66147, which enable unauthenticated remote code execution. No exploitation has been publicly confirmed, but the severity and nature of these flaws make them high-priority targets for both ransomware operators and state-sponsored actors.

Impact
Attackers can gain complete control of SonicWall GMS platforms without authentication, providing access to managed firewall configurations, VPN credentials, network topology data, and pivot points into entire managed infrastructures. Organizations using GMS for centralized firewall management face total compromise risk affecting all managed security appliances and protected networks.

Recommendations

  • Immediately isolate all SonicWall GMS instances from internet access and restrict management access to authorized networks only
  • Apply vendor patches as soon as available via MySonicWall portal; monitor security bulletins continuously
  • Review GMS access logs for suspicious authentication attempts or administrative activity predating patch application
  • Implement network segmentation and IP allowlisting at the firewall level as compensating controls until patching is complete
  • Conduct threat hunting for indicators of compromise on GMS platforms and downstream managed devices

SAP Commerce Cloud Maximum-Severity RCE Under Active Exploitation

What happened
A CVSS 10.0 remote code execution vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter extension was patched on August 11, 2026. Threat intelligence firm Defused confirmed active exploitation beginning August 14—just three days post-patch. Attackers are targeting internet-exposed instances with unauthenticated RCE attempts observed against honeypots.

Impact
Successful exploitation grants attackers complete system compromise with no authentication required. SAP Commerce Cloud is deployed by major global retailers and e-commerce platforms handling sensitive customer transaction data and intellectual property. The Shadowserver Foundation tracks over 4,200 internet-exposed instances, primarily in Europe and North America. The rapid weaponization timeline indicates sophisticated threat actors with advance knowledge or rapid reverse-engineering capabilities.

Recommendations

  • Apply SAP Security Note 3771065 immediately to all Commerce Cloud instances, prioritizing internet-facing production systems
  • Audit network logs for unauthorized Data Hub Adapter access attempts, focusing on authentication client abuse patterns
  • Verify default authentication clients are disabled or properly restricted per SAP hardening guidance
  • Conduct emergency asset inventory including development and test environments to confirm comprehensive patch coverage
  • Monitor for unusual process execution, outbound connections, or lateral movement from Commerce Cloud servers as compromise indicators

macOS Screen Sharing Authentication Bypass Exploited for Cryptomining

What happened
The Netherlands NCSC warned of active exploitation of CVE-2026-65400, an authentication bypass vulnerability in macOS Screen Sharing (VNC protocol, TCP port 5900). Attackers are deploying Monero cryptocurrency miners after gaining root access to systems with internet-exposed Screen Sharing. Public exploit code is available, lowering the barrier to widespread exploitation.

Impact
Network-based attackers bypass authentication on macOS Screen Sharing to gain unauthorized access without credentials. Confirmed attacks achieve root-level access, enabling full system compromise including arbitrary application execution, file access, security setting modification, and resource-draining cryptominer deployment. Organizations with macOS endpoints exposing port 5900 to the internet or untrusted networks face immediate risk.

Recommendations

  • Update all macOS systems to patched versions: Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 immediately
  • Block TCP port 5900 from internet access on all macOS endpoints via firewall rules and network ACLs
  • Disable Screen Sharing on systems where not operationally required via System Settings → General → Sharing
  • Hunt for compromise indicators: unauthorized root access, unexpected processes, high CPU usage, xmrig binaries, and outbound connections to mining pools
  • Review VNC/Screen Sharing access logs for authentication anomalies or connections from unexpected source IPs

Threat Actor Activity

Clop Ransomware Gang Exploits PTC Windchill Zero-Day

The Clop ransomware gang exploited CVE-2026-12569, a critical vulnerability in internet-exposed PTC Windchill and FlexPLM instances, to breach 43 organizations across aerospace, defense, automotive, heavy machinery, retail, and medical technology sectors. High-profile victims include Shell (investigating claims of 89GB data theft), General Electric, and Philips. Attackers deployed JSP webshells for persistence and exfiltrated sensitive intellectual property including engineering drawings, facility testing reports, project plans, blueprints, and system files. The campaign demonstrates Clop's established pattern of mass exploitation targeting enterprise management platforms for data extortion. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 26, 2026, following German BSI emergency warnings.

Defensive priority: Organizations using PTC Windchill or FlexPLM must immediately apply patches, hunt for JSP webshells, isolate PLM systems from direct internet exposure, and monitor for anomalous data exfiltration patterns.

ShinyHunters Breaches RingCentral via Social Engineering

The ShinyHunters extortion group breached RingCentral in July 2026 through social engineering, stealing personal information from 1.6 million accounts including names, email addresses, phone numbers, and physical addresses. The group exfiltrated 623GB of compressed data and disclosed the breach via Have I Been Pwned. This incident continues ShinyHunters' year-long campaign targeting cloud platform providers including Salesforce (1.5 billion records stolen via Salesloft Drift and Salesforce Aura), Snowflake customers, and over 100 organizations via an Oracle PeopleSoft zero-day. The group operates a "pay or leak" extortion model, publishing stolen data on dark web leak sites when ransom demands are refused.

