Friday, August 14, 2026 | Jonathan Brown
GeoServer’s unpatched SQL-injection flaw is already drawing hundreds of exploitation attempts
Attackers are already probing an unpatched vulnerability in GeoServer only hours after its public disclosure. SecurityWeek reported Friday that watchTowr has recorded hundreds of exploitation attempts from a relatively small number of source IP addresses. The flaw had no CVE identifier or vendor patch at the time of this briefing.
The vulnerability affects GeoServer’s jsonArrayContains filter function and permits SQL injection in relevant database-backed configurations, including PostGIS and Oracle JDBC data stores. Remote code execution appears possible under some configurations, but that condition should not be generalized to every GeoServer installation. Most importantly, watchTowr says the traffic observed so far has consisted largely of probing: researchers had not observed follow-on activity demonstrating successful compromise.
That distinction also means the flaw should not yet be called a zero-day under BCG’s definition. The publicly documented exploitation attempts began after disclosure; there is currently no evidence that attackers exploited the vulnerability before it became public.
Until OSGeo provides remediation, defenders should identify externally reachable GeoServer installations and restrict exposure wherever operationally possible. Review application and database logs for suspicious use of jsonArrayContains, preserve telemetry from systems receiving exploitation attempts, and investigate unexpected database-spawned processes or outbound connections. Internet exposure is the immediate control variable.
Watch for: An OSGeo advisory and patch, a CVE assignment, confirmed post-exploitation activity, or evidence of exploitation before public disclosure.
Sources: SecurityWeek, “Hackers Exploiting Unpatched GeoServer Zero-Day,” August 14, 2026; watchTowr exploitation telemetry cited by SecurityWeek, August 14, 2026.
VMware vCenter exploitation turns a July patch into an incident-response priority
A critical VMware vCenter vulnerability patched by Broadcom on July 29 is now being exploited in the wild. CVE-2026-59310 is a directory-traversal vulnerability in the vCenter Syslog server that Broadcom rates at CVSS 9.8. An attacker with network access to a vulnerable vCenter instance can exploit the flaw to execute arbitrary code without first authenticating.
Quirso reported exploitation beginning August 3, only five days after disclosure. Its investigation identified compromise associated with 361 IP addresses across 47 countries and observed attackers deploying the open-source reverse_ssh framework for persistent remote access. That gives the attacker an outbound reverse channel rather than requiring continued inbound connectivity. The numbers represent observed IP addresses, not necessarily 361 distinct organizations.
Broadcom’s currently supported fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f, depending on the deployed branch. Broadcom’s August 3 revision specifically added the U2f express patch. No workaround is listed.
For organizations whose vCenter management plane was reachable from untrusted networks before remediation, installing the update should not close the incident. Hunt for unauthorized binaries, abnormal process execution by vCenter services, unexpected outbound encrypted connections, persistence artifacts and evidence of reverse_ssh. A compromised vCenter can provide leverage over virtual machines, ESXi hosts, access controls and configuration across a substantial portion of an enterprise estate.
Watch for: Broadcom or government confirmation of the exploitation campaign, additional post-compromise tooling, or evidence that operators are concentrating on particular industries or countries.
Sources: Broadcom, VMSA-2026-0006.1, updated August 3, 2026; Quirso, CVE-2026-59310 exploitation analysis, August 2026; BleepingComputer, “Critical VMware vCenter RCE flaw exploited for reverse SSH access,” August 13, 2026.
Cl0p names nearly 50 companies as investigators focus on Windchill and FlexPLM
Cl0p has claimed data theft from nearly 50 organizations worldwide, including Shell, Philips, Fiserv and GE. Reuters reported Thursday that Philips confirmed an attempted compromise involving an enterprise server containing internal data; Shell acknowledged a possible incident and opened an investigation; GE activated its cyber-response process; and Fiserv said its review had found no evidence that customer, banking, transaction or personal information, or its operating environment, had been affected. Reuters could not independently verify Cl0p’s broader theft claims.
The important technical connection is PTC’s Windchill and FlexPLM environment. Ransom-ISAC warned on July 22 that Cl0p was exploiting vulnerabilities affecting those products, while PTC has been responding since June to hostile activity involving CVE-2026-12569, an unauthorized remote-code-execution vulnerability. But the initial-access mechanism for every newly named company has not been independently established, so CVE-2026-12569 should not be presented as the confirmed entry point for every Cl0p claim.
PTC’s own incident guidance makes the post-compromise requirement unusually clear. The company has published malicious JSP web-shell paths, command-and-control infrastructure, a suspicious request header and patterns for identifying additional dynamically named web shells. PTC specifically advises customers to search historical HTTP logs for suspicious POST requests under /Windchill/login/, inspect the filesystem for unexpected JSP files and look beyond the exact filenames already published.
Operators should therefore treat exposure during the exploitation period as an investigation question, not merely a patch-status question. Remediation closes the vulnerability; it does not remove a web shell or another foothold established before patching.
Watch for: Additional victim confirmations and forensic evidence establishing whether the newly claimed Cl0p compromises stem from the Windchill/FlexPLM campaign or another access path.
Sources: Reuters, “Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others,” August 13, 2026; PTC Trust Center, “Critical Vulnerability in Windchill and FlexPLM,” updated through July 27, 2026; Ransom-ISAC warning, July 22, 2026.
France confirms taxpayer data was stolen from its national tax administration
France’s Finance Ministry disclosed late Thursday that attackers stole data belonging to individual and professional taxpayers from the General Directorate of Public Finances, or DGFiP. A malicious actor claimed on Wednesday to have breached the agency in late June, and the ministry says its investigation has confirmed unauthorized consultation and extraction of taxpayer data.
The government has not yet established publicly which specific data fields were accessed or exactly how many taxpayers are affected. FrenchBreaches, a French breach-tracking platform, reported that data relating to close to 700,000 taxpayers had been stolen, citing information obtained from the alleged hackers. The ministry had not confirmed that figure when Reuters published Friday morning.
No initial-access method or responsible threat actor has been publicly established. There is likewise no basis yet to assume that passwords, financial credentials or particular identity documents were included. That precision matters because downstream defensive actions should follow the data actually confirmed compromised rather than an assumed worst-case dataset.
The ministry says affected users will receive individual notifications identifying information that may have been consulted or extracted and, where applicable, precautions to take. Organizations handling French tax and corporate information should anticipate credible impersonation attempts using genuine contextual information if the stolen dataset proves sufficiently detailed.
Watch for: The government’s confirmed victim count, the specific data categories stolen, disclosure of the initial-access mechanism and evidence establishing whether the motive was espionage, fraud or another objective.
Sources: French Finance Ministry statement, August 13, 2026, as reported by Reuters; Reuters, “French taxpayers’ data stolen in cyber attack, French Finance Ministry says,” August 14, 2026.
Taiwan confirms an AI-assisted government attack as researchers document expansion into nuclear and energy targets
Taiwan’s Ministry of Digital Affairs confirmed Thursday that overseas attackers used a combination of human-directed operations and AI agents against government systems during July. Taiwan’s National Institute of Cyber Security began issuing warnings on July 20, and the ministry says the affected agencies have completed response actions and strengthened monitoring. Taiwan’s statement did not attribute the activity to China.
Research from Israeli cybersecurity company Dream describes a substantially broader operation. According to Dream’s findings, reported by the Financial Times, attackers deployed as many as eight AI agents in parallel during a four-day operation in early July. The system mapped 21 government systems, compromised at least 85 government user accounts, extracted more than 2,500 personnel records, and subsequently expanded its activity to Taiwan’s nuclear safety agency and at least seven energy companies. Those scope figures are Dream’s findings; they should not be represented as figures independently confirmed in Taiwan’s public government statement.
Dream found that the operation used open-source agent frameworks including Hermes and OpenClaw. The agents performed reconnaissance, researched vulnerabilities, tested attack paths and reprioritized tactics when earlier approaches failed. Researchers could not determine which underlying AI model powered the system. The operation therefore appears to demonstrate meaningful automation of intrusion work, but not an independent machine selecting its own geopolitical target or strategic objective.
Attribution also remains unresolved. Dream did not name a threat group. Simplified Chinese appeared in internal operational material, leading researchers to assess a likely Chinese connection, but Taiwan itself has not publicly attributed the campaign. Language evidence is relevant intelligence; it is not sufficient by itself for confident state attribution.
The expansion toward nuclear-safety and energy organizations makes the campaign considerably more important than a demonstration of AI-enabled reconnaissance. Defenders should examine bursts of parallel scanning, authentication attempts and API activity across multiple systems; correlate apparently independent probes that converge on the same identities or infrastructure; and reduce unnecessary permissions for exposed administrative, automation and API interfaces. AI changes the speed and breadth of reconnaissance, but access control, segmentation and strong authentication still interrupt the underlying attack paths.
Watch for: Forensic evidence connecting the nuclear and energy activity to successful compromise, identification of the underlying AI model, or government-backed attribution based on infrastructure, malware, intelligence or operator evidence.
Sources: Taiwan Ministry of Digital Affairs statement, August 13, 2026; Financial Times, “China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack,” August 12, 2026; The Guardian, “Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack,” August 13, 2026; Dream research, August 2026.
PATCHCORD pushes suspected Transparent Tribe espionage deeper into Afghan telecom and South Asian infrastructure
Acronis Threat Research Unit disclosed Thursday an ongoing espionage campaign deploying previously undocumented malware against Afghan telecommunications providers and other government, defense, energy and critical-infrastructure organizations in South Asia. The principal implant, PATCHCORD, is a compiled C/C++ backdoor delivered through highly tailored material including fake Afghan Telecom VPN installers and telecommunications-management software.
Infrastructure analysis led Acronis to two additional malware families. SHEETCORD is a Go-based implant that abuses Google Sheets for command and control, while investigators also identified a HACKERAI C2 Agent. An exposed staging server contained remote-access frameworks, credential-harvesting tools and exploit tooling, and campaign infrastructure included domains impersonating India’s National Informatics Centre.
The legitimate-cloud-service abuse is operationally important because command traffic can blend into Google or GitHub activity routinely permitted through enterprise networks. Telecom providers are particularly valuable espionage targets because compromise can expose subscriber information, communications infrastructure and government traffic far beyond a single workstation.
Acronis assesses with moderate confidence that the campaign overlaps with APT36, also known as Transparent Tribe, based on targeting, malware similarities, infrastructure and operational tradecraft. That remains an analytic assessment rather than confirmed attribution.
Telecom and government defenders in the region should hunt the published indicators, investigate unauthorized VPN or telecom-management installers, and scrutinize unexpected Google Sheets or GitHub Gist traffic from servers and administrative systems that have no legitimate need to use those services.
Watch for: Independent attribution, additional telecom victims, or evidence that the campaign has progressed from endpoint espionage into carrier, subscriber or communications-management systems.
Sources: Acronis Threat Research Unit, “PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure,” August 13, 2026.
Evooo1Bot turns compromised edge devices into network pivots, not merely DDoS bots
FortiGuard Labs disclosed Thursday that a previously undocumented Linux botnet called Evooo1Bot has been actively targeting internet-facing equipment since July. Fortinet observed exploitation attempts against known vulnerabilities affecting devices from vendors including Alcatel, Netgear, Tenda, Mitsubishi Electric, Telesquare and D-Link, with payload callbacks converging on common loader infrastructure.
Evooo1Bot inherits Mirai-derived distributed-denial-of-service capability but adds encrypted command and control, SSH brute forcing, credential sniffing, interactive shells, file transfer, persistence and an integrated exploit dispatcher. Fortinet’s telemetry demonstrates active exploitation attempts against exposed devices, although it does not establish a global count of successful infections.
The most consequential addition is an integrated SOCKS5 relay. In reverse-relay mode, an infected device creates an outbound encrypted connection to attacker infrastructure and can subsequently proxy arbitrary sessions. That can transform an edge appliance from a DDoS node into a network pivot or anonymized attack platform, potentially allowing operators to reach systems accessible from the compromised device while avoiding reliance on inbound connectivity.
Fortinet identified 91.92.40[.]118 as loader infrastructure in observed exploitation traffic. Edge-device operators should patch the known vulnerabilities Fortinet lists, retire unsupported devices where possible, investigate callbacks to the published infrastructure, and look for unexplained systemd, init, cron or shell-profile persistence. Persistent outbound encrypted sessions or unexpected SOCKS functionality on an appliance should be treated as compromise evidence.
Watch for: Expansion to additional edge-product vulnerabilities or evidence that operators are systematically using infected devices as pivots into enterprise or operational networks.
Sources: FortiGuard Labs, “Multi-Functional Linux Botnet ‘Evooo1Bot’,” August 13, 2026.
CISA warns that a Haiwell HMI gateway flaw can execute commands as root
CISA published an industrial-control-system advisory Thursday for CVE-2026-19188 affecting Haiwell IoT Cloud HMI Gateway 3.40.1.12. Successful exploitation can inject arbitrary operating-system commands that execute with root privileges, and the vulnerability carries a CVSS score of 10.
