← All threat briefs

Cybersecurity Threat Brief — 2026-08-17

SECURITY // 2026-08-17

Cybersecurity Threat Brief — 2026-08-17

Active Exploitation & Campaigns

  • Evooo1Bot Linux botnet weaponizes decade-old CVEs to build SOCKS5 proxy army — Fortinet FortiGuard Labs uncovered a previously undocumented Mirai-derived botnet active since July 2026. Evooo1Bot exploits 11 known vulnerabilities (CVE-2007-3010 through CVE-2025-55583) in edge devices — Alcatel PBX, NETGEAR, Tenda, D-Link, Telesquare, Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, Kubernetes — to install a loader that fetches architecture-specific binaries, establishes encrypted C2 over port 443, and converts infected routers, firewalls, and cameras into SOCKS5 proxies for follow-on operations. The malware includes SSH brute-forcing, credential sniffing, and DDoS capabilities. (Source: The Hacker News)

  • Suspected China-nexus APT exploits VMware vCenter CVE-2026-59310 (CVSS 9.8), deploys Babuk-derived ransomware — German IR firm QUIRSO attributes rapid exploitation (starting 5 days post-disclosure) to a Chinese-speaking actor in UTC+08:00 timezone, based on Chinese-language artifacts, tooling, and victimology excluding mainland China. Campaign compromised ~361 unique IPs across 47 countries (top: Germany 55, US 41, Turkey 38, Iran 26, France 25). Attack chain leverages CVE-2026-59310 directory traversal for RCE, drops linuxFile WebSocket backdoor with XOR-obfuscated C2, establishes persistence via systemd/cron, and deploys reverse SSH binaries. A second flaw, CVE-2026-59309 (auth bypass), was exploited on same hosts as early as Aug 1. Broadcom patched both July 29. (Source: The Hacker News)

  • macOS Screen Sharing flaw (CVE-2026-65400) exploited to deploy Monero miners — Dutch NCSC confirmed in-the-wild exploitation ~1 week after Apple's Aug 6 patch (macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9). The high-severity auth bypass in screensharingd lets remote attackers log in without credentials by simply naming an account — usernames are visible on login screen. Threat actors gain root, install XMRig. NCSC reports abuse on systems with port 5900 exposed; Calif estimates ~40,000 internet-accessible macOS hosts had Screen Sharing enabled as of Aug 8. Separate RCE in same daemon was silently patched in late July. (Source: SecurityWeek)

  • SAP Commerce Cloud CVE-2026-58231 (CVSS 10) exploited 3 days post-disclosure — SAP patched the insufficient-authorization/input-validation flaw Aug 11; Defused honeypots detected exploitation attempts Aug 14. KEVIntel independently confirmed attacks. No public PoC existed at disclosure; one emerged Aug 15. CISA's KEV catalog currently lists 14 SAP flaws but only CVE-2019-0344 for Commerce Cloud; CVE-2026-58231 not yet added. (Source: SecurityWeek)

Vulnerability & Patch Landscape

  • SANS 2026 AI Survey: Adoption outpacing governance — Survey of 536 security professionals finds AI security programs falling short on detection efficacy, trust/transparency, and workforce readiness. Organizations deploying AI for defense and offense alike, but governance frameworks lag. Full report: "Poisoned Wells and Pure Springs: Drawing Security and Compromise from the Same AI Source" (July 2026). (Source: The Hacker News / SANS Institute)

Threat Intelligence & Observability

  • DecryptAds launches free service mapping adtech supply chains, exposes Russian adtech on US military sites — New platform scrapes/correlates ads.txt, app-ads.txt, sellers.json, buyers.json to reveal tracking entities across web/app ecosystems. Analysis of espn.com shows 143 ad partners, 19 registered data brokers (half collecting geolocation). US military news sites (armytimes.com, defensenews.com, etc.) all permit Between Digital — flagged as Russian firm routing payments through sanctioned Alfa Bank — plus entities in UAE and Panama. Between Digital appears on ~55,000 partner sites. Tool flags "geo-risk" partners in China, Russia, Cyprus, UAE. (Source: Krebs on Security)