SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, August 15, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY SAP Commerce Cloud and GeoServer Under Active Exploitation | CRITICAL |
|
5 C2 IPs | 83 OTX IOCs | 21 ARTICLES |
|
■ ANALYST TLDR Active exploitation of critical vulnerabilities dominates today's threat landscape, highlighted by a maximum-severity RCE in SAP Commerce Cloud and an unpatched SQL injection zero-day in OSGeo GeoServer. Additionally, macOS systems are being targeted via a Screen Sharing authentication bypass to deploy cryptocurrency miners, while major data breaches impact RingCentral, Trezor, and Beacon CRM. Organizations must prioritize patching public-facing systems and auditing cloud access credentials. |
|
■ CRITICAL STORIES Max severity SAP Commerce Cloud flaw now targeted in attacks A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being actively targeted by threat actors just three days after a patch was released, necessitating immediate remediation. |
Hackers Exploiting Unpatched GeoServer Zero-Day Attackers are actively exploiting an unpatched SQL injection vulnerability in OSGeo GeoServer that allows remote code execution, posing an immediate threat to organizations running the software. |
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner A public exploit for a macOS Screen Sharing authentication bypass is being actively leveraged in the wild to compromise systems and install Monero cryptocurrency miners. |
Over 1,000 Charities Hit by Beacon CRM Data Breach A compromised AWS access key exposed in public JavaScript build artifacts led to a major data breach affecting over 1,000 charities using Beacon CRM, highlighting the severe risk of credential leakage in development pipelines. |
|
■ CVEs IDENTIFIED [CVE-TBD] SAP Commerce Cloud — Remote Code Execution (RCE) |
[CVE-TBD] OSGeo GeoServer — SQL Injection leading to Remote Code Execution (RCE) |
[CVE-TBD] Apple macOS Screen Sharing — Authentication Bypass leading to Monero miner deployment |
[CVE-TBD] Commerzbank Service Provider — Security flaw allowing unauthorized withdrawals |
|
■ THREAT ACTORS Claimed data theft of 89GB from Shell. |
ShinyHunters | Cybercrime/Extortion Group |
Stole and published data of 1.6 million RingCentral accounts. |
North Korean IT Workers | State-Sponsored |
Breached an unnamed federal agency. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of SAP Commerce Cloud and GeoServer vulnerabilities. |
| T1068 | | Exploitation for Privilege Escalation | Authentication bypass in macOS Screen Sharing. |
| T1528 | | Steal Application Access Token | Stolen OAuth tokens used to access Google Workspace (Gmail, Drive). |
| T1496 | | Resource Hijacking | Deployment of Monero miners on compromised macOS systems. |
| T1552.005 | | Credentials in Files | AWS access keys exposed in public JavaScript build artifacts. |
| T1539 | | Steal Web Session Information | AmnesiaStealer harvesting Safari cookies and browser sessions. |
|
■ PATCH PRIORITY SAP — Commerce Cloud — Active exploitation of maximum-severity RCE vulnerability — [BC] Max severity SAP Commerce Cloud flaw now targeted in attacks |
OSGeo — GeoServer — Active exploitation of unpatched SQL injection zero-day leading to RCE — [SW] Hackers Exploiting Unpatched GeoServer Zero-Day |
Apple — macOS Screen Sharing — Active exploitation of authentication bypass to deploy Monero miners — [BC] Hackers exploit macOS Screen Sharing flaw to deploy Monero miner |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch SAP Commerce Cloud immediately to mitigate the actively exploited maximum-severity RCE vulnerability ([CVE-TBD]). |
| 2 | [P1] Apply security updates or workarounds for OSGeo GeoServer to prevent exploitation of the unpatched SQL injection zero-day ([CVE-TBD]). |
| 3 | [P1] Update macOS systems immediately to patch the Screen Sharing authentication bypass vulnerability ([CVE-TBD]) currently exploited to deploy Monero miners. |
| 4 | [P2] Audit Google Workspace OAuth token grants and implement strict conditional access policies to block unauthorized session hijacking. |
| 5 | [P2] Scan public code repositories and JavaScript build artifacts for exposed AWS access keys, particularly for Beacon CRM and cloud integrations. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |