SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, August 12, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Zero-Day and SharePoint RCE Patched | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR This brief highlights Microsoft's massive August 2026 Patch Tuesday addressing over 400 vulnerabilities, including an actively exploited Windows kernel driver zero-day (afd.sys) and a critical SharePoint RCE vulnerability (CVE-2026-55040). Additionally, Russian threat group Sandworm (UAC-0145) is actively targeting IT professionals with trojanized WireGuard VPN clients, while the DeadLock ransomware group has adopted decentralized Polygon blockchain smart contracts to secure its extortion infrastructure against takedowns. Organizations must also prioritize immediate patching for critical zero-click execution flaws in Zoom's annotation tool and actively exploited denial-of-service bugs in Cisco ASA/FTD devices. |
|
■ CRITICAL STORIES Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE A critical vulnerability (CVE-2026-55040) with a CVSS score of 10.0 allows unauthenticated attackers to bypass authentication and gain administrative access to Microsoft SharePoint servers. The exploit chain was discovered with the assistance of an AI agent, highlighting the growing capability of AI-driven vulnerability research. |
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft addressed over 400 vulnerabilities, including an actively exploited use-after-free vulnerability in the afd.sys Windows kernel-mode driver. This zero-day allows attackers to escalate privileges to SYSTEM, posing an immediate threat to unpatched Windows environments. |
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored group Sandworm is targeting IT administrators using social engineering disguised as recruitment. Victims are tricked into installing a trojanized WireGuard VPN client that grants attackers command execution capabilities on target systems. |
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware operation has integrated decentralized infrastructure, using Polygon blockchain smart contracts and Session messaging. This makes their communication channels and data-leak operations highly resilient to traditional law enforcement takedown efforts. |
|
■ CVEs IDENTIFIED CVE-2026-55040 Microsoft SharePoint — Unauthenticated Remote Code Execution (RCE) |
[CVE-TBD-AFD] Microsoft Windows Kernel Driver (afd.sys) — Privilege Escalation to SYSTEM (Actively Exploited) |
[CVE-TBD-CISCO] Cisco Secure Firewall ASA and Threat Defense (FTD) — Denial of Service (Device Crash) |
[CVE-TBD-ZOOM] Zoom Client (Annotation Tool) — Zero-Click Remote Code Execution |
|
■ THREAT ACTORS Sandworm (UAC-0145) | Nation-state (Russia) |
Targeting Ukrainian IT professionals with fake job offers to deliver trojanized WireGuard VPN clients. |
Utilizing Polygon blockchain smart contracts and Session messaging for decentralized extortion infrastructure. |
Kimwolf (AISURU) | Botnet Operator |
Deploying v7 of an Android/IoT botnet utilizing HTTP/2 to masquerade DDoS traffic as legitimate browsing. |
|
|
|
■ ATT&CK TTPs | T1204.002 | | User Execution: Malicious File | IT pros tricked into running trojanized WireGuard VPN installer. |
| T1566.002 | | Phishing: Spearphishing Link | Fake job offers and fake CCleaner websites used to distribute malware. |
| T1068 | | Exploitation for Privilege Escalation | Active exploitation of afd.sys Windows kernel driver for SYSTEM privileges. |
| T1190 | | Exploit Public-Facing Application | Unauthenticated RCE in Microsoft SharePoint (CVE-2026-55040). |
| T1498 | | Network Denial of Service | Kimwolf botnet launching HTTP/2 DDoS traffic; Cisco ASA/FTD targeted with device-crashing exploits. |
| T1584.005 | | Compromise Infrastructure: Botnet | Kimwolf v7 Android/IoT botnet expansion. |
|
■ PATCH PRIORITY Microsoft Windows (afd.sys) — Actively exploited zero-day kernel driver privilege escalation to SYSTEM — [SW] August 2026 Patch Tuesday |
Microsoft SharePoint — CVE-2026-55040 unauthenticated RCE with CVSS 10.0 — [THN] Researchers Disclose AI-Assisted SharePoint Exploit Chain |
Zoom Client — Zero-click remote code execution vulnerability in Annotation tool — [SW] Zoom Patches Zero-Click Code Execution Vulnerability |
Cisco Secure Firewall ASA & FTD — Actively exploited denial-of-service vulnerability causing remote device crashes — [BC] Cisco warns of ASA and FTD VPN flaw |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply Microsoft August 2026 Patch Tuesday updates immediately to address the actively exploited afd.sys kernel driver vulnerability and CVE-2026-55040 in SharePoint. |
| 2 | [P1] Update Cisco Secure Firewall ASA and Threat Defense (FTD) software to the latest version to mitigate actively exploited denial-of-service vulnerabilities. |
| 3 | [P1] Update Zoom desktop clients immediately to patch the zero-click code execution vulnerability residing in the Annotation tool. |
| 4 | [P2] Apply Adobe security updates for ColdFusion and Campaign Classic to prevent critical arbitrary code execution and denial-of-service attacks. |
| 5 | [P2] Educate IT administrators and system engineers on the threat of trojanized WireGuard VPN clients distributed via fake job recruitment campaigns (Sandworm/UAC-0145). |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |