SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, August 14, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active VMware and Windows Zero-Day Exploitations Surge | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 26 ARTICLES |
|
■ ANALYST TLDR Threat actors are actively exploiting critical enterprise vulnerabilities, including a VMware vCenter Syslog Server RCE (CVE-2026-59310) and a Microsoft SharePoint authentication bypass (CVE-2026-55040). Concurrently, newly disclosed Windows zero-days like "ShieldBreak" and "LegacyHive" are enabling immediate SYSTEM privilege escalation on compromised endpoints. Organizations must immediately prioritize patching these edge and enterprise assets to block active intrusion and persistence campaigns. |
|
■ CRITICAL STORIES Critical VMware vCenter RCE flaw exploited for reverse SSH access Threat actors are actively exploiting CVE-2026-59310 in VMware vCenter Syslog Server to drop reverse SSH tools, establishing persistent remote access inside target networks. |
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A newly disclosed zero-day exploit allows local users to escalate privileges to SYSTEM, severely undermining Windows endpoint security. |
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt Akira ransomware affiliates are bypassing endpoint detection and response (EDR) agents by forcing systems to reboot into Safe Mode with Networking, highlighting a critical gap in endpoint defense strategies. |
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Active exploitation of CVE-2026-55040 began immediately following the public release of a proof-of-concept, putting unpatched SharePoint servers at immediate risk. |
|
■ CVEs IDENTIFIED CVE-2026-59310 VMware vCenter Server — Directory traversal leading to Remote Code Execution (RCE) and reverse SSH backdoor deployment |
CVE-2026-71362 Adobe Commerce — Remote Code Execution vulnerability targeted immediately after public disclosure |
CVE-2026-55040 Microsoft SharePoint — Authentication bypass vulnerability exploited in the wild following PoC release |
[CVE-TBD] Microsoft Windows (ShieldBreak) — Zero-day privilege escalation exploit allowing any user to spawn a shell with SYSTEM privileges |
|
■ THREAT ACTORS Akira | Ransomware Affiliate |
Disabled EDR solutions via Safe Mode with Networking to exfiltrate data |
Jewelbug | Cyber Espionage Group |
Targeted government and military webmail while running parallel cryptocurrency fraud |
Nightmare Eclipse | Threat Group |
Released the 'ShieldBreak' Windows zero-day exploit for SYSTEM privilege escalation |
|
|
|
■ ATT&CK TTPs | T1562.001 | | Impair Defenses: Disable or Modify Tools | Akira ransomware forced system reboots into Safe Mode to disable EDR agents |
| T1212 | | Exploitation for Credential Access | Mirai variant sniffs network traffic for default access credentials |
| T1068 | | Exploitation for Privilege Escalation | ShieldBreak exploit used to escalate local user privileges to SYSTEM on Windows |
| T1133 | | External Remote Services | Attackers deployed reverse SSH tools on VMware vCenter for persistent remote access |
| T1204.002 | | User Execution: Malicious File | WordPress RCE triggered via malicious Postscript files |
| T1021.004 | | Remote Services: SSH | Attackers established reverse SSH tunnels on compromised vCenter servers |
|
■ PATCH PRIORITY VMware — vCenter Server (CVE-2026-59310) — Active exploitation of RCE to deploy reverse SSH backdoors — BleepingComputer |
Microsoft — SharePoint (CVE-2026-55040) — Active exploitation of authentication bypass following PoC release — The Hacker News |
Adobe — Commerce (CVE-2026-71362) — RCE vulnerability targeted immediately after disclosure — SecurityWeek |
Microsoft — Windows (ShieldBreak / LegacyHive) — Zero-day exploits allowing SYSTEM privilege escalation and unauthorized access — SecurityWeek / BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch VMware vCenter immediately to address CVE-2026-59310 to block active directory traversal and reverse SSH backdoor deployment. |
| 2 | [P1] Apply Microsoft security updates for SharePoint (CVE-2026-55040) and Windows (ShieldBreak and LegacyHive zero-days) to prevent authentication bypass and SYSTEM privilege escalation. |
| 3 | [P1] Update Adobe Commerce immediately to remediate CVE-2026-71362 due to active exploitation in the wild. |
| 4 | [P1] Apply Fortinet patches for FortiWeb and FortiManager to resolve critical authentication bypass and appliance impersonation vulnerabilities. |
| 5 | [P2] Update WordPress installations to version 7.0.4 or higher to mitigate Postscript-based RCE. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |