Cybersecurity Intelligence Report — 18 August 2026

Written by

in

> CRITICAL SECTION

[12] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More (TheHackerNews)
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a

[11] Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware (TheHackerNews)
CVEs: CVE-2026-59310
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

[10] GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE (TheHackerNews)
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

[10] Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure (SecurityWeek)
CVEs: CVE-2026-58231
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .

> CISA KEV (last 14 days)

CVE Vendor/Product Score Required action
CVE-2025-62593 [CISA KEV] CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability – Ray-Project Ray 6 Ray-Project Ray Code Injection Vulnerability – Ray-Project Ray. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders

> RANSOMWARE VICTIMS (today)

  • AuditTeam: De***up
  • incransom: SD Associates Sdn Bhd, Third Coast Bancshares

> NEWS

[8] Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads (TheHackerNews)
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

[7] Microsoft working on Defender patch for ShieldBreak zero-day (BleepingComputer)
Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. […]

[7] IAM Compliance Requirements and Best Practices (TheHackerNews)
IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can

[7] Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer (HelpNetSecurity)
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials. Apple fixed the issue with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), and advised its macOS users to upgrade their s

[7] [RANSOMWARE] direwolf leaked Eva AI Limited (ransomware.live/direwolf)
Victim: Eva AI Limited | Group: direwolf | Website: eva.ai | Country: GB | Details: Human Resources

[7] [RANSOMWARE] dragonforce leaked Vermont XCenter (ransomware.live/dragonforce)
Victim: Vermont XCenter | Group: dragonforce | Website: vermont.com.br | Country: BR | Details: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que o cliente deve estar no Centro das Atenções. Com isso estabelecido, a companhia acredita que é mais simples interpretar o mercado a partir dos desejos e perspectivas do mesmo. Vermont XCenter: Centro de interAçõ

[6] Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic (TheHackerNews)
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

[6] Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies (TheHackerNews)
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

[6] Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner (TheHackerNews)
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to

[5] Philips and GE investigating Clop ransomware data theft claims (BleepingComputer)
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. […]

[5] SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch (TheHackerNews)
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit

[5] [RANSOMWARE] nightspire leaked T****w**x (ransomware.live/nightspire)
Victim: T****w**x | Group: nightspire | Details: Data is not available now.

[5] [RANSOMWARE] insomnia leaked Codinter (ransomware.live/insomnia)
Victim: Codinter | Group: insomnia | Website: www.codinter.com | Country: US | Details: Private company supplying welding, cutting, finishing products and services across North/Central/South America. Offers equipment, tools, accessories, consumables – from mobile units to robotic systems. Oil industry: pipeline, tanks, refinery, platforms.

[5] [RANSOMWARE] qilin leaked GSW Gemeinschaftsstadtwerke GmbH (ransomware.live/qilin)
Victim: GSW Gemeinschaftsstadtwerke GmbH | Group: qilin | Website: www.gsw-kamen.de | Country: DE | Details: N/A

[5] [RANSOMWARE] qilin leaked White-Daters & Associates, Inc (ransomware.live/qilin)
Victim: White-Daters & Associates, Inc | Group: qilin | Website: www.whitedaters.com | Country: US | Details: N/A

[5] [RANSOMWARE] qilin leaked The University of the West Indies (ransomware.live/qilin)
Victim: The University of the West Indies | Group: qilin | Website: www.uwi.edu | Country: TT | Details: N/A

[5] [RANSOMWARE] qilin leaked EmpireWorks (ransomware.live/qilin)
Victim: EmpireWorks | Group: qilin | Website: www.empireworks.com | Details: N/A

[5] [RANSOMWARE] play leaked Bridgeport Capital Services (ransomware.live/play)
Victim: Bridgeport Capital Services | Group: play | Website: www.bridgeportcapital.com | Country: US | Details: United States

[5] [RANSOMWARE] play leaked Sam Pack Auto Group (ransomware.live/play)
Victim: Sam Pack Auto Group | Group: play | Website: www.sampack.com | Country: US | Details: United States

[5] [RANSOMWARE] play leaked Woodhaven Association (ransomware.live/play)
Victim: Woodhaven Association | Group: play | Website: www.woodhavenassociation.com | Country: US | Details: United States

> SUMMARY

New items collected: 80. Critical items: 4. Active ransomware groups represented today: 2. CVEs to prioritise for review: CVE-2026-58231, CVE-2026-65400, CVE-2026-59310, CVE-2025-62593, CVE-2026-15748, CVE-2026-69414.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Open the companion interactive HTML intelligence report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *