Tuesday, August 18, 2026 | Jonathan Brown


CISA flags active exploitation of a browser-to-Ray remote-code path

CISA on August 17 added CVE-2025-62593 in the Ray distributed-computing framework to its Known Exploited Vulnerabilities catalog, establishing that the flaw has been used in real attacks. The vulnerability affects Ray versions before 2.52.0 and can permit arbitrary code execution against development systems and network-adjacent Ray instances. CISA has not disclosed the observed intrusions, victims, or how attackers are exploiting the flaw in practice.

The published attack is unusually important for developer and AI infrastructure because an internet-facing Ray service is not necessarily required. The original GitHub advisory demonstrates a DNS-rebinding attack in Firefox and Safari that can turn a developer's browser into a conduit to the Ray Jobs API. A malicious site or advertisement can therefore reach a Ray service on localhost or elsewhere inside a private network and submit code through inadequately protected endpoints. A complete public proof of concept has existed since the November 2025 disclosure.

Ray 2.52.0 fixes the vulnerability and introduces an authentication mechanism that is disabled by default. Defenders should update vulnerable installations, restrict Ray dashboards and Jobs APIs to explicitly authorized management paths, and determine whether authentication has actually been enabled rather than assuming the upgrade alone changed the trust model. Because CISA now confirms exploitation, exposed or developer-accessible Ray environments should also be reviewed for unexpected jobs, processes and API activity rather than treated as patch-only cases.

Watch for: Details from CISA or Ray identifying the attack path used in the observed exploitation, particularly whether attackers are using browser-based rebinding, directly reachable Ray services, or both.

Sources: CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” August 17, 2026; Ray Project GitHub Security Advisory GHSA-q279-jhrf-cc6v, November 26, 2025.

SAP Commerce Cloud exploit attempts begin only days after disclosure

Threat-intelligence organizations reported on August 17 that attackers had begun attempting to exploit CVE-2026-58231 in SAP Commerce Cloud's Data Hub Adapter only three days after SAP's August 11 disclosure. SAP rates the flaw at CVSS 10.0 and lists COM_CLOUD 2211 and 2211-JDK21 as affected. The vulnerability can be reached without authentication and can lead to arbitrary code execution and compromise of internal components.

KEV Intelligence says its sensors observed exploitation attempts, while Defused reported malicious traffic reaching honeypots on August 14. That is evidence of active attempts, not evidence that every probe resulted in compromise or that exploitation is already widespread. The attack abuses a default authentication client together with insufficient authorization and input validation.

Organizations operating the Data Hub Adapter should apply SAP Security Note 3771065 immediately and determine whether vulnerable functions were reachable from untrusted networks. Systems that were exposed during the disclosure window deserve retrospective review for unusual requests, spawned processes and access to connected SAP components. Any secrets reachable from a demonstrably compromised Commerce Cloud system should be treated as potentially exposed.

Watch for: Confirmation of successful compromises, broader exploitation telemetry, or a CISA KEV addition that would establish a stronger public picture of the campaign.

Sources: SAP, “SAP Security Patch Day – August 2026,” August 11, 2026; KEV Intelligence, “CVE-2026-58231 Exploitation Observed,” August 2026; SecurityWeek, “Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure,” August 17, 2026.

Microsoft formally tracks ShieldBreak while Defender remains exposed to a public privilege-escalation exploit

Microsoft has formally assigned CVE-2026-69414 to the Defender vulnerability known publicly as ShieldBreak and says it is developing a security update. As of August 18, no fix has been released. The vulnerability was publicly disclosed before a patch was available, but there is currently no public evidence that attackers are exploiting it in the wild.

ShieldBreak is a local privilege-escalation flaw, not a remote entry point. The public proof of concept requires an attacker who already has limited access to a Windows endpoint; successful exploitation can elevate that foothold to SYSTEM. The researcher describes ShieldBreak as a bypass of Microsoft's earlier remediation for CVE-2026-50656, although Microsoft's investigation and eventual advisory will determine the final technical relationship between the two issues.

Until Microsoft ships the fix, defenders should concentrate on the prerequisite foothold: restrict untrusted local code execution, investigate suspicious activity from user-writable locations, and monitor unusual Defender and filesystem interactions associated with privilege transitions. Disabling Defender would remove a security control while doing nothing to address the underlying problem and is not an appropriate mitigation.

Watch for: Microsoft's security update, confirmed affected engine versions, and any evidence that ShieldBreak has moved from public proof of concept into operational exploitation.

Sources: Microsoft CVE-2026-69414 security record, August 14, 2026; BleepingComputer, “Microsoft working on Defender patch for ShieldBreak zero-day,” August 17, 2026.

TWINLOOT turns Microsoft 365 into a covert command-and-control fabric

Ontinue disclosed TWINLOOT on August 18 after recovering the previously undocumented Python implant during an investigation of an active July campaign. The malware routes tasking through SharePoint Online using Microsoft Graph, interactive operator traffic through Microsoft Teams TURN infrastructure, and Graph communications through a headless instance of Microsoft Edge. Its primary command-and-control traffic therefore terminates inside trusted Microsoft infrastructure rather than conventional attacker-controlled servers.