Defensive priority: Implement phishing-resistant multi-factor authentication (FIDO2/WebAuthn), monitor for anomalous data exfiltration patterns, enforce conditional access policies with behavioral analytics, and establish dark web monitoring for organizational data leaks.

Insider Threat: Former Brightly Software Contractor Sentenced

Cameron Curry, a former data analyst contractor for Brightly Software, was sentenced to two years in prison for stealing sensitive payroll and corporate data and conducting a $2.5 million extortion scheme. Curry leveraged legitimate access obtained during his six-month contract to exfiltrate employee PII, payroll records, and corporate financial information. After learning his contract would not be extended, he demanded cryptocurrency payment under threat of public disclosure and SEC reporting, using the alias "Loot" and email lootsoftware@outlook.com. Brightly paid $7,540 in Bitcoin before FBI intervention led to Curry's arrest on January 24, 2024, conviction in March 2026, and sentencing in August 2026.

Defensive priority: Implement robust offboarding procedures with immediate credential revocation, deploy DLP solutions with behavioral analytics for contractor activity, and establish cryptocurrency transaction monitoring with immediate law enforcement notification protocols for extortion demands.

Geopolitical Context

Transatlantic Law Enforcement Cooperation Against Financial Cybercrime

Four cybercriminals were arrested in Brazil and three charged in Europe for exploiting a service provider vulnerability to conduct €30 million in bank fraud against Commerzbank customers. The coordinated action demonstrates growing transatlantic cooperation against financially motivated cybercrime, likely facilitated through Europol channels. The incident underscores systemic third-party risk in European banking infrastructure and may accelerate regulatory pressure under the Digital Operational Resilience Act (DORA) framework. Successful prosecution could establish a model for future joint operations targeting cybercriminal infrastructure in jurisdictions outside traditional Five Eyes or EU frameworks.

European Supply Chain Security Concerns

Belgian CERT advisories on SonicWall GMS and Plesk vulnerabilities reflect heightened European awareness of enterprise IT supply-chain exposure, consistent with EU cybersecurity policy priorities under NIS2 and the Cyber Resilience Act. The SonicWall vulnerabilities pose acute risk to NATO member states and EU institutions where these products maintain significant market presence. Delayed remediation in mid-sized enterprises and under-resourced public sector organizations may create persistent attack surfaces exploitable by both ransomware operators and state-sponsored actors.

Recommended Actions

Immediate (0-24 hours)

  • Patch CVE-2026-66145 and CVE-2026-66147 in all SonicWall GMS instances; isolate from internet access until patched
  • Apply SAP Security Note 3771065 to all Commerce Cloud instances; prioritize internet-facing deployments
  • Update all macOS systems to patched versions addressing CVE-2026-65400; block TCP port 5900 from internet access
  • Audit PTC Windchill and FlexPLM instances for compromise indicators; apply patches for CVE-2026-12569 if not already completed
  • Inventory all internet-facing Linux gateway devices for signs of Evooo1Bot botnet compromise

Within 24-72 hours

  • Conduct threat hunting for JSP webshells on PTC platforms and Monero miner artifacts on macOS endpoints
  • Review access logs for SonicWall GMS, SAP Commerce Cloud, and RingCentral for authentication anomalies
  • Implement network segmentation to isolate PLM systems, GMS platforms, and critical SaaS integrations
  • Deploy behavioral analytics for cloud platform credential abuse and data exfiltration patterns
  • Verify contractor and temporary employee offboarding procedures include immediate credential revocation

This week

  • Apply Plesk patches addressing privilege escalation vulnerability (CVE: see source)
  • Conduct security assessments of all third-party service providers with access to banking and financial infrastructure
  • Review firewall rules and network exposure for all management interfaces and remote access services
  • Implement DLP policies targeting sensitive PII fields and establish dark web monitoring for organizational data leaks
  • Update incident response playbooks for supply chain compromise scenarios and extortion demands

Watch List

  • SonicWall GMS exploitation: Monitor for proof-of-concept code publication and active exploitation indicators; expect rapid weaponization if PoC emerges
  • SAP Commerce Cloud: Track additional exploitation reports and potential victim notifications as attackers target unpatched instances
  • Clop PTC Windchill campaign: Additional victim disclosures likely as organizations complete forensic investigations
  • Evooo1Bot botnet expansion: Monitor for increased scanning activity targeting Linux gateway devices and SOCKS5 proxy behavior on compromised systems
  • ShinyHunters activity: Watch for additional cloud platform breaches following established targeting pattern of SaaS providers and integration ecosystems

Sources

  • BleepingComputer: New Evooo1Bot Linux botnet turns routers into traffic relay nodes
  • BleepingComputer: Hackers arrested over €30M bank fraud exploiting service provider flaw
  • BleepingComputer: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
  • BleepingComputer: Max severity SAP Commerce Cloud flaw now targeted in attacks
  • BleepingComputer: Shell investigates 'potential incident' after Clop data theft claims
  • BleepingComputer: RingCentral data breach exposed info of 1.6 million accounts
  • BleepingComputer: Data analyst sent to prison for stealing data, extorting employer
  • CERT.BE: Warning on SonicWall Global Management System vulnerabilities (CVE-2026-66145, CVE-2026-66147)
  • CERT.BE: Warning on Plesk privilege escalation vulnerability