Generated · Archived snapshot 21 findings · 3 CVEs
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are under active exploitation across diverse technology stacks, ranging from AI/ML platforms and enterprise software to cloud infrastructure and industrial systems. CISA has added two high-impact flaws to its Known Exploited Vulnerabilities catalog—a critical Ray distributed computing framework vulnerability enabling browser-based remote code execution and a high-severity Windows Task Host vulnerability now leveraged by ransomware gangs. Simultaneously, critical unauthenticated RCE vulnerabilities in GitLab (CVE-2026-19478, CVSS 9.4) and the widely deployed Forminator WordPress plugin (CVE-2026-15748, CVSS 9.8) have been patched but require immediate deployment given their exploitation potential.

Threat actor activity shows increasing sophistication in living-off-the-land and cloud-native tradecraft. The Clop ransomware gang has developed a custom Java web shell targeting PTC Windchill and FlexPLM servers with built-in credential decryption and repository enumeration capabilities. A novel Python implant framework dubbed TWINLOOT operates its entire command-and-control infrastructure within trusted Microsoft services including SharePoint Online and Teams, while the Iranian-linked Cavern C2 framework leverages DNS and Google Apps Script to blend into legitimate traffic. The "City Forum" campaign has scraped Salesforce and ServiceNow portals across multiple industries for over a year from a single infrastructure IP, and a typosquatting campaign on RubyGems ("StubMaker") has deployed 16 malicious packages stealing browser credentials and cryptocurrency wallets.

Emerging attack surfaces in AI ecosystems are being actively researched and exploited. Microsoft Copilot Personal contains three vulnerabilities ("CoSnitch") enabling single-click data exfiltration from connected applications via an undocumented URL parameter. Researchers have demonstrated self-propagating "mind viruses" spreading between AI agents through persistent prompt files, while the MLflow AI platform and FUXA SCADA software face active scanning and exploitation of critical SSRF flaws. A credential-based intrusion campaign claims 3.6 million Azure account records stolen from Fortune 500 companies, and the Certighost vulnerability (CVE-2026-54121) allows standard domain users to escalate Enterprise Certificate Authorities to Domain Controller equivalence, highlighting persistent PKI trust boundary failures.

Active Exploitation Details

Severity unknownPotentialInvestigate#

  • Description: Three vulnerabilities in Microsoft Copilot Personal collectively named CoSnitch that leverage an undocumented URL parameter surfaced by the assistant itself. A single click on a crafted link can silently exfiltrate data from connected apps and other information available to the victim's Copilot session.
  • Impact: Silent data exfiltration from all connected applications and Copilot-accessible information without user interaction beyond clicking a link.
  • Status: Disclosed by Varonis Threat Labs; patch status not specified in source.

CriticalActive exploitationPatch#

  • Description: Critical Server-Side Request Forgery vulnerability in MLflow, an open-source AI/ML platform, allowing attackers to steal cloud credentials and secrets through malicious scanning and exploitation.
  • Impact: Theft of cloud credentials and secrets from MLflow deployments; active exploitation campaigns observed.
  • Status: Actively exploited in the wild per watchTowr and VulnCheck reports; patch availability not specified in source.

CriticalActive exploitationPatch#

  • Description: Critical vulnerability in FUXA, an open-source web-based SCADA/HMI software for operational technology and industrial automation, subject to malicious scanning and exploitation.
  • Impact: Potential compromise of OT/industrial automation systems; active exploitation campaigns observed.
  • Status: Actively exploited in the wild per watchTowr and VulnCheck reports; patch availability not specified in source.

HighActive exploitationInvestigate#

  • Description: Custom Java web shell specifically designed for PTC Windchill and FlexPLM servers with built-in features to decrypt credentials, enumerate file repositories, and steal files, likely linked to the Clop ransomware gang.
  • Impact: Targeted data theft from Windchill/FlexPLM installations including credential decryption, repository enumeration, and file exfiltration.
  • Status: Active deployment in Clop ransomware operations; no vendor patch mentioned for the web shell itself.

HighActive exploitationPatch#

  • Description: High-severity Windows Task Host vulnerability confirmed by CISA as actively exploited by ransomware gangs, originally flagged as actively exploited in April.
  • Impact: Ransomware deployment and system compromise via Windows Task Host exploitation.
  • Status: CISA-confirmed active exploitation by ransomware gangs; added to KEV catalog.

CriticalActive exploitationPatch#

  • Description: Critical flaw in Ray, an open-source Python-native distributed computing framework for AI/ML workloads, that can trigger browser-based remote code execution. CISA added to KEV catalog citing evidence of active exploitation.
  • Impact: Browser-based remote code execution affecting Ray distributed computing clusters used for AI/ML workloads.
  • Status: CISA-confirmed active exploitation; added to KEV catalog; patch status not specified in source.

CriticalPotentialMonitor#

  • Description: Two vulnerabilities in Unisoc modems that can be chained to take over an Android device by delivering a payload when the victim answers a video call.
  • Impact: Full Android device compromise via video call interaction; zero-click or one-click exploitation depending on implementation.
  • Status: Proof-of-concept demonstrated by researchers; active exploitation status not confirmed in source.

