Daily Security Intel

Archives
Log in
Subscribe
August 15, 2026

[SecurityIntel] 15 Aug | SAP Commerce Cloud and GeoServer Under Active Exploitation

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, August 15, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

SAP Commerce Cloud and GeoServer Under Active Exploitation

CRITICAL

5

C2 IPs

83

OTX IOCs

21

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities dominates today's threat landscape, highlighted by a maximum-severity RCE in SAP Commerce Cloud and an unpatched SQL injection zero-day in OSGeo GeoServer. Additionally, macOS systems are being targeted via a Screen Sharing authentication bypass to deploy cryptocurrency miners, while major data breaches impact RingCentral, Trezor, and Beacon CRM. Organizations must prioritize patching public-facing systems and auditing cloud access credentials.

■ CRITICAL STORIES

CRITICAL#1

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being actively targeted by threat actors just three days after a patch was released, necessitating immediate remediation.

CRITICAL#2

Hackers Exploiting Unpatched GeoServer Zero-Day

Attackers are actively exploiting an unpatched SQL injection vulnerability in OSGeo GeoServer that allows remote code execution, posing an immediate threat to organizations running the software.

HIGH#3

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

A public exploit for a macOS Screen Sharing authentication bypass is being actively leveraged in the wild to compromise systems and install Monero cryptocurrency miners.

HIGH#4

Over 1,000 Charities Hit by Beacon CRM Data Breach

A compromised AWS access key exposed in public JavaScript build artifacts led to a major data breach affecting over 1,000 charities using Beacon CRM, highlighting the severe risk of credential leakage in development pipelines.

■ CVEs IDENTIFIED

[CVE-TBD]

SAP Commerce Cloud — Remote Code Execution (RCE)

Critical

[CVE-TBD]

OSGeo GeoServer — SQL Injection leading to Remote Code Execution (RCE)

Critical

[CVE-TBD]

Apple macOS Screen Sharing — Authentication Bypass leading to Monero miner deployment

High

[CVE-TBD]

Commerzbank Service Provider — Security flaw allowing unauthorized withdrawals

High

■ THREAT ACTORS

Clop

Ransomware Group

Claimed data theft of 89GB from Shell.

ShinyHunters

Cybercrime/Extortion Group

Stole and published data of 1.6 million RingCentral accounts.

North Korean IT Workers

State-Sponsored

Breached an unnamed federal agency.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of SAP Commerce Cloud and GeoServer vulnerabilities.
T1068
Exploitation for Privilege Escalation | Authentication bypass in macOS Screen Sharing.
T1528
Steal Application Access Token | Stolen OAuth tokens used to access Google Workspace (Gmail, Drive).
T1496
Resource Hijacking | Deployment of Monero miners on compromised macOS systems.
T1552.005
Credentials in Files | AWS access keys exposed in public JavaScript build artifacts.
T1539
Steal Web Session Information | AmnesiaStealer harvesting Safari cookies and browser sessions.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

SAP — Commerce Cloud — Active exploitation of maximum-severity RCE vulnerability — [BC] Max severity SAP Commerce Cloud flaw now targeted in attacks

[P1 PATCH NOW]≤24h

OSGeo — GeoServer — Active exploitation of unpatched SQL injection zero-day leading to RCE — [SW] Hackers Exploiting Unpatched GeoServer Zero-Day

[P2 PATCH NOW]≤72h

Apple — macOS Screen Sharing — Active exploitation of authentication bypass to deploy Monero miners — [BC] Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch SAP Commerce Cloud immediately to mitigate the actively exploited maximum-severity RCE vulnerability ([CVE-TBD]).
2[P1] Apply security updates or workarounds for OSGeo GeoServer to prevent exploitation of the unpatched SQL injection zero-day ([CVE-TBD]).
3[P1] Update macOS systems immediately to patch the Screen Sharing authentication bypass vulnerability ([CVE-TBD]) currently exploited to deploy Monero miners.
4[P2] Audit Google Workspace OAuth token grants and implement strict conditional access policies to block unauthorized session hijacking.
5[P2] Scan public code repositories and JavaScript build artifacts for exposed AWS access keys, particularly for Beacon CRM and cloud integrations.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 16 Aug | Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays Older → [SecurityIntel] 14 Aug | Active VMware and Windows Zero-Day Exploitations Surge
Powered by Buttondown, the easiest way to start and grow your newsletter.