Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch geotools geotools systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters with JDBCDataStore implementations. Users are advised to upgrade to either version 27.4 or to 28.2 to resolve this issue. Users unable to upgrade may disable `encode functions` for PostGIS DataStores or enable `prepared statements` for JDBCDataStores as a partial mitigation.
⚡ UPDATE: GeoServer has patched the actively targeted SQL injection flaw.
The issue affects PostGIS-backed deployments and is a regression of CVE-2023-25158.
Update now: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html https://t.co/q1UD8Htz7T
Post summary
GeoServer has released a patch for an actively targeted SQL injection vulnerability in PostGIS‑backed deployments, referencing CVE‑2023‑25158. No PoC or exploit details are provided in the update.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 15, 2026
1️⃣ MACOS SCREEN SHARING FLAW EXPLOITED FOR MONERO MINING
Attackers are actively exploiting CVE-2026-65400, a vulnerability in Apple's macOS Screen Sharing feature, to install Monero cryptocurrency miners on compromised systems. The flaw affects Macs with port 5900 exposed to the internet, allowing unauthenticated remote access. Apple has already released emergency updates to patch the vulnerability, but security researchers warn that many internet-facing machines may remain unpatched and at risk. System administrators should immediately verify their macOS installations are up to date and ensure VNC ports are not unnecessarily exposed.
🔹 @TheHackersNews
2️⃣ SABLE SQUIRREL SPENDS $7 MILLION ON EXPIRED DOMAINS FOR CYBERCRIME
A sophisticated cybercrime group known as Sable Squirrel has been identified spending nearly $7 million acquiring expired domains to build a massive infrastructure for malicious operations. The group now controls over 10,000 domains that facilitate illegal streaming services, online gambling platforms, and malware command-and-control communications. At least 31,000 distinct malware samples have been observed communicating with these domain networks, making it one of the largest domain-based cybercrime infrastructures documented to date.
🔹 @TheHackersNews
3️⃣ SAP COMMERCE CLOUD CRITICAL FLAW SEEKING ACTIVE EXPLOITATION
CVE-2026-58231, a CVSS 10.0 critical vulnerability in SAP Commerce Cloud, is already under active exploitation attempts just three days after the patch was released. The flaw allows unauthenticated attackers to execute arbitrary code remotely on affected systems. Security researchers emphasize that this is a race against time — organizations running SAP Commerce Cloud must apply the vendor patch immediately, as the exploit code is circulating in threat actor communities and being actively leveraged in targeted campaigns.
🔹 @TheHackersNews
4️⃣ GEOSERVER PATCHES ACTIVELY TARGETED SQL INJECTION REGRESSION
GeoServer has released a patch for an actively exploited SQL injection vulnerability affecting PostGIS-backed deployments. The flaw is a regression of CVE-2023-25158, meaning organizations that previously fixed the original issue may have been re-exposed by subsequent updates. The vulnerability allows attackers to execute arbitrary SQL commands against the database backend, potentially leading to full data compromise. All GeoServer administrators using PostGIS should update immediately and verify their deployment is no longer vulnerable.
🔹 @TheHackersNews
5️⃣ HACKERS ARRESTED OVER €30 MILLION BANK FRAUD
Law enforcement agencies have arrested several individuals responsible for a €30 million bank fraud scheme that exploited a vulnerability in a critical service provider's infrastructure. The attackers leveraged the flaw to intercept and manipulate financial transactions across multiple banking institutions. The arrests highlight the growing importance of securing third-party service providers in the financial supply chain, as a single compromised vendor can cascade into massive losses across their entire customer base.
🔹 @BleepinComputer
6️⃣ SANDWORM DEPLOYS TROJANIZED WIREGUARD AGAINST UKRAINIAN IT WORKERS
The Sandworm threat group, linked to Russian military intelligence, has launched a targeted campaign against Ukrainian IT professionals using trojanized WireGuard VPN clients. Operating through its UAC-0145 cluster, the group is conducting fake job interviews to distribute the compromised software. This social engineering approach makes the attack particularly effective, as victims believe they are participating in legitimate recruitment processes. The use of WireGuard — typically a trusted open-source VPN tool — demonstrates adversaries' increasing sophistication in weaponizing legitimate software.
🔹 @Huntio
7️⃣ EVOOO1BOT LINUX BOTNET TURNS ROUTERS INTO TRAFFIC RELAY NODES
A new Mirai-based Linux botnet called Evooo1Bot is targeting internet-facing gateways and compromising routers to convert them into SOCKS5 traffic relay nodes. This modular malware allows attackers to route their malicious traffic through compromised infrastructure, making attribution and blocking significantly more difficult. Network operators should ensure their gateway devices are running firmware with the latest security patches and monitor for unusual outbound traffic patterns that may indicate infection.
🔹 @BleepinComputer
💭 The threat landscape this week demonstrates a clear pattern: attackers are weaponizing trust. Whether it's trojanized open-source VPN software, expired domains that look legitimate, or service providers whose customers assume are secure — the common thread is exploiting relationships and tools that organizations rely on without question. Defenders need to shift from trusting by default to verifying continuously.
Which of these threats should your organization prioritize patching first? 👇
#Cybersecurity#InfoSec#ZeroDay#DataBreach#ThreatIntelligence#OpenSource#Privacy
Post summary
Several high‑severity CVEs are confirmed to be in active exploitation, with vendors releasing patches and advisories; immediate patching is essential.
The article reports that GeoServer CVE-2023-25158 is currently being actively exploited via unauthenticated SQL injection leading to potential remote code execution, and it advises immediate patching and hardening measures.