CriticalPotentialPatchCVE-2026-19478#

  • Description: Critical vulnerability in GitLab Community Edition and Enterprise Edition GraphQL implementation allowing unauthenticated attackers to remotely modify or delete public projects and user data under certain conditions.
  • Impact: Unauthenticated remote modification or deletion of public projects and user data; CVSS 9.4.
  • Status: Security updates released by GitLab; exploitation in wild not explicitly confirmed.

CriticalPotentialPatchCVE-2026-15748#

  • Description: Critical unauthenticated remote code execution vulnerability in Forminator Forms WordPress plugin (600,000+ active installations) via malicious PHP file uploads.
  • Impact: Unauthenticated arbitrary code execution on vulnerable WordPress sites; CVSS 9.8.
  • Status: Disclosed by security researcher; patch status not specified in source.

CriticalPotentialPatchCVE-2026-54121#

  • Description: Vulnerability allowing a standard domain user to turn an Enterprise Certificate Authority into a Domain Controller, exposing fundamental PKI trust boundary failures.
  • Impact: Full domain compromise via PKI privilege escalation; standard user to Domain Controller equivalence.
  • Status: Patch available; described as "the easy part" with deeper architectural lessons needed.

HighPotentialInvestigate#

  • Description: GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository (.github/workflows/jira_issue.yml) allowing crafted GitHub issues to execute commands with internal Jira credentials.
  • Impact: Command execution in CI/CD pipeline with access to internal Jira credentials; supply chain compromise vector.
  • Status: Disclosed by Wiz researchers; patch status not specified in source.

MediumObservedMonitor#

  • Description: Authorization flaw in an order-tracking plug-in exposing names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.
  • Impact: PII and order data exposure for nearly 40,000 hardware wallet customers.
  • Status: Disclosed by SafePal; affected customers notified individually via email on August 16.

HighActive exploitationInvestigate#

  • Description: Modular, PyArmor-hardened Python implant framework operating its entire command-and-control infrastructure inside trusted Microsoft services (SharePoint Online, Teams) for credential theft and lateral movement.
  • Impact: Stealthy credential theft, persistence, and network lateral movement entirely within legitimate Microsoft cloud infrastructure.
  • Status: Active deployment documented by Ontinue researchers; no vendor patch applicable.

HighActive exploitationInvestigate#

  • Description: Long-running campaign scraping records from Salesforce and ServiceNow customer portals across multiple industries since 2025, traced to single infrastructure IP 158.220.87.79.
  • Impact: Unauthorized access to customer portal data across multiple industries; sustained access for over one year.
  • Status: Active campaign documented by Reco researchers; ongoing as of publication.

MediumActive exploitationInvestigate#

  • Description: Typosquatting campaign on RubyGems with 16 malicious packages (ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn, and others) deploying Windows-based information stealer targeting browser credentials and cryptocurrency wallets.
  • Impact: Credential and cryptocurrency wallet theft from developers installing typosquatted packages.
  • Status: Active campaign discovered August 15, 2026 by OpenSourceMalware; packages published to RubyGems.

HighActive exploitationMonitor#

  • Description: Evolving Cavern/Cav3rn command-and-control framework used by Iranian nation-state hackers targeting entities in Israel, leveraging DNS and Google Apps Script to blend into legitimate traffic.
  • Impact: Stealthy persistent access to Israeli targets; C2 infrastructure camouflaged within legitimate Google/DNS traffic.
  • Status: Active since December 2025 per Kaspersky monitoring; new components discovered.

HighActive exploitationMonitor#

  • Description: Linux botnet expanding Mirai capabilities with exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
  • Impact: DDoS plus persistent access, credential theft, and proxy infrastructure from compromised Linux/IoT devices.
  • Status: Active evolution documented; exploitation modules indicate active vulnerability targeting.

CriticalActive exploitationInvestigate#

  • Description: Threat actor selling employee databases allegedly stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
  • Impact: 3.6 million Azure account records claimed stolen; Fortune 500 compromise via credential reuse/theft.
  • Status: Actor actively selling data; compromise method confirmed as credential-based.

MediumPotentialMonitor#

  • Description: Self-propagating payloads spreading between AI agents through editable system prompt files that autonomous agent harnesses use to carry state between sessions.
  • Impact: Cross-agent malware propagation in multi-agent AI systems; persistent compromise of agent memory/state.
  • Status: Demonstrated in simulated six-agent coding environment by Anthropic and EPFL researchers; preprint released August 10, 2026.

MediumActive exploitationInvestigate#

  • Description: Ransomware affiliate posing as incident-recovery service, proactively emailing victims offering to delete stolen data from ransomware groups' servers for $20,000-$60,000.
  • Impact: Secondary extortion of ransomware victims; potential double-dip on ransom payments; diversion of recovery funds.
  • Status: Active campaign spotted by GuidePoint Research; anomalous incident-recovery impersonation.

MediumObservedMonitor#

  • Description: Third-party data breach via CEVA Logistics exposing customer personal and order information for Pokémon Center customers in the United Kingdom and Germany.
  • Impact: Customer PII and order data exposure; some orders cancelled.
  • Status: Breach confirmed; notification to UK/Germany customers in progress.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities