daily cyber × ai intelligence

index

August 15, 2026

A Heavy Day for Exploit Research and In-the-Wild N-Days

61 of 70 sources 404 gathered 400 triaged 43 clustered 43 written

Active exploitation broadened across enterprise infrastructure — VMware vCenter, SAP Commerce Cloud, GeoServer and Citrix NetScaler all saw movement — while a rich crop of fresh vulnerability research dropped for Exchange, managed Postgres, Ruby and the Linux kernel. On the AI side, defenders got a concrete look at autonomous agents hitting critical infrastructure and a clean production-guardrail bypass that coughed up a full system prompt.

Vulnerabilities & Exploits

  • Citrix NetScaler pre-auth RCE CVE-2026-8452 got a full technical writeup from watchtowr, who characterize it as an n-day worth patching but not panicking over — @watchtowrcyber frame it as “it’s an n-day, stop panicking.
  • VMware vCenter exploitation widened: Broadcom pushed VMSA-2026-0006.1, adding a critical auth-bypass (CVE-2026-59309, CVSS 9.8) and a VMXNET3 out-of-bounds write (CVE-2026-47876) alongside the directory-traversal RCE CVE-2026-59310 already under active APT exploitation for reverse-SSH persistence (Broadcom advisory, earlier coverage).
  • SAP Commerce Cloud maximum-severity flaw CVE-2026-58231 (CVSS 10.0, Data Hub Adapter) is now being targeted in attacks, enabling unauthenticated arbitrary code execution (BleepingComputer, The Hacker News).
  • GeoServer is under active exploitation via an unpatched SQL-injection zero-day that chains to remote code execution (SecurityWeek).
  • An Exchange Server 0-day bug chain leveraging MRSProxy and NTLM relay to reach PST write access is detailed in a “hunt like a detective” writeup that also notes how AI is accelerating discovery and commoditizing such exploits (testbnull).
  • A PostGIS memory-corruption bug in a widely deployed PostgreSQL extension was turned into code execution across NeonDB, Supabase, Xata and other managed-Postgres providers — a systemic look at extension risk in the managed-database industry (mehmetince.net).
  • Ruby 4.0 has a universal deserialization RCE gadget chain, disclosed by elttam (elttam, discussion).
  • Microsoft patched LegacyHive, a Windows zero-day disclosed after the July 2026 Patch Tuesday (BleepingComputer).
  • A stack buffer overflow in Realtek Ameba SDKs (AmebaZ/Z2/Z2Plus) lets an attacker spoofing unencrypted 802.11 beacons with oversized SSID IEs overwrite return addresses for potential code execution (PoC gist).

New Tools & Releases

  • Apache IoTDB v2.0.10 pre-auth/unauth attack-surface lab with reproducible PoCs for a 0-day RCE (GitHub).
  • VsockDrop — an unprivileged Linux kernel LPE in the io_uring/vsock zerocopy path that needs no user namespaces, affecting recent 6.x kernels (writeup).

AI & Model Security

  • Autonomous open-source AI agents were used in early July to hack government systems and energy companies, TrendAI’s Tom Kellermann told The Register, calling weaponized AI against critical infrastructure a “clear and present danger” — a broadening of the near-autonomous agent activity seen against Taiwan’s energy and nuclear sectors (The Register, earlier coverage).
  • Escape.tech’s Cascade AI-pentesting engine talked a production AI agent’s prompt-injection guardrail into handing over its entire system prompt on the second attempt — a clean demonstration of guardrail bypass against a live deployment (Escape.tech).
  • Anthropic announced a watermark-detection API (built on Google’s SynthID approach) that lets third parties check whether text was written by Claude — and within days a wave of “watermark removers,” including a 4,500-star open-source project, flooded the web, none with verifiable claims since no public detector exists yet (The Decoder, BleepingComputer, earlier coverage).
  • New reporting on the LiteLLM compromise clarifies attribution: the SANDCLOCK campaign by TeamPCP harvested CI/CD credentials via a backdoored Trivy GitHub Action, and over 95% of the ~2,500 affected orgs were exposed before the malicious LiteLLM packages ever shipped (SecurityWeek, Resecurity, earlier coverage).

Threat Activity

  • Clop listed 40+ organizations on its leak site — including Shell, Philips and GE — likely from PTC Windchill exploitation, with Shell now confirming it is investigating a “potential incident” (BleepingComputer).
  • Attackers are exploiting a macOS Screen Sharing flaw in the wild to deploy a Monero miner, turning previously published PoC work into real-world campaigns (BleepingComputer, earlier coverage).
  • Apple sent a fresh round of “Threat Notification” alerts to users in 110 countries targeted by mercenary spyware; it has now notified customers in over 150 countries to date (BleepingComputer, TechCrunch).
  • HoneyMyte upgraded its CoolClient backdoor with a signed kernel-mode driver acting as a stealthy Windows rootkit for persistence, process hiding and C2 evasion, primarily against Asian targets (Securelist).
  • China-linked Jewelbug is running parallel operations — government/military espionage (including breaching government webmail) alongside cryptocurrency theft and fraud across Asia and the Middle East (BleepingComputer, Dark Reading).
  • A rise in ClickFix campaigns is delivering KongTuke payloads by abusing a legitimate Mozilla binary, using Rust-based DLLs masquerading as Firefox components with AMSI bypass, shell execution, screenshotting and persistence (Unit 42).
  • Armored Likho expanded its espionage toolkit with a Rust/Tauri dropper fronted by a fake catalog, plus “Still Sync” for Telegram data theft and “Still Audio” for voice surveillance, targeting Russian users (Securelist).
  • ENIBot, a rapidly expanding Mirai-derived IoT botnet, has captured 7,504 unique bot IPs since March, escalating brute-force and ADB exploitation through June–July (Unit 42).
  • Ukraine shut down 94 fraudulent call centers in a nationwide crackdown on investment scams — 411 searches, 3,336 computers, 5,200+ SIMs and roughly $2M in cash seized (BleepingComputer).

Data Breaches

  • France’s tax authority (DGFiP) confirmed a late-June intrusion after an attacker gained VPN access to internal lookup tools; officials cite ~680,000 taxpayers while the seller now touts up to 2 million records (The Record, The Register, earlier coverage, discussion).
  • RingCentral notified that ShinyHunters stole and published data on 1.6 million accounts (names, addresses, emails, phone numbers) after a July intrusion (BleepingComputer, SecurityWeek, earlier coverage).
  • Beacon CRM exposed data belonging to over 1,000 charities after a compromised AWS access key was leaked in publicly available JavaScript build artifacts — a textbook CI/CD pipeline failure (SecurityWeek, The Register).
  • A threat actor is advertising an alleged fresh August 2026 Plenty of Fish database of ~170 million records (usernames, emails, DOB, location and extensive profile fields) for $300 — unverified (DailyDarkWeb).
Models