← All threat briefs

Cybersecurity Brief — 2026-08-25

SECURITY // 2026-08-25

Cybersecurity Brief — 2026-08-25

Active Exploitation & Critical Vulnerabilities

  • miniOrange SAML plugin for WordPress under active attack — Threat actors are exploiting two unauthenticated authentication bypass flaws (CVE-2026-61979, CVSS 8.1; CVE-2026-15981, CVSS 9.8) in the Xecurify miniOrange SAML 2.0 SSO plugin. The bugs stem from signature validation logic errors in PHP's openssl_verify(), allowing attackers to forge SAML responses and log in as any WordPress user, including administrators. Opportunistic scanning from at least six IP addresses suggests broad, untargeted exploitation. Patches available in versions 17.0.5 and 17.0.6. (Source: The Hacker News)

  • CISA adds Oracle WebLogic flaw to KEV catalog — CVE-2026-21962 (CVSS 10.0), an improper access control vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in, has been added to CISA's Known Exploited Vulnerabilities catalog with evidence of active exploitation. The flaw allows unauthenticated attackers to access or modify critical data. Patches were released in January 2026, but GreyNoise and CloudSEK have observed ongoing exploitation attempts, including activity targeting older WebLogic RCEs (CVE-2020-14882/14883, CVE-2020-2551, CVE-2017-10271). Federal agencies have until August 27, 2026 to patch per BOD 26-04. (Source: The Hacker News)

  • SAP Commerce Cloud CVE-2026-58231 exploited days after patch — A maximum-severity (CVSS 10.0) authorization bypass in SAP Commerce Cloud began drawing exploitation attempts just three days after the patch release, per Defused Cyber and KEVIntel honeypot data. The flaw allows unauthenticated attackers to abuse a default authentication client and execute arbitrary code. No public PoC exists yet. Onapsis recommends immediate patching and, as a workaround, configuring IP Filter Sets to restrict access to the vulnerable endpoint. Prior SAP NetWeaver flaws have been weaponized by China-nexus espionage groups (UNC5221, UNC5174, CL-STA-0048) and ransomware operators (BianLian, RansomExx). (Source: The Hacker News)

Espionage & Targeted Threats

  • Apple issues mercenary spyware alerts to users in 110 countries — Apple sent a new batch of high-confidence threat notifications to individuals it believes were targeted by mercenary spyware, bringing the total notified countries to over 150 since the program began in late 2021. Targets typically include journalists, activists, politicians, and diplomats. Access Now reports a record volume of assistance requests following this wave; some recipients include members of Ukraine's military. Citizen Lab notes the geographic diversity of public reports is "unprecedented," suggesting a broader campaign. (Source: The Hacker News)

  • VMware vCenter CVE-2026-59310 exploited in suspected APT campaign — QUIRSO discovered active exploitation of a directory-traversal flaw (CVSS 9.8) patched by Broadcom in late July. The attack chain uses path traversal for initial access, then deploys a malicious cron job with reverse_ssh for persistent outbound connections to attacker infrastructure. Compromise confirmed on 361 unique IPs across 47 countries (concentrated in Germany, U.S., Turkey, Iran, France). First victim contact observed August 3 — five days post-disclosure — suggesting the patch release triggered the campaign. Chinese APT groups (UNC5174, PurpleHaze) have previously weaponized similar VMware flaws. Concurrent scanning for CVE-2026-59309 (unauthenticated auth bypass in vmdir, CVSS 9.8) is also spiking. (Source: The Hacker News)

Post-Patch Exploitation & PoC-Driven Attacks

  • SharePoint authentication bypass exploited after PoC release — CVE-2026-55040 (CVSS 9.1), a JWT token validation bypass patched in Microsoft's July 2026 Patch Tuesday, is being actively exploited following Rapid7's public PoC release. The flaw chains four weaknesses to forge valid JWTs and impersonate any SharePoint site user/admin. KEVIntel telemetry shows 12 exploitation attempts from eight IPs across five regions (Hong Kong, Japan, Netherlands, Taiwan, U.S.), with eight attempts on August 12–13 alone. This is the fifth SharePoint vulnerability exploited in 2026. (Source: The Hacker News)

Supply Chain & Privacy Intelligence

  • DecryptAds launches to map adtech supply chains and expose geo-risk partners — A new free service (decryptads.com) continuously scrapes and cross-references ads.txt, app-ads.txt, and sellers.json files to reveal the full advertising ecosystem behind websites and apps. Analysis of espn.com found 143 ad partners and 19 registered data brokers, many collecting geolocation and device fingerprints. Notably, U.S. military news sites (armytimes.com, defensenews.com, etc.) all permit the Russian adtech firm Between Digital (payments routed through sanctioned Alfa Bank), plus entities in the UAE and Panama. The tool flags "geo-risk" partners in adversarial nations and identifies supply-chain integrity issues like cloned declarations and broken cross-references. (Source: Krebs on Security)