Cybersecurity Brief — 2026-08-16
Active Exploitation & Critical Vulnerabilities
-
SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) under active exploitation — Defused Cyber observed exploitation attempts against honeypots just three days after SAP released patches. The flaw allows unauthenticated attackers to abuse a default authentication client and execute arbitrary code. No public PoC exists yet. Prior SAP NetWeaver flaws (CVE-2025-31324) were weaponized by China-nexus groups (UNC5221, UNC5174, CL-STA-0048) and ransomware gangs (BianLian, RansomExx). Onapsis urges immediate patching and IP filtering as a workaround. (Source: The Hacker News)
-
Apple macOS Screen Sharing CVE-2026-65400 (CVSS 9.8) exploited to deploy Monero miners — The Netherlands NCSC warns of active abuse against internet-exposed Macs with port 5900 open. Attackers gain root access and install cryptominers. Patched in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 (released August 6). A separate pre-auth vulnerability in the same component (screensharingd) was also identified by researcher @osxreverser, who estimates ~40,000 exposed Screen Sharing hosts globally, half in the U.S. (Source: The Hacker News)
-
Metabase zero-day (CVSS 10.0, no CVE) exploited in the wild — Unauthenticated SQL injection via
/api/session/reset_passwordgrants full admin access to Metabase instances. Metabase Cloud already patched; self-hosted versions >=1.58 affected (fixed in x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5). Confirmed victims include Framework (customer PII exposed) and n8n (136 customer records, including 5 bcrypt-hashed passwords, accessed). Workaround: block the reset_password endpoint and rotate credentials. (Source: The Hacker News)
Supply Chain & Infrastructure Risks
- DecryptAds service maps adtech supply chain, exposes adversarial ad networks on major sites — New free service scrapes and cross-references ads.txt, app-ads.txt, and sellers.json files to reveal tracking ecosystems. Analysis of espn.com shows 143 ad partners and 19 registered data brokers, with ~50% collecting geolocation. Flags "geo-risk" partners in Russia, China, UAE, Cyprus on U.S. military news sites (armytimes.com, defensenews.com, etc.). Between Digital (Russian firm routed through sanctioned Alfa Bank) found across multiple defense publications. (Source: Krebs on Security)
Other Notable Activity
-
N-able N-central servers compromised again after incomplete fix — Attackers took over management servers despite vendor's earlier patch. Second round of updates required. (Source: The Hacker News)
-
NatJack attacks hijack TCP sessions and spoof DNS by manipulating NAT tables — New technique affects enterprise and carrier-grade NAT devices. (Source: The Hacker News)
-
Azure Cosmos DB flaw exposed platform-wide master key — Could access any customer database across the platform. (Source: The Hacker News)
-
18-year-old Linux SCTP flaw (CVE-2026-?) allows local root and container escape — Long-dormant vulnerability in Stream Control Transmission Protocol. (Source: The Hacker News)
-
Critical cPanel flaw lets hosting customers run SQL as database root — Actively exploitable. (Source: The Hacker News)
-
Zbtlink routers ship with backdoor opening unauthenticated root shells — Chinese-manufactured devices. (Source: The Hacker News)
-
Google Password Manager attacks could hijack passkey-protected accounts — Novel attack vector against passkey implementation. (Source: The Hacker News)
Brief compiled from The Hacker News and Krebs on Security. Deduplicated across sources. All times approximate to U.S. Eastern.