Generated · Archived snapshot 18 findings · 2 CVEs
On this page

Exploitation Report

Executive Summary

Critical exploitation activity continues to accelerate across enterprise software, operating systems, and identity infrastructure. Two maximum-severity vulnerabilities—CVE-2026-59310 in VMware vCenter Syslog Server and CVE-2026-55040 in Microsoft SharePoint—are under active global exploitation within days of patch availability, with threat actors weaponizing public proof-of-concept code to establish persistent reverse SSH access and bypass authentication.

Simultaneously, multiple zero-day vulnerabilities in Windows (LegacyHive and a separate Lazarus Group-exploited flaw), macOS Screen Sharing, and Belgium's eID browser extension are being actively exploited for cryptojacking, espionage, and remote code execution against high-value targets.

State-sponsored and financially motivated threat actors are diversifying their operations. The North Korean Lazarus Group continues Operation Dream Job, exploiting a Windows zero-day to deploy novel backdoors against defense and aerospace organizations across four countries. The Jewelbug APT simultaneously conducts government espionage and cryptocurrency fraud from shared infrastructure. Ransomware groups Akira and Clop demonstrate evolving tactics—Akira affiliates now disable EDR via Safe Mode with Networking, while Clop claims 89GB exfiltration from Shell. The ShinyHunters extortion group breached 1.6 million RingCentral accounts, and a long-running City-Forum campaign has targeted Salesforce and ServiceNow environments since March 2025 with custom tooling.

Supply chain and identity-focused attacks are expanding rapidly. A service provider vulnerability enabled €30M bank fraud against Commerzbank customers, resulting in international arrests. Belgium's entire eID trust framework was compromised through severe browser extension vulnerabilities affecting citizen authentication. Over 737 malicious Chrome VPN extensions with 75,000+ installations were caught routing traffic through attacker-controlled proxies. Apple issued new Threat Notifications for mercenary spyware targeting iPhones, while a widespread data breach at the Scottish prosecutor's office may extend to other agencies through a shared third-party provider.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-59310#

  • Description: A critical remote code execution vulnerability in VMware vCenter Syslog Server that allows unauthenticated attackers to execute arbitrary code on affected systems. The flaw resides in the syslog processing component and can be triggered remotely without authentication.
  • Impact: Attackers achieve full system compromise, deploying reverse SSH tools for persistent remote access and lateral movement within virtualized infrastructure. Exploitation grants complete control over vCenter management infrastructure.
  • Status: Actively exploited in a global threat campaign since early this month. Patches are available but may not fully mitigate risk if exploitation already occurred.

CriticalActive exploitationPatchCVE-2026-55040#

  • Description: A critical authentication bypass vulnerability in Microsoft SharePoint (CVSS 9.1) stemming from weak authentication mechanisms. The flaw allows attackers to bypass security features and gain unauthorized access to SharePoint environments.
  • Impact: Attackers can access sensitive documents, internal sites, and connected systems within Microsoft 365 ecosystems. The vulnerability provides a pathway to Gmail, Drive, and other connected services through the broader Workspace attack chain.
  • Status: Actively exploited in the wild following public PoC code release. Patched in Microsoft's July 2026 Patch Tuesday updates.

HighActive exploitationPatch#

  • Description: An authentication bypass vulnerability in macOS Screen Sharing that allows remote attackers to bypass authentication controls. Public exploit code emerged prior to active exploitation, enabling rapid weaponization.
  • Impact: Attackers deploy Monero cryptocurrency miners on compromised macOS systems, consuming system resources for financial gain. The Netherlands' NCSC has issued warnings about active exploitation.
  • Status: Actively exploited following public exploit code release. Patch status not specified in reporting.

CriticalActive exploitationPatch#

  • Description: A maximum-severity remote code execution vulnerability in SAP Commerce Cloud that was patched only three days before active targeting began. The flaw allows unauthenticated remote code execution on affected Commerce Cloud instances.
  • Impact: Attackers can achieve full compromise of e-commerce platforms, accessing customer data, payment information, and backend systems. Threat intelligence firm Defused confirmed active targeting immediately post-patch.
  • Status: Actively targeted in attacks within days of patch release. Patches are available.

CriticalActive exploitationPatch#

  • Description: A Windows zero-day vulnerability dubbed "LegacyHive" that was actively exploited before Microsoft released patches following the July 2026 Patch Tuesday. Details of the underlying flaw remain limited in public reporting.
  • Impact: As a zero-day exploit, attackers achieved SYSTEM-level access on compromised Windows systems prior to patch availability, enabling full system compromise and persistence.
  • Status: Patched by Microsoft after active exploitation as a zero-day. Patches released in July 2026 Patch Tuesday.

CriticalActive exploitationInvestigate#

  • Description: A separate Windows zero-day vulnerability exploited by the North Korean Lazarus Group as part of Operation Dream Job, a long-running cyber espionage campaign. The flaw enables SYSTEM-level access and deployment of a never-before-seen backdoor.
  • Impact: Targets defense and aerospace companies in France, Germany, Brazil, and India. Provides persistent SYSTEM access and custom backdoor deployment for long-term espionage.
  • Status: Actively exploited in targeted attacks. Patch status not specified in reporting.

CriticalObservedMitigate#

  • Description: Severe vulnerabilities in a key browser extension underlying Belgium's electronic ID (eID) authentication system. The trust framework for citizen authentication was fully compromised, exposing fundamental weaknesses in browser extension security architecture.
  • Impact: Remote code execution on citizen systems, complete compromise of the eID trust framework, potential access to government services, banking, and identity verification for all Belgian citizens using the system.
  • Status: Vulnerabilities identified and framework compromised. Remediation status not specified.

HighObservedInvestigate#

  • Description: An unspecified vulnerability at a service provider that allowed cybercriminals to withdraw funds from Commerzbank customers' accounts, resulting in €30M fraud. Four perpetrators arrested in Brazil, three charged in Europe.
  • Impact: Direct financial theft from bank customers, compromise of banking authentication/authorization flows through third-party service provider.
  • Status: Law enforcement action completed with arrests. Vulnerability presumably remediated.

HighObservedInvestigate#

  • Description: 737 malicious Chrome VPN and proxy extensions (across 40+ developer accounts) with 75,486 total installations were found intercepting browser traffic and routing it through attacker-controlled proxy infrastructure. 274 extensions impersonated 66 legitimate brands.
  • Impact: Full visibility into victims' browsing traffic, credential harvesting, session hijacking, and potential injection of malicious content. Primarily targeted Russian-speaking users seeking blocked services.
  • Status: Extensions identified and presumably removed from Chrome Web Store. 75,000+ installations already occurred.

CriticalActive exploitationMonitor#

  • Description: Apple issued new Threat Notifications to users targeted by mercenary spyware attacks on iPhones. The specific vulnerabilities exploited were not disclosed, but such attacks typically leverage zero-day chains for silent installation.
  • Impact: Full device compromise, access to communications, location data, credentials, and encryption keys. Targets are typically high-value individuals (journalists, activists, officials).
  • Status: Active targeting confirmed by Apple's threat notifications. Apple mitigations deployed via notifications and likely silent patches.

HighObservedMitigate#

  • Description: An Akira ransomware affiliate demonstrated a novel technique to disable Endpoint Detection and Response (EDR) solutions by restarting compromised systems into Safe Mode with Networking, where EDR drivers typically do not load.
  • Impact: EDR evasion enabling data exfiltration without encryption (in this observed case). Technique allows ransomware operators to operate unimpeded by behavioral monitoring.
  • Status: Observed in active intrusion. No patch available—requires defensive configuration changes.

HighActive exploitationInvestigate#

  • Description: The Jewelbug hacker group breached government webmail systems while simultaneously running cryptocurrency fraud operations. The group operates as hackers-for-hire performing both espionage and financially motivated heists from shared infrastructure.
  • Impact: Government and military espionage, credential theft, cryptocurrency fraud. Dual-mission operations blur attribution lines between state-sponsored and criminal activity.
  • Status: Active campaign observed. Initial access vector not specified in reporting.

HighActive exploitationInvestigate#

  • Description: A long-running data theft campaign (active since at least March 2025) targeting Salesforce and ServiceNow environments across multiple sectors using custom tooling. The campaign demonstrates sophisticated understanding of SaaS platform internals.
  • Impact: Theft of sensitive CRM and IT service management data, including customer records, internal communications, and operational data from enterprise SaaS platforms.
  • Status: Ongoing campaign with custom tooling. Specific vulnerabilities exploited not publicly disclosed.

HighObservedInvestigate#

  • Description: The Clop ransomware gang claimed theft of 89GB of data from Shell, prompting the oil giant to investigate a potential security incident. Clop continues to focus on data extortion over encryption.
  • Impact: Large-scale data exfiltration from a major energy corporation, potential exposure of operational, financial, and proprietary data.
  • Status: Claimed by threat actor, under investigation by victim. Initial access vector not specified.

HighObservedInvestigate#

  • Description: The ShinyHunters extortion group breached RingCentral in July, stealing personal information from 1.6 million accounts. Data surfaced via Have I Been Pwned breach notification service.
  • Impact: Exposure of personal information for 1.6 million RingCentral customers, enabling identity theft, phishing, and account takeover attacks.
  • Status: Breach occurred in July, data now circulating. Initial access method not specified.

HighObservedInvestigate#

  • Description: A data breach at the Scottish prosecutor's office caused by a third-party service provider that may have serviced other government agencies, potentially widening the impact across the Scottish government.
  • Impact: Compromise of legal/prosecutorial data, potential cascade to other agencies sharing the same third-party provider. Supply chain risk realization.
  • Status: Breach reported, scope potentially widening. Third-party relationship under investigation.

HighObservedInvestigate#

  • Description: Ransomware attack on the Colombian Justice Ministry days before a presidential transition, part of increased targeting of critical infrastructure and government organizations across Latin America.
  • Impact: Disruption of judicial operations during political transition, potential data theft, operational paralysis of critical government functions.
  • Status: Attack executed during sensitive political period. Ransomware variant and initial access not specified.

HighActive exploitationMitigate#

  • Description: Attackers leverage stolen OAuth tokens as an alternative initial access vector into Google Workspace environments (Gmail, Drive, connected systems), bypassing traditional phishing defenses and MFA.
  • Impact: Full access to email, documents, and integrated applications without credential compromise. Tokens provide persistent access until explicitly revoked.
  • Status: Active attack vector highlighted by Material Security. Not a vulnerability but an abused legitimate feature.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities