Daily Security Intel

Archives
Log in
Subscribe
August 18, 2026

[SecurityIntel] 18 Aug | Active Exploitation of macOS Screen Sharing Vulnerability

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, August 18, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Exploitation of macOS Screen Sharing Vulnerability

CRITICAL

5

C2 IPs

41

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by active exploitation of a macOS Screen Sharing vulnerability to deploy cryptominers and the rapid weaponization of a critical SAP Commerce Cloud vulnerability (CVE-2026-58231) just three days after disclosure. Additionally, a zero-day vulnerability in Microsoft Defender, dubbed ShieldBreak (CVE-2026-69414), bypasses previous patches to grant local attackers SYSTEM privileges. Organizations must also secure Active Directory Certificate Services against CVE-2026-54121 (Certighost) to prevent domain escalation by standard users.

■ CRITICAL STORIES

CRITICAL#1

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Attackers are actively exploiting CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud, to execute arbitrary code and compromise internal components. This rapid weaponization underscores the urgency of patching enterprise cloud environments immediately.

CRITICAL#2

Microsoft Working on Defender Patch for ShieldBreak Zero-Day

A newly disclosed zero-day vulnerability tracked as CVE-2026-69414 (ShieldBreak) allows attackers to bypass Microsoft's previous patch for a Defender flaw and escalate privileges to SYSTEM. Microsoft is currently working on a patch, leaving systems temporarily exposed to local privilege escalation.

HIGH#3

Certighost Flaw Allows Domain Controller Takeover via Certificate Authority

Tracked as CVE-2026-54121, the Certighost vulnerability allows a standard domain user to escalate privileges and turn an Enterprise Certificate Authority (CA) into a Domain Controller, highlighting critical risks in PKI identity infrastructure.

HIGH#4

Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access

Security researchers have disclosed a zero-click, two-stage exploit chain impacting Unisoc modem firmware via VoLTE video calls. The vulnerability allows full Android kernel access, and currently has no fix from the chipset vendor.

■ CVEs IDENTIFIED

CVE-2026-58231

SAP Commerce Cloud — Remote Code Execution

Critical

CVE-2026-69414

Microsoft Defender — Local Privilege Escalation (ShieldBreak)

Critical

CVE-2026-54121

Active Directory Certificate Services (Certighost) — Privilege Escalation to Domain Controller

High

[CVE-TBD]

Apple macOS Screen Sharing — Root Access and Cryptomining Execution

High

■ THREAT ACTORS

Cavern (Cav3rn)

APT

Iranian nation-state group targeting Israeli entities using DNS and Google Apps Script for C2.

Clop

Ransomware

Cybercrime group claiming data theft from tech giants Philips and General Electric.

Evooo1Bot

Botnet

Mirai-derived Linux botnet exploiting known vulnerabilities to turn edge devices into SOCKS5 proxies.

■ ATT&CK TTPs

T1133
External Remote Services | Apple Screen Sharing (VNC) used to gain initial access.
T1219
Remote Access Software | Screen sharing exploitation.
T1059.006
Command and Scripting Interpreter: Python/PHP | Forminator plugin exploited for malicious PHP uploads.
T1584.005
Compromise Infrastructure: Botnet | Evooo1Bot recruiting edge devices.
T1071.004
Application Layer Protocol: DNS | Cavern C2 using DNS tunneling.
T1484
Domain Policy Modification | Certighost CVE-2026-54121 used to turn Enterprise CA into Domain Controller.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

SAP — Commerce Cloud — CVE-2026-58231 is actively exploited in the wild for remote code execution — SecurityWeek

[P1 PATCH NOW]≤24h

Apple — macOS — Screen Sharing vulnerability is actively exploited to gain root access and deploy cryptominers — Malwarebytes

[P1 PATCH NOW]≤24h

GitLab — GitLab CE/EE — Unauthenticated GraphQL flaw allows remote deletion of public projects — The Hacker News

[P1 PATCH NOW]≤24h

WPMU DEV — Forminator WordPress Plugin — Critical flaw allows unauthenticated RCE via malicious PHP uploads — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch SAP Commerce Cloud immediately to resolve CVE-2026-58231 and prevent active exploitation.
2[P1] Apply the latest Apple macOS and iOS security updates to patch the actively exploited Screen Sharing vulnerability.
3[P1] Update GitLab CE/EE instances to the latest security release to mitigate the critical unauthenticated GraphQL project deletion vulnerability.
4[P1] Update the Forminator WordPress plugin to the latest version to prevent unauthenticated arbitrary PHP code execution.
5[P2] Implement restrictive access controls and monitor Active Directory Certificate Services (PKI) to defend against Certighost (CVE-2026-54121) exploitation.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 17 Aug | AmnesiaStealer macOS Malware Hijacks Browser Sessions
Powered by Buttondown, the easiest way to start and grow your newsletter.