Initial access in the investigated intrusion came through Microsoft Teams social engineering. An external actor impersonated IT support and persuaded a user to execute PowerShell that downloaded the implant. Once running, TWINLOOT can provide a reverse SOCKS5 tunnel into the victim network, execute commands and present a convincing fake Windows lock screen to harvest credentials. Ontinue also documented what it says is the first malicious in-the-wild use of an offline-forged NTUSER.MAN mandatory-profile hive for persistence without administrative privileges.

This is significant because conventional domain- or reputation-based egress controls may see SharePoint, Teams, Graph and Edge rather than obvious command infrastructure. Ontinue recommends restricting external Teams access where it is unnecessary and disabling Edge headless mode and remote debugging on standard workstations. Defenders should additionally investigate endpoints making Graph connections to SharePoint tenants outside their organization, unexpected Python runtimes in user-writable locations, and credential exposure where the fake lock-screen component executed. Ontinue has not attributed the activity to a named actor.

Watch for: Additional victims or telemetry showing whether TWINLOOT is a narrowly deployed operator tool or the beginning of broader abuse of Microsoft collaboration infrastructure as a general-purpose C2 layer.

Sources: Ontinue Cyber Defense Center, “Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure,” August 18, 2026.

GitLab patches an unauthenticated GraphQL flaw that can alter or delete public projects

GitLab issued an out-of-cycle critical security release on August 17 for CVE-2026-19478, a GraphQL vulnerability affecting self-managed Community and Enterprise Edition installations. Under certain conditions, an unauthenticated remote attacker can modify or delete public projects and user data. GitLab has not reported active exploitation.

Affected releases include GitLab 18.2 through versions before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6 and 19.2 before 19.2.4. GitLab.com and GitLab Dedicated are already patched; operators of self-managed installations need to upgrade. The same release fixes CVE-2026-19650, a separate GraphQL request-validation weakness that can allow unauthorized mutations through cross-site request forgery under conditions requiring user interaction.

The primary risk here is integrity and availability rather than a demonstrated server takeover. Public projects may include source code, release artifacts, CI/CD information and documentation that downstream users implicitly trust. Administrators should therefore patch promptly and, where exposure existed, review public-project changes, deletions and anomalous GraphQL activity against repository and backup history.

Watch for: Public exploit development or evidence of attacks against self-managed GitLab instances, which would move this from an urgent integrity vulnerability into an incident-response problem.

Sources: GitLab, “Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11,” August 17, 2026.

France's tax authority confirms credential-driven theft affecting 678,000 people and businesses

France's Directorate General of Public Finances, the DGFiP, confirmed that unauthorized access during June and July resulted in data concerning approximately 678,000 individuals and businesses being viewed or extracted. The government said on August 14 that the intrusions relied on impersonated credentials belonging to a DGFiP employee and an authorized third party. The public tax portal itself and taxpayer login credentials were not compromised.

The stolen or accessed information includes reference taxable income, family-quotient data, withholding-tax rates, corporate names and SIREN identifiers, along with some cadastral information concerning property addresses and surface areas. More importantly for defenders, the DGFiP said its initial access reviews failed to identify that data had been stolen; deeper investigation after the attacker publicly claimed access established the extraction.

That sequence is an operational warning about identity-centered intrusions. Revoking a compromised account does not establish what the account did while valid. Organizations managing privileged government, financial or third-party identities should preserve and retrospectively examine query, export and bulk-access telemetry whenever credentials are known to have been misused. France has implemented additional access restrictions and is continuing the investigation with ANSSI and other government services.

Watch for: Findings from the continuing French investigation that clarify the duration of unauthorized sessions, the exact extraction mechanisms, and whether additional records or systems were reached.

Sources: French Ministry of Economy and Finance, “Accès illégitimes au système d'information de la Direction générale des Finances publiques,” August 14, 2026; DGFiP public notice, modified August 17, 2026.

Alleged Entra tenant exports from major companies point back toward stolen identity rather than an Azure zero-day

A threat actor using the name TheHatman is offering what it claims are millions of internal employee records extracted from Microsoft Azure and Entra environments belonging to companies including McDonald's, Vodafone, Tata Consultancy Services, Kyndryl, HCL Technologies, Gap, IHG, Hexaware and Wyndham. Hudson Rock published its investigation on August 16, and reporting on August 17 put the claimed total at roughly 3.6 million records.

This should not currently be described as a Microsoft Azure breach. The actor claims compromised credentials were used, and Hudson Rock found previously stolen Azure-related credentials associated with most of the organizations, but researchers have not independently established the initial-access method or proved that those specific credentials produced the advertised datasets. TCS has also reportedly said material attributed to it appears to be several years old.

The potentially important issue is directory access at scale. Employee records, reporting structures, group membership and privileged identities can become reconnaissance for later impersonation or cloud compromise even when application data is untouched. Entra administrators should review unusual directory enumeration and Graph export activity, sign-ins from infostealer-associated sessions, token and session reuse, and access by third-party applications with broad directory permissions. Where credential theft is established, revoke sessions and refresh credentials rather than relying on password changes alone.

Watch for: Direct victim confirmations and authentication telemetry that establish how current the datasets are and whether password theft, session-cookie theft, weak multifactor authentication or delegated application permissions provided access.

Sources: Hudson Rock, “Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials,” August 16, 2026; SecurityWeek, “Fortune 500 Companies Hit in Azure Data Theft Campaign,” August 17, 2026; BleepingComputer, “Hacker claims 3.6 million Azure account records stolen from major companies,” August 17, 2026.

One operator is systematically scraping exposed Salesforce and ServiceNow guest portals

Reco has identified a long-running campaign it calls City-Forum in which one operator uses custom tooling to extract information exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. Research published August 12 and updated August 13 traces the activity to a single server that has been in place since at least March 2025 and continues to target telecommunications, finance, enterprise-software and public-sector environments.

This is not a Salesforce or ServiceNow zero-day. Reco says it has observed guest-user activity rather than authenticated compromise. The attacker probes Salesforce Aura and Lightning Web Runtime interfaces, including GraphQL through the UI-API, while also querying ServiceNow's public portal-search interface. The common failure is excessive permission granted to anonymous guest identities.

Reco identifies 158.220.87.79 and the Go-http-client/1.1 user agent as strong campaign indicators, but merely blocking the known infrastructure does not fix the exposed data. Salesforce operators should review guest sharing rules, object and field permissions and LWR guest UI-API access. ServiceNow operators should verify which portal search sources are available anonymously and ensure access-control rules prevent sensitive records from being returned.

Watch for: Additional infrastructure or named victims showing whether City-Forum is expanding beyond the currently observed operator and whether exposed guest data is being used for subsequent intrusions.

Sources: Reco, “The City-Forum Campaign,” updated August 13, 2026; BleepingComputer, “City-Forum data theft attacks target Salesforce, ServiceNow portals,” August 2026.

Jewelbug runs government espionage and cryptocurrency fraud from the same operational infrastructure

Broadcom's Symantec Threat Hunter Team reported on August 13 that the group it tracks as Jewelbug is conducting espionage against government and military targets in the Middle East and Asia while using overlapping infrastructure for large-scale cryptocurrency fraud. Symantec assesses Jewelbug as a China-based hackers-for-hire operation; that assessment should not be read as proof that every operation is directed by the Chinese government.

The researchers gained unusual visibility into Jewelbug's own operational systems. Symantec reports more than one million implant check-ins, over 580,000 stolen browser cookies and more than 2,300 exfiltrated emails between February and May. Its espionage activity includes compromised government webmail environments, browser-stealing components and multiple backdoors. The same XG-Web management platform was used across espionage and financially motivated operations.

The overlap matters because it complicates assumptions about motive and attribution. An intrusion showing Chinese-language infrastructure or established espionage malware does not automatically establish state direction, while ostensibly criminal infrastructure can simultaneously support intelligence collection. Defenders at government, defense, aerospace and telecom organizations should give particular weight to anomalous browser extensions, stolen session cookies, unauthorized webmail access and systems being repurposed as internal or external proxies.

Watch for: Government attribution, identification of Jewelbug's customers, or additional evidence clarifying whether espionage tasking is state-directed, privately contracted, or a mixture of both.

Sources: Symantec Threat Hunter Team/Broadcom, “Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side,” August 13, 2026.

The PTC Windchill campaign moves from leak-site claims toward confirmed corporate investigations

The Cl0p extortion group has now named dozens of organizations in a campaign associated by researchers with exploitation of PTC Windchill and FlexPLM, enterprise platforms heavily used in engineering and manufacturing. The important update is not the leak-site list itself: Philips has confirmed and contained an attempted compromise of a server associated with internal data, while Shell and GE have opened investigations. Fiserv says its review has found no evidence that customer, banking, transaction or personal data, or its operating environment, was affected.

Reporting links the broader campaign to CVE-2026-12569 in internet-exposed PTC Windchill and FlexPLM systems. PTC began issuing patches in June, and CISA subsequently placed the vulnerability in its Known Exploited Vulnerabilities catalog. Researchers have reported JSP web shells in compromised PLM environments. Cl0p claims it stole engineering drawings, project plans, backups and facility information from some victims, but those specific data-theft claims remain unverified and should not be treated as confirmed facts.

For industrial organizations, product-lifecycle-management systems deserve treatment as repositories of strategic engineering information rather than ordinary business applications. Operators that exposed affected PTC systems should verify remediation and retrospectively review the June and July period for web-shell activity, unusual archive creation, large outbound transfers and access to engineering repositories. Where compromise is established, patching alone does not answer whether intellectual property was already removed.

Watch for: Victim disclosures confirming what data, if any, left their environments and further evidence defining how broadly CVE-2026-12569 was used across the named organizations.

Sources: Reuters, “Hacking group claims mass data theft from Shell, Philips, GE, Fiserv and dozens of others,” August 13, 2026; NVD, CVE-2026-12569; The Hacker News, “CISA Adds Exploited PTC Windchill RCE Flaw to KEV Catalog,” June 2026.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.