Cybersecurity Threat Brief — 2026-08-15
Active Exploitation & Critical Vulnerabilities
SAP Commerce Cloud CVE-2026-58231 under active exploitation days after patch — A maximum-severity (CVSS 10.0) vulnerability in SAP Commerce Cloud is being actively targeted. The flaw allows unauthenticated attackers to abuse a default authentication client and submit crafted input to functions lacking sufficient validation, enabling arbitrary code execution. Defused Cyber observed exploitation attempts hitting honeypots just three days after the patch release. No public PoC exists. Prior SAP NetWeaver flaws (CVE-2025-31324) have been weaponized by China-nexus espionage clusters (UNC5221, UNC5174, CL-STA-0048) and cybercrime groups (BianLian, RansomExx). (Source: The Hacker News)
Apple macOS Screen Sharing flaw (CVE-2026-65400, CVSS 9.8) exploited to deploy Monero miners — The Netherlands NCSC warns of active exploitation of a critical authentication bypass in macOS Screen Sharing on internet-exposed Macs (port 5900). Attackers gain root access and drop a Monero crypto miner. Patched in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 (released August 6). Separately, researcher @osxreverser describes a distinct pre-auth vulnerability in screensharingd allowing remote code execution without credentials on any Mac with Screen Sharing enabled — estimating ~40,000 exposed hosts globally, nearly half in the U.S. (Source: The Hacker News)
Supply Chain & Software Security
Trivy scanner compromise, not LiteLLM, behind 2,500-organization supply chain attack — SOCRadar analysis reveals over 95% of the ~2,500 organizations affected by the "LiteLLM" supply chain attack were actually compromised via a malicious Trivy build published March 19, not the later LiteLLM packages (March 24, online ~40 minutes). The TeamPCP/Shai-Hulud worm used a .pth file executed at Python interpreter startup, bypassing ignore-scripts protections. Activity surged March 22–23 when malicious Trivy images hit Docker Hub. Stolen secrets (JWTs, AWS keys, GitHub tokens, OpenAI keys, etc.) from over 1,000 organizations are now being brokered on Telegram. Six CI/CD platforms affected: GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, Buildkite. (Source: SecurityWeek)
Infoblox: Threat actors spent nearly $7M on expired "dropcatch" domains for scams and malware — In H1 2026, 50,400–65,000 expired domains were re-registered daily (~20% of all registrations). Threat actor "Sable Squirrel" (linked to Vietnam, overlaps with illegal streaming network Xoi Lac TV) acquired domains to inherit reputation, backlinks, residual traffic, and lingering connections (email, cached results, DNS records) for illegal streaming, gambling promotion, and malware infrastructure. DropCatch.com and similar services automate catching at millisecond precision; multi-party backorders trigger public auctions. (Source: The Hacker News)
Data Breaches & Extortion
ShinyHunters dumps 1.6M RingCentral accounts after failed extortion — 1.6 million unique email addresses plus names, addresses, and phone numbers leaked after RingCentral refused to pay. ShinyHunters claimed 623 GB stolen via vishing an employee (voice phishing for credentials). The group has hit 100+ orgs in 2026 including education tech, healthcare, and Abbott's cancer diagnostics (10.9M emails + health data). RingCentral disclosed July 28; leak posted August 3. (Source: The Register)
Trezor confirms 13,000 customer records exposed in logistics provider breach — Hardware wallet maker Trezor disclosed that shipping/logistics partner ShipMonk suffered a breach exposing customer names, emails, and shipping addresses. No private keys or funds affected. (Source: The Register)
French tax authority admits 2M records stolen — A threat actor claimed 2M records from the French tax administration (DGFiP); the agency confirmed a breach but disputes continued access claims. (Source: The Register)
Beacon CRM breach via exposed AWS key in JavaScript — Over 1,000 charities impacted after an AWS access key embedded in client-side JavaScript allowed access to Beacon's CRM database. (Source: The Register)
AI-Driven Threats
Autonomous AI agents pose "clear and present danger" to critical infrastructure — In early July, suspected Chinese operators used Hermes and OpenClaw AI agents in 12 "attack waves" against Taiwan, compromising a government website, nuclear safety agency, IT supply chain vendors, and 7+ energy companies. FBI Cyber Division Assistant Director Brett Leatherman: critical infrastructure targeting is the top concern — "where cyber becomes kinetic." Former US National Cyber Director Chris Inglis warns 40–50 years of tech debt (unpatched PLCs, EOL systems) expands attack surface; open-weight models now excel at finding and chaining vulnerabilities. (Source: The Register)
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency — Related to above; agentic swarm deployed up to 8 sub-agents with independent targets/techniques, stealing credentials and sensitive data while moving laterally. (Source: The Register)
Policy & Emerging Threats
Trump administration proposes licensing private cyber firms to "hack back" — Contractors could surveil and disrupt foreign criminal networks under strict rules with a $1M bond. (Source: The Register)
Microsoft-vendetta hacker claims new Windows zero-day (system privileges on fully patched) — Self-described vendetta actor publishes exploit for a local privilege escalation on fully patched Windows; "Exploit Wednesday" returns. (Source: The Register)
Spectre returns: RISC-V chips shown susceptible to speculative execution attacks — Eight years after Spectre/Meltdown, researchers demonstrate new variants affecting RISC-V architectures. (Source: The Register)
Chinese Loongson processors found with leaky caches — Researchers show side-channel data extraction possible even from inside a guest VM. (Source: The Register)
Brief compiled from The Hacker News, SecurityWeek, and The Register. All stories dated August 14–15, 2026.