Daily Security Intel

Archives
Log in
Subscribe
August 14, 2026

[SecurityIntel] 14 Aug | Active VMware and Windows Zero-Day Exploitations Surge

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, August 14, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active VMware and Windows Zero-Day Exploitations Surge

CRITICAL

5

C2 IPs

80

OTX IOCs

26

ARTICLES

■ ANALYST TLDR

Threat actors are actively exploiting critical enterprise vulnerabilities, including a VMware vCenter Syslog Server RCE (CVE-2026-59310) and a Microsoft SharePoint authentication bypass (CVE-2026-55040). Concurrently, newly disclosed Windows zero-days like "ShieldBreak" and "LegacyHive" are enabling immediate SYSTEM privilege escalation on compromised endpoints. Organizations must immediately prioritize patching these edge and enterprise assets to block active intrusion and persistence campaigns.

■ CRITICAL STORIES

CRITICAL#1

Critical VMware vCenter RCE flaw exploited for reverse SSH access

Threat actors are actively exploiting CVE-2026-59310 in VMware vCenter Syslog Server to drop reverse SSH tools, establishing persistent remote access inside target networks.

CRITICAL#2

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

A newly disclosed zero-day exploit allows local users to escalate privileges to SYSTEM, severely undermining Windows endpoint security.

HIGH#3

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

Akira ransomware affiliates are bypassing endpoint detection and response (EDR) agents by forcing systems to reboot into Safe Mode with Networking, highlighting a critical gap in endpoint defense strategies.

CRITICAL#4

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Active exploitation of CVE-2026-55040 began immediately following the public release of a proof-of-concept, putting unpatched SharePoint servers at immediate risk.

■ CVEs IDENTIFIED

CVE-2026-59310

VMware vCenter Server — Directory traversal leading to Remote Code Execution (RCE) and reverse SSH backdoor deployment

Critical

CVE-2026-71362

Adobe Commerce — Remote Code Execution vulnerability targeted immediately after public disclosure

Critical

CVE-2026-55040

Microsoft SharePoint — Authentication bypass vulnerability exploited in the wild following PoC release

Critical

[CVE-TBD]

Microsoft Windows (ShieldBreak) — Zero-day privilege escalation exploit allowing any user to spawn a shell with SYSTEM privileges

Critical

■ THREAT ACTORS

Akira

Ransomware Affiliate

Disabled EDR solutions via Safe Mode with Networking to exfiltrate data

Jewelbug

Cyber Espionage Group

Targeted government and military webmail while running parallel cryptocurrency fraud

Nightmare Eclipse

Threat Group

Released the 'ShieldBreak' Windows zero-day exploit for SYSTEM privilege escalation

■ ATT&CK TTPs

T1562.001
Impair Defenses: Disable or Modify Tools | Akira ransomware forced system reboots into Safe Mode to disable EDR agents
T1212
Exploitation for Credential Access | Mirai variant sniffs network traffic for default access credentials
T1068
Exploitation for Privilege Escalation | ShieldBreak exploit used to escalate local user privileges to SYSTEM on Windows
T1133
External Remote Services | Attackers deployed reverse SSH tools on VMware vCenter for persistent remote access
T1204.002
User Execution: Malicious File | WordPress RCE triggered via malicious Postscript files
T1021.004
Remote Services: SSH | Attackers established reverse SSH tunnels on compromised vCenter servers

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

VMware — vCenter Server (CVE-2026-59310) — Active exploitation of RCE to deploy reverse SSH backdoors — BleepingComputer

[P1 PATCH NOW]≤24h

Microsoft — SharePoint (CVE-2026-55040) — Active exploitation of authentication bypass following PoC release — The Hacker News

[P1 PATCH NOW]≤24h

Adobe — Commerce (CVE-2026-71362) — RCE vulnerability targeted immediately after disclosure — SecurityWeek

[P1 PATCH NOW]≤24h

Microsoft — Windows (ShieldBreak / LegacyHive) — Zero-day exploits allowing SYSTEM privilege escalation and unauthorized access — SecurityWeek / BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch VMware vCenter immediately to address CVE-2026-59310 to block active directory traversal and reverse SSH backdoor deployment.
2[P1] Apply Microsoft security updates for SharePoint (CVE-2026-55040) and Windows (ShieldBreak and LegacyHive zero-days) to prevent authentication bypass and SYSTEM privilege escalation.
3[P1] Update Adobe Commerce immediately to remediate CVE-2026-71362 due to active exploitation in the wild.
4[P1] Apply Fortinet patches for FortiWeb and FortiManager to resolve critical authentication bypass and appliance impersonation vulnerabilities.
5[P2] Update WordPress installations to version 7.0.4 or higher to mitigate Postscript-based RCE.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 15 Aug | SAP Commerce Cloud and GeoServer Under Active Exploitation Older → [SecurityIntel] 13 Aug | Lazarus Exploits Windows Zero-Day in Defense Attacks
Powered by Buttondown, the easiest way to start and grow your newsletter.