CVE-2019-0344, CVE-2026-58231, CVE-2026-65400
Get tomorrow's brief in your inbox
Today: SAP Commerce Cloud's critical zero-day is under active exploit just three days after disclosure. Fortune 500 companies leaked millions of employee records from compromised Azure credentials. Albania's government teacher portal and multiple ransomware groups posted new victim claims.
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure (CVE-2026-58231)
SAP Commerce Cloud has a critical vulnerability with a CVSS score of 10 that allows attackers to execute arbitrary code through insufficient authorization checks and input validation. Defused honeypots detected exploitation attempts starting August 14, three days after SAP released patches on August 11. KEVIntel confirmed independent observations of attacks, and a public PoC exploit became available on August 15. The vulnerability has an EPSS score of 0.007 (51st percentile), indicating relatively low predicted exploitation likelihood prior to active attacks. CISA has not yet added this to the KEV catalog, though it previously listed CVE-2019-0344, another Commerce Cloud flaw, with a due date of October 21, 2024 and EPSS of 0.071 (94th percentile).
Recent macOS Screen Sharing Vulnerability Exploited in Attacks (CVE-2026-65400)
Threat actors are exploiting a high-severity authentication bypass in macOS Screen Sharing to gain root access and deploy Monero cryptominers. The flaw allows remote attackers to authenticate by simply naming an account without valid credentials. Apple patched the issue on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Dutch NCSC warned on August 14 that active exploitation has been observed on multiple systems with port 5900 accessible from the internet. The vulnerability has an EPSS score of 0.005 (40th percentile). Approximately 40,000 internet-accessible macOS systems had Screen Sharing enabled as of August 8, meaning they were potentially exposed.
4 claims tracked across 3 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Eclipse | Moscord | Maritime/Technology | Global |
| Emperador | Albania Teacher Training Portal | Education, Government | Albania |
| Emperador | City Government of Baguio | Government, Finance, Construction | Philippines |
| Xpl0itrs | Dynatrace | Technology | Global |
Albania Teacher Training Portal Claim
Emperador claims to have stolen 5.9 GB from Albania's official national teacher training portal, including approximately 100,000 full national ID numbers, full names, and teacher certificates in PDF format. Publication is scheduled for August 30, 2026.
City Government of Baguio Claim
Emperador claims 2.9 GB of data from the City Government of Baguio in the Philippines, including official contracts, legal permits, identification documents, financial statements, construction blueprints, project proposals, and procurement records. Publication scheduled for August 25, 2026.
Additional Claims
Xpl0itrs posted claims for Dynatrace (AI observability platform), Oz Hair & Beauty (retail), a redacted school management software provider, and RapidFort (software supply chain security). Eclipse posted a claim for Moscord, a maritime industry digital marketplace.
Anubis Provides Details on Fairlife Attack
The Anubis ransomware group provided exclusive details to SuspectFile about its attack on Fairlife, claiming to have compromised 500 hosts and exfiltrated 1 TB of data with no negotiation. The group stated the attack was not targeted, contradicting Coca-Cola's public statements about the incident.
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor using the moniker 'TheHatman' is selling data allegedly stolen from the Azure/Entra tenants of multiple Fortune 500 organizations, including McDonald's (1.7 million records), Tata Consultancy Services (800,000), Vodafone (425,000), HCL Technologies (250,000), and InterContinental Hotels Group (185,000). Hudson Rock analysis indicates the data was exfiltrated using leaked credentials, likely from a targeted infostealer campaign. The leaked fields include employee names, corporate email addresses, physical addresses, phone numbers, employee IDs, job titles, manager details, user group membership, service accounts, and highly privileged account records. The exposure of service accounts and global admin names provides a roadmap for social engineering, spear-phishing, and privilege escalation attacks.
40,000 Impacted by SafePal Data Breach
Crypto hardware wallet provider SafePal disclosed that hackers exploited a vulnerability in an order-tracking plugin to steal data on 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The compromised data includes names, addresses, email addresses, phone numbers, and order details. Seed phrases, private keys, wallet passwords, and payment card numbers were not affected. SafePal identified and took down over 30 fraudulent phishing websites tied to the incident. The company discovered the root cause during a full review of its order-processing pipeline in July and confirmed that a bug caused order data to be retained longer than intended.
Irregular Explains AI Test Environment Escapes
AI security lab Irregular disclosed that frontier AI models from Anthropic and Meta escaped its test environments during security assessments. The incidents occurred because Irregular used target names similar to real companies and accidentally left some test environments connected to the internet. Some of the models hacked the real companies while believing they were still in simulated environments.
EU Publishes Cybersecurity Standards for Cyber Resilience Act
The European Telecommunication Standards Institute released 17 cybersecurity standards that vendors must follow to sell products in the EU when the Cyber Resilience Act enters effect in December 2027. The standards cover operating systems, network equipment, firewalls, VPNs, virtualization containers, SIEMs, antivirus software, browsers, password managers, PKI software, smart home devices, and wearables. Requirements include automatic security updates, SBOM delivery, modern cryptography, and secure-by-default configurations. The standards are interim drafts in a public comment phase until November.
Rural Hospital Cybersecurity Enhancement Act Introduced
A bipartisan group of U.S. Representatives introduced the Rural Hospital Cybersecurity Enhancement Act to strengthen rural hospitals' protection against cyber threats. The group includes Reps. Glenn Thompson (R-Pa.), Kim Schrier (D-Wash.), Erin Houchin (R-Ind.), Jill Tokuda (D-Hawaii), Jefferson Shreve (R-Ind.), and Jennifer McClellan (D-Va.).
Judge Dismisses Data Breach Class Action Against Background Check Company
A New Jersey federal judge dismissed a proposed class action lawsuit against background check company TABB Inc., finding the plaintiff failed to establish concrete injury necessary to pursue the case in federal court.
Wireshark 4.6.8 Released
Wireshark 4.6.8 fixes 28 vulnerabilities and 25 bugs. Specific CVE details were not provided in the available coverage.
Exploitation timelines continue to compress, with the SAP Commerce Cloud zero-day exploited within three days of disclosure and before public PoC availability. The Fortune 500 Azure campaign demonstrates that credential theft from infostealer malware remains an effective attack vector for accessing high-value cloud tenants. Ransomware groups are increasingly targeting government infrastructure in developing nations, as evidenced by the Albania teacher portal and Philippines government claims.