The affected device sits at a sensitive boundary between remote management and operational technology. A root-level compromise of an HMI gateway may expose credentials, connected controllers, engineering services or adjacent management infrastructure depending on how the device has been integrated. That makes network placement and surrounding trust relationships as important as the nominal vulnerability score.
CISA’s publication is a vulnerability advisory, however, not evidence that the flaw is being exploited in the wild. No exploitation claim should be inferred from the CVSS rating alone.
Operators should identify affected gateways, remove unnecessary direct internet exposure and port forwarding, require tightly controlled remote-access paths, and segment the gateway from wider enterprise and OT networks. Internet-exposed systems should be reviewed for unexplained command execution, account or configuration changes and abnormal outbound communications while operators follow Haiwell and CISA remediation guidance.
Watch for: Public exploit code, confirmed exploitation, a CISA Known Exploited Vulnerabilities addition or vendor clarification of the complete affected and remediated version range.
Sources: CISA, “Haiwell IoT Cloud HMI Gateway,” ICSA-26-225-02, August 13, 2026.
Fortinet patches authentication weaknesses whose real risk depends on configuration
Fortinet disclosed fixes Wednesday for authentication vulnerabilities in FortiWeb and FortiManager. CVE-2026-26035 affects FortiWeb when a Remote, RADIUS-type administrator account has the Wildcard option enabled. That option is not the normal condition for every installation. Where the vulnerable configuration exists, a remote unauthenticated attacker can authenticate to the FortiWeb GUI or CLI with an arbitrary username and password.
Fortinet fixes the flaw in FortiWeb 8.0.3, 7.6.7, 7.4.12 and 7.2.13 or later releases on the respective branches. Administrators unable to update immediately can disable the Wildcard option on affected Remote administrator accounts.
CVE-2026-70468 in FortiManager and FortiManager Cloud presents a different authentication problem. Under the vulnerable CLI configuration, an attacker possessing a valid certificate may be able to impersonate a FortiGate device managed by FortiManager. Again, the prerequisites matter: this is not equivalent to an unauthenticated takeover of every FortiManager installation.
Public reporting reviewed for this briefing does not establish active exploitation of either flaw. Defenders should first determine whether the vulnerable configurations are present, patch the applicable branch and then examine relevant administrative sessions, device registrations, certificates and FortiGate management identities for anomalies.
Watch for: Public proof-of-concept code, exploitation telemetry or evidence that attackers are actively enumerating installations with the required configurations.
Sources: Fortinet PSIRT FG-IR-26-158, CVE-2026-26035, August 12, 2026; Fortinet PSIRT FG-IR-26-160, CVE-2026-70468, August 12, 2026.
The White House creates a federally controlled offensive-cyber role for private companies
A presidential memorandum signed August 12 directs the U.S. government to establish a program allowing vetted American companies to conduct cyber-surveillance and cyber-effects operations against foreign cyber-enabled transnational criminal organizations. The National Coordination Center will administer the program under joint Department of Justice and Department of Homeland Security oversight.
The memorandum is unusually explicit about what “cyber effects” may include: manipulation, disruption, denial, degradation or destruction of information systems, networks, infrastructure and information. Participating firms must act under federal direction and legal authority, enter contractual agreements, undergo vetting and receive written approval and direction for each operations package before taking action. The government may also require a bond or escrow of at least $1 million.
This is therefore not a general authorization for American companies to hack back independently. Operations remain under federal control. Activities likely to cause death or serious injury, or rise to the level of use of force or armed attack under international law, are classified as “Critical Outcomes” and fall outside the ordinary approval authority established by the program. Participating companies must also stop and report operations that unintentionally exceed approved targeting boundaries.
The memorandum also reveals a difficult attribution boundary. Eligible targets must be foreign cyber-enabled criminal organizations that are not institutional components of foreign governments or wholly operated under foreign-government direction. Yet ransomware, intrusion and fraud ecosystems frequently overlap with tolerated, protected or intelligence-linked operators. Determining where criminal activity ends and state direction begins may therefore become one of the program’s hardest operational problems.
For threat-intelligence teams, the immediate change is institutional rather than tactical. Private-sector telemetry and capability can now feed into a framework designed not merely to identify adversary infrastructure but, after government adjudication, potentially to disrupt or degrade it.
Watch for: The operating procedures due within 60 days, the companies admitted to the program, the first publicly acknowledged operations and how the government handles attribution, third-party infrastructure and state-linked criminal organizations.
Sources: White House, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” Presidential Memorandum, August 12, 2026; White House fact sheet, August 12, 2026.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: