# Threat Intel Brief — August 18, 2026

TL;DR

  • Critical vulnerabilities under active exploitation: SAP Commerce Cloud (CVE-2026-58231, CVSS 10.0) and Adobe Commerce are being targeted within days of patch release; immediate patching required.
  • China-nexus APT exploits VMware vCenter: CVE-2026-59310 weaponized in five days, compromising 361 systems across 47 countries with Babuk ransomware deployment.
  • Enterprise infrastructure at risk: GitLab GraphQL flaw (CVE-2026-19478, CVSS 9.4) enables unauthenticated project deletion; Active Directory Certificate Services vulnerability (CVE-2026-54121) allows domain takeover from standard user accounts.
  • Iranian APT evolves tradecraft: Cavern C2 framework now abuses Google Apps Script and DNS tunneling to target Israeli government and defense entities.
  • Major data breaches: French tax authority (678,000 records), Azure account claims (3.6 million records), and third-party logistics compromises affecting Pokémon Center and other retailers.

Critical Threats

SAP Commerce Cloud Zero-Day Exploitation (CVE-2026-58231)

What happened: A critical vulnerability in SAP Commerce Cloud (CVSS 10.0) is experiencing active exploitation attempts just three days after patch release on August 11, 2026. The flaw involves insufficient authorization checks and input validation, allowing unauthenticated attackers to abuse default authentication clients and execute arbitrary code remotely.

Impact: Complete compromise of SAP Commerce Cloud instances is possible, with attackers achieving full control over confidentiality, integrity, and availability. The rapid exploitation timeline (72 hours post-patch) demonstrates attacker capability and intent. Organizations running SAP Commerce Cloud face immediate risk of data exfiltration, system compromise, and potential ransomware deployment. Historical SAP vulnerabilities have been exploited by China-nexus APTs and ransomware groups including BianLian and RansomExx.

Recommendations:

  • Immediately patch SAP Commerce Cloud to fixed release levels per SAP security note and rebuild/redeploy updated versions.
  • As temporary mitigation, configure IP Filter Set to restrict access to vulnerable endpoints until patching is complete.
  • Review access logs from August 11 onward for suspicious authentication attempts or anomalous traffic to default authentication clients.
  • Monitor network traffic for unauthenticated requests to authentication endpoints with unusual payloads.

China-Nexus APT Exploits VMware vCenter (CVE-2026-59310)

What happened: A suspected China-nexus threat actor weaponized CVE-2026-59310, a critical directory-traversal vulnerability (CVSS 9.8) in Broadcom VMware vCenter Server, within five days of public disclosure on July 29, 2026. The campaign compromised an estimated 361 unique systems across 47 countries, deploying custom backdoors and Babuk-derived ransomware.

Impact: The attack enables arbitrary code execution on vCenter appliances, providing centralized access to entire virtualized infrastructure environments. The threat actor deployed custom "linuxFile" backdoor with WebSocket-based C2, JSP web shells, and persistence mechanisms via systemd services and cron jobs. Geographic targeting concentrated in Germany (55 victims), United States (41), Turkey (38), Iran (26), and France (25), with mainland China notably excluded—consistent with state-sponsored intelligence collection operations.

Recommendations:

  • Immediately patch CVE-2026-59310 and CVE-2026-59309 in all VMware vCenter Server deployments; Broadcom released fixes July 29, 2026.
  • Hunt for suspicious cron jobs in /etc/cron.d/, particularly files with patterns like 'zz-poc*' or impersonating VMware services.
  • Inspect vCenter for unauthorized administrator accounts (e.g., 'vcenter_admin') and review authentication logs.
  • Block or alert on WebSocket connections from vCenter appliances to external infrastructure.
  • Monitor for connections to known malicious infrastructure: 146.59.252[.]178, 5.34.177[.]38, 185.144.28[.]120, 192.255.141[.]13, 5.34.176[.]100, intel.se9ly9upbhay.shop.

GitLab GraphQL Vulnerability Enables Unauthenticated Project Deletion (CVE-2026-19478)

What happened: GitLab released emergency security updates to address a critical GraphQL directive vulnerability (CVSS 9.4) affecting self-managed Community Edition and Enterprise Edition installations. The flaw allows unauthenticated attackers to remotely modify or delete public projects and user data.

Impact: Self-managed GitLab instances hosting public repositories face data loss and integrity compromise. The vulnerability is exploitable over the network with no credentials or user interaction required. GitLab.com and GitLab Dedicated are already patched. Technical details will be disclosed mid-November 2026 per GitLab's 90-day policy, limiting current defensive visibility.

Recommendations:

  • Immediately upgrade self-managed GitLab to patched versions: 19.2.4, 19.1.6, 19.0.8, or 18.11.11.
  • Prioritize instances hosting public projects as primary attack surface.
  • Review GitLab access logs and GraphQL query logs for anomalous unauthenticated requests targeting public projects.
  • Monitor GitLab's issue tracker in mid-November for technical details and adjust detection rules accordingly.

Active Directory Certificate Authority Privilege Escalation (CVE-2026-54121)

What happened: The "Certighost" vulnerability allows a standard domain user to escalate privileges and effectively turn an Enterprise Certificate Authority into a Domain Controller. Public proof-of-concept was published July 24, 2026, demonstrating full attack chain from standard user to domain admin via forged DC certificate and DCSync attacks.

Impact: Complete domain compromise is achievable from standard user accounts. Attackers exploit AD CS "chase" functionality to obtain fraudulent Domain Controller certificates, then use PKINIT/Kerberos to extract krbtgt hash via DCSync, enabling Golden Ticket attacks. The vulnerability leverages default AD configuration (MachineAccountQuota) and implicit trust between CA and domain—no ACL modification required. Microsoft patched July 14, 2026, but public PoC availability significantly increases exploitation risk.

Recommendations:

  • Apply Microsoft security update released July 14, 2026 to all Enterprise Certificate Authority servers immediately.
  • Set MachineAccountQuota to 0 in Active Directory to prevent standard users from creating machine accounts.
  • Audit AD CS certificate template permissions; restrict templates allowing machine or DC authentication to privileged accounts only.
  • Enable enhanced logging for AD CS enrollment events (Event IDs 4886, 4887, 4888) and monitor for unusual certificate issuance patterns.
  • Treat Enterprise CA as Tier 0 asset with network isolation and privileged access management controls equivalent to Domain Controllers.

Threat Actor Activity

Iranian APT Evolves Cavern C2 Framework

Iranian nation-state actors affiliated with the Ministry of Intelligence and Security (MOIS), operating as Cavern Manticore with overlaps to MuddyWater and OilRig/APT34, have evolved their Cavern command-and-control framework with new evasion capabilities. Kaspersky researchers discovered the framework now abuses Google Apps Script as a relay mechanism and employs DNS tunneling for C2 channel selection, disguising malicious traffic as legitimate cloud service communications.

The framework targets Israeli government, defense, and critical infrastructure entities with a modular, plugin-based architecture operational since late April 2026. Key capabilities include abuse of Microsoft 365 calendar events as covert dead-drops (with events dated to 2050 to avoid detection), HTTPS-based C2 with dynamic channel switching, and post-exploitation modules for Active Directory reconnaissance, LDAP brute-force attacks, and SOCKS5 proxy tunneling.

Infrastructure includes expired and re-registered domains (studiotikva[.]com, originally registered February 2024, expired February 2026, re-registered May 2026) and compromised legitimate infrastructure in target regions. The continuous framework evolution since December 2025 indicates sustained intelligence collection requirements against Israeli targets.

Clop Ransomware Gang Targets Enterprise PLM Platforms

The Clop ransomware and extortion gang is exploiting CVE-2026-12569, a critical vulnerability in PTC Windchill and PTC FlexPLM product lifecycle management platforms, to conduct mass data theft campaigns. General Electric, Philips, and Shell are investigating claims of breaches, with 43 total organizations listed on Clop's leak site from this campaign wave.

The attack chain involves exploiting Internet-exposed PTC instances, deploying JSP webshells for persistence, and conducting extensive data exfiltration targeting backups, project plans, facility photos, drawings, diagrams, and blueprints. Targeting focuses on aerospace, defense, automotive, heavy machinery, retail, and medtech sectors—industries handling highly sensitive intellectual property.

This campaign follows Clop's established pattern of mass-exploitation targeting enterprise software vulnerabilities, including previous campaigns against Accellion FTA, GoAnywhere MFT, MOVEit Transfer (affecting over 2,770 organizations), and Oracle EBS. PTC began releasing patches June 17, 2026, and CISA added the vulnerability to its KEV catalog.

Microsoft Defender Zero-Day Under Development

Security researcher Nightmare Eclipse disclosed ShieldBreak (CVE-2026-69414), a privilege escalation vulnerability in Microsoft Defender that enables local attackers with limited permissions to gain SYSTEM privileges. The vulnerability bypasses the previously patched RoguePlanet flaw (CVE-2026-50656) and affects all fully patched Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025 systems.

A public proof-of-concept exploit is available with 100% reported success rate. Microsoft is developing a patch but has not provided a release timeline. The disclosure is part of an ongoing dispute between the researcher and Microsoft over vulnerability handling practices, with multiple zero-day vulnerabilities disclosed since April 2026.

Geopolitical Context

European Government Infrastructure Under Pressure

France's General Directorate of Public Finances (DGFiP) disclosed a data breach affecting 678,000 individuals, with attackers stealing tax and cadastral data including reference tax income, family quotients, and property records. The threat actor "ZeroBytes" is publicly selling the stolen data on criminal forums. This represents the latest in a sustained pattern of attacks targeting French government infrastructure throughout 2026, including breaches at France Travail (43 million records), FICOBA (1.2 million accounts), and ANTS (19 million records).

The repeated compromises raise concerns about the security posture of EU member state digital government services, particularly as the bloc advances digitalization under the Digital Decade policy framework. The incidents may accelerate implementation of NIS2 Directive requirements and increase scrutiny of public sector cybersecurity investments across European capitals.

Supply Chain Vulnerabilities in Logistics Sector

CEVA Logistics, a subsidiary of the world's third-largest shipping conglomerate CMA CGM Group, suffered a data breach affecting Pokémon Center customers in the United Kingdom and Germany. The compromise occurred between July 29 and August 1, 2026, disrupting eight European warehouses and affecting multiple retailers including Valve's Steam hardware operations. The incident highlights systemic vulnerabilities in globalized supply chain networks where third-party logistics providers serve as critical nodes connecting consumer platforms with distribution infrastructure.

The breach's geographic concentration in UK and Germany may trigger regulatory scrutiny under GDPR and NIS2 frameworks, with potential enforcement proceedings if inadequate security controls or delayed breach notification are identified. The incident demonstrates how single points of failure in logistics networks can cascade across consumer brands, potentially eroding trust in cross-border e-commerce.

Recommended Actions

Immediate (0-24 hours)

  • Patch SAP Commerce Cloud (CVE-2026-58231): Apply vendor updates immediately; configure IP filtering as temporary mitigation if patching requires extended downtime.
  • Patch VMware vCenter (CVE-2026-59310, CVE-2026-59309): Update all instances and conduct forensic investigation for indicators of compromise from July 29 onward.
  • Patch GitLab self-managed instances (CVE-2026-19478): Upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11; prioritize instances with public repositories.
  • Patch Active Directory Certificate Services (CVE-2026-54121): Apply July 14, 2026 Microsoft update; set MachineAccountQuota to 0.
  • Patch Adobe Commerce: Apply vendor security updates per CERT.BE warning of active exploitation.
  • Monitor Microsoft Defender: Watch for unusual privilege escalation attempts involving MsMpEng.exe and related processes pending CVE-2026-69414 patch.

Within 24-72 hours

  • Patch Forminator WordPress plugin (CVE-2026-15748): Update to version 1.56.2 or later; audit forms with File Upload and Select fields.
  • Hunt for Evooo1Bot botnet: Patch 18 exploited CVEs in edge devices; block outbound connections to 91.92.40[.]118; audit for SOCKS5 proxy listeners.
  • Investigate AmnesiaStealer on macOS: Block execution of shell scripts from untrusted sources; monitor for Chrome DevTools Protocol WebSocket connections.
  • Review Azure account security: Audit Azure AD logs for suspicious authentication patterns following claims of 3.6 million account record theft.
  • Assess PTC Windchill/FlexPLM exposure: Review access logs for JSP webshell indicators if running PTC platforms; patch CVE-2026-12569.

This week

  • Patch Ivanti EPM: Check Ivanti security advisories for specific patch releases addressing high severity flaws.
  • Patch IBM i systems: Review IBM Security Bulletins for critical vulnerability details and apply vendor-provided patches.
  • Review Unisoc device inventory: Identify devices using T606, T612, and T7250 chipsets; monitor vendor bulletins for firmware updates addressing CWE-1189 privilege escalation.
  • Audit GitHub Actions workflows: Review for direct expansion of untrusted input in run: blocks; refactor to use intermediate environment variables.
  • Assess Threema service availability: Verify message delivery if using cloud-hosted Threema; review business continuity plans for encrypted communications.
  • Implement Cavern C2 detection: Monitor for anomalous DNS A-record queries, unusual Microsoft 365 calendar usage (events dated to 2050), and Google Apps Script API abuse.

Watch List

  • Microsoft Defender ShieldBreak patch: Monitor MSRC advisories for CVE-2026-69414 release timeline given public PoC availability.
  • GitLab technical disclosure: Watch for mid-November 2026 technical details on CVE-2026-19478 to adjust detection rules.
  • Unisoc modem vulnerability: Monitor for vendor response to CWE-1189 architectural flaw; no patch available as of August 17, 2026.
  • Clop ransomware campaign: Track additional victim disclosures from PTC Windchill/FlexPLM exploitation wave.
  • French government breach investigations: Monitor for attribution details and regulatory enforcement actions under GDPR.
  • SafePal cryptocurrency wallet breach: Watch for stolen data appearing on criminal marketplaces affecting 39,798 customers.

Sources

  • The Hacker News: SAP Commerce Cloud, GitLab GraphQL, Forminator WordPress, Cavern C2, Unisoc VoLTE, Evooo1Bot, China-Nexus VMware, Snowflake GitHub Actions
  • BleepingComputer: Azure account breach claims, Pokémon Center/CEVA Logistics, Certighost AD CS, Clop ransomware, French DGFiP breach, Microsoft Defender ShieldBreak, SafePal breach, Threema DDoS, AmnesiaStealer macOS
  • CERT.BE (Belgium): Ivanti EPM, IBM i, Adobe Commerce active exploitation warnings

---

*This report synthesizes threat intelligence from multiple sources as of August 18, 2026. Organizations should verify applicability to their specific environments and consult vendor advisories for detailed remediation guidance.*