SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, August 18, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Exploitation of macOS Screen Sharing Vulnerability | CRITICAL |
|
5 C2 IPs | 41 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation of a macOS Screen Sharing vulnerability to deploy cryptominers and the rapid weaponization of a critical SAP Commerce Cloud vulnerability (CVE-2026-58231) just three days after disclosure. Additionally, a zero-day vulnerability in Microsoft Defender, dubbed ShieldBreak (CVE-2026-69414), bypasses previous patches to grant local attackers SYSTEM privileges. Organizations must also secure Active Directory Certificate Services against CVE-2026-54121 (Certighost) to prevent domain escalation by standard users. |
|
■ CRITICAL STORIES Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Attackers are actively exploiting CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud, to execute arbitrary code and compromise internal components. This rapid weaponization underscores the urgency of patching enterprise cloud environments immediately. |
Microsoft Working on Defender Patch for ShieldBreak Zero-Day A newly disclosed zero-day vulnerability tracked as CVE-2026-69414 (ShieldBreak) allows attackers to bypass Microsoft's previous patch for a Defender flaw and escalate privileges to SYSTEM. Microsoft is currently working on a patch, leaving systems temporarily exposed to local privilege escalation. |
Certighost Flaw Allows Domain Controller Takeover via Certificate Authority Tracked as CVE-2026-54121, the Certighost vulnerability allows a standard domain user to escalate privileges and turn an Enterprise Certificate Authority (CA) into a Domain Controller, highlighting critical risks in PKI identity infrastructure. |
Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access Security researchers have disclosed a zero-click, two-stage exploit chain impacting Unisoc modem firmware via VoLTE video calls. The vulnerability allows full Android kernel access, and currently has no fix from the chipset vendor. |
|
■ CVEs IDENTIFIED CVE-2026-58231 SAP Commerce Cloud — Remote Code Execution |
CVE-2026-69414 Microsoft Defender — Local Privilege Escalation (ShieldBreak) |
CVE-2026-54121 Active Directory Certificate Services (Certighost) — Privilege Escalation to Domain Controller |
[CVE-TBD] Apple macOS Screen Sharing — Root Access and Cryptomining Execution |
|
■ THREAT ACTORS Iranian nation-state group targeting Israeli entities using DNS and Google Apps Script for C2. |
Cybercrime group claiming data theft from tech giants Philips and General Electric. |
Mirai-derived Linux botnet exploiting known vulnerabilities to turn edge devices into SOCKS5 proxies. |
|
|
|
■ ATT&CK TTPs | T1133 | | External Remote Services | Apple Screen Sharing (VNC) used to gain initial access. |
| T1219 | | Remote Access Software | Screen sharing exploitation. |
| T1059.006 | | Command and Scripting Interpreter: Python/PHP | Forminator plugin exploited for malicious PHP uploads. |
| T1584.005 | | Compromise Infrastructure: Botnet | Evooo1Bot recruiting edge devices. |
| T1071.004 | | Application Layer Protocol: DNS | Cavern C2 using DNS tunneling. |
| T1484 | | Domain Policy Modification | Certighost CVE-2026-54121 used to turn Enterprise CA into Domain Controller. |
|
■ PATCH PRIORITY SAP — Commerce Cloud — CVE-2026-58231 is actively exploited in the wild for remote code execution — SecurityWeek |
Apple — macOS — Screen Sharing vulnerability is actively exploited to gain root access and deploy cryptominers — Malwarebytes |
GitLab — GitLab CE/EE — Unauthenticated GraphQL flaw allows remote deletion of public projects — The Hacker News |
WPMU DEV — Forminator WordPress Plugin — Critical flaw allows unauthenticated RCE via malicious PHP uploads — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch SAP Commerce Cloud immediately to resolve CVE-2026-58231 and prevent active exploitation. |
| 2 | [P1] Apply the latest Apple macOS and iOS security updates to patch the actively exploited Screen Sharing vulnerability. |
| 3 | [P1] Update GitLab CE/EE instances to the latest security release to mitigate the critical unauthenticated GraphQL project deletion vulnerability. |
| 4 | [P1] Update the Forminator WordPress plugin to the latest version to prevent unauthenticated arbitrary PHP code execution. |
| 5 | [P2] Implement restrictive access controls and monitor Active Directory Certificate Services (PKI) to defend against Certighost (CVE-2026-54121) exploitation. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |