CVE-2020-9771, CVE-2026-26035, CVE-2026-34492, CVE-2026-43284, CVE-2026-43500, CVE-2026-59310, CVE-2026-64887, CVE-2026-65640, CVE-2026-70465, CVE-2026-70468, CVE-2026-71362
Get tomorrow's brief in your inbox
Today: GeoServer zero-day exploited within hours of disclosure, ransomware groups surge to 93 active operations in Q2, and critical VMware vCenter flaw sees global exploitation just days after patch release.
GeoServer Zero-Day Under Active Exploitation (No Patch Available)
An SQL injection vulnerability in GeoServer's jsonArrayContains function allows remote code execution under certain configurations. Exploitation began within hours of public disclosure on August 13. WatchTowr observed hundreds of attempts from a small number of source IPs targeting the unpatched flaw. GeoServer is used across government, agriculture, telecom, and transit sectors, with multiple prior vulnerabilities in CISA's Known Exploited Vulnerabilities catalog.
VMware vCenter CVE-2026-59310 Exploited Globally
A critical directory traversal flaw (CVSS 9.8) in VMware vCenter came under heavy exploitation just five days after disclosure on July 29. QUIRSO identified a suspected APT actor targeting 361 unique IPs across 47 countries, with the US, France, Iran, and Turkey most heavily affected. The attacker is establishing persistence using reverse_ssh, which survives patching.
No structured claims data available in today's feed.
Q2 2026: Ransomware Ecosystem Expands to 93 Active Groups
Check Point Research reports victim volume held flat at 2,139 in Q2 (up 0.8% from Q1, up 33% year-over-year), but the number of active groups climbed from 71 to 93, a new high. Top 10 groups accounted for 57.6% of victims, down from 71% in Q1. Qilin remained the most prolific operator for a fourth straight quarter with 279 victims (down 17%), while The Gentlemen surged 62% to 269 victims and outpaced Qilin during June. An internal leak from The Gentlemen exposed a core team of nine operators and confirmed use of AI coding assistants to build their ransomware management panel in about three days, the first direct evidence of AI accelerating malicious tooling development. Ransom payment rates fell to a multi-year low near 23%, continuing a six-year decline from 85% in 2019.
Crypting Services Lower Barrier to Evasion
Recorded Future analyzed 24 threat actors advertising crypting services within the past year, finding a competitive, reputation-driven market focused on Windows payloads. Crypters modify malicious executables to bypass AV and EDR detection, offering payload wrapping, in-memory execution, anti-analysis checks, process injection, persistence options, and post-detection re-crypting. Advanced providers operate as broader malware-enablement services. No macOS or Linux crypting services were identified.
JWR Real-Time Phishing Framework Uses Live Keystroke Monitoring
Cisco Talos discovered JWR, a previously undocumented real-time phishing framework likely a variant of The Outsider phishing-as-a-service platform. JWR uses an open WebSocket connection allowing attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints. The operator-driven design allows active MFA bypass by prompting victims for 2FA codes exactly when needed.
HoneyMyte APT Upgrades CoolClient with Kernel-Mode Rootkit
Kaspersky discovered the latest CoolClient variant from HoneyMyte (Mustang Panda) can deploy a signed kernel-mode driver as a Windows service. The driver hides the CoolClient process, protects related files and registry entries, and prevents inspection or modification. The design is comparable to kernel-mode enhancements previously observed in ToneShell, but CoolClient's driver exposes dedicated IOCTL handlers for direct communication with the user-mode backdoor. The updated variant was observed in intrusions across Pakistan, Mongolia, and Myanmar.
Adobe Commerce CVE-2026-71362 Targeted Immediately After Disclosure
A critical incorrect authorization flaw (CVSS 9.1) in Adobe Commerce allows unauthenticated attackers to elevate privileges and take over customer accounts. Sansec blocked the first exploitation attempts immediately after Adobe's August 2026 Patch Tuesday advisory was published. The vulnerability impacts all Commerce, Commerce B2B, and Magento Open Source versions up to and including those running July 2026 patches. Adobe released an isolated patch to allow merchants to apply the fix with fewer integration risks.
White House Authorizes Private Sector Offensive Cyber Operations
A presidential memo directed the Department of Homeland Security to establish a program through which private companies can carry out offensive cyber operations against cybercrime organizations on behalf of the US government. The program will run under the DHS National Coordination Center with oversight from DOJ and DHS. Companies must provide $1 million in escrow, operate secure facilities, have vetted personnel, and demonstrate proven technical proficiency. Each operation requires written approval from co-Executive Directors from both DHS and DOJ. Operations targeting US infrastructure and individuals involved in large cybercrime are permitted. The program must be operational within 60 days (approximately October 11).
WordPress 7.0.4 Patches RCE via Malicious Postscript Files (CVE-2026-65640)
WordPress patched a high-severity RCE flaw (CVSS 8.8) that allows authenticated attackers with Author-level permissions to execute arbitrary code via malicious Postscript file uploads. The vulnerability affects only installations using Imagick and Ghostscript. ImageMagick processes file contents while WordPress checks file extensions, allowing attackers to upload a PNG containing PostScript that executes in Ghostscript. The fix was backported to all branches back to 4.7.
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet resolved eight vulnerabilities including high-severity authentication bugs in FortiWeb (CVE-2026-26035) and FortiManager (CVE-2026-70468). FortiWeb's flaw allows remote, unauthenticated attackers to log in with random credentials when the wildcard setting for administrator accounts is enabled (disabled by default). FortiManager's flaw allows remote attackers to impersonate any managed FortiGate device with a valid certificate and specific CLI option set. A high-severity buffer overflow in FortiClient for Windows (CVE-2026-70465) allows unauthenticated attackers who can modify DNS responses to execute arbitrary code.
CISA Advisories: Siemens, Hitachi Energy, ANDRITZ, Johnson Controls
CISA published 15 ICS advisories covering multiple vendors. Notable vulnerabilities include:
Johnson Controls Airwall: Hard-coded cryptographic key (CVE-2026-64887) and arbitrary file read (CVE-2026-34492). Update to v4.1.0 or later.
Sources: CISA ICS Advisories
AmnesiaStealer macOS Infostealer Uses Browser Remote Control
Jamf discovered AmnesiaStealer, a multi-stage Rust-based macOS infostealer distributed through fake GitHub download pages in ClickFix attacks. The malware harvests keychains, Chromium browser databases, Apple Notes, and documents. It attempts two TCC bypasses for Safari cookies and full disk access, and can download a stream module providing real-time remote control over the victim's browser session at 3fps via Chrome DevTools Protocol. The malware overwrites per-browser Safe Storage keys, rendering previously saved passwords and cookies unrecoverable.
Exploitation windows continue to shrink. GeoServer came under attack within hours of disclosure, VMware vCenter within five days, and Adobe Commerce immediately upon public advisory. AI is increasingly cited as the accelerant lowering exploit development costs. The ransomware ecosystem shows concentration at the top even as the total number of active groups reaches new highs, suggesting lower barriers to entry but continued dominance by established operations. Payment rates are falling to historic lows while average payments rise, indicating a split market where large enterprises pay heavily while mid-market organizations increasingly refuse.