CVE-2026-58231Active Exploitation

CRITICALCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 31 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 77 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 108 mentions across 14 observed days

What's happening

  • Active exploitation reported across 77 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 78 signals
  • Technical details provided in 72 signals
  • Disclosure: 7 classified signals
  • Peaked 7d ago at 31 mentions (2026-08-17); latest day: 2
  • 108 total mentions across 14 days

Deep dive

Activity timeline108 mentions / 14d
08162331Mentions · 2026-08-11: 3Mentions · 2026-08-12: 14Mentions · 2026-08-13: 2Mentions · 2026-08-14: 7Mentions · 2026-08-15: 23Mentions · 2026-08-16: 13Mentions · 2026-08-17: 31Mentions · 2026-08-18: 5Mentions · 2026-08-19: 4Mentions · 2026-08-21: 1Mentions · 2026-08-24: 1Mentions · 2026-08-25: 1Mentions · 2026-08-29: 1Mentions · 2026-08-30: 2PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-16: 1PoC Mentioned / Linked · 2026-08-18: 2Exploit Tool / Code · 2026-08-18: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 5Active Exploitation · 2026-08-15: 20Active Exploitation · 2026-08-16: 11Active Exploitation · 2026-08-17: 30Active Exploitation · 2026-08-18: 4Active Exploitation · 2026-08-19: 2Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-29: 1Active Exploitation · 2026-08-30: 2Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-12: 10Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 6Patch / Workaround · 2026-08-15: 17Patch / Workaround · 2026-08-16: 8Patch / Workaround · 2026-08-17: 22Patch / Workaround · 2026-08-18: 4Patch / Workaround · 2026-08-19: 3Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 2Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 13Technical Details · 2026-08-13: 2Technical Details · 2026-08-14: 7Technical Details · 2026-08-15: 12Technical Details · 2026-08-16: 8Technical Details · 2026-08-17: 13Technical Details · 2026-08-18: 5Technical Details · 2026-08-19: 4Technical Details · 2026-08-21: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-29: 1Technical Details · 2026-08-30: 208-1108-1208-1308-1408-1508-1608-1708-1808-1908-2108-2408-2508-2908-30
Signal classification5 categories
Active Exploitation
7469.2%
Patch
2018.7%
Disclosure
76.5%
General
43.7%
Exploit
21.9%
Referenced assets81 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-113
Disclosure1Patch2
2026-08-1214
Disclosure3General1Patch10
2026-08-132
Active Exploitation1Patch1
2026-08-147
Active Exploitation5Disclosure1Patch1
2026-08-1523
Active Exploitation20Disclosure2Patch1
2026-08-1613
Active Exploitation11General1Patch1
2026-08-1731
Active Exploitation27Exploit1Patch2
2026-08-185
Active Exploitation4Exploit1
2026-08-194
Active Exploitation2Patch2
2026-08-211
General1
2026-08-241
Active Exploitation1
2026-08-251
General1
2026-08-291
Active Exploitation1
2026-08-302
Active Exploitation2
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Exploitation attempts hit SAP just three days after the patch. CVE-2026-58231 is a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code. Inside the attacks: https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html

    Post summary

    Exploitation attempts against SAP Commerce Cloud CVE-2026-58231 were observed within days of the patch, with unauthenticated attackers potentially achieving arbitrary code execution.

    24021323550.4K
    2.4M followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ Warning: SAP Commerce Cloud flaw could enable arbitrary code execution. CVE-2026-58231 carries a CVSS 10.0 score and can be triggered by an unauthenticated attacker abusing a default authentication client with crafted input. SAP has released a fix. Patch and redeploy. Read: https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html

    Post summary

    SAP Commerce Cloud flaw (CVE-2026-58231) delivers arbitrary code execution to unauthenticated callers via crafted input; a vendor patch has been issued and should be applied.

    6331721828.0K
    2.4M followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload 👉https://console.defusedcyber.com/signup https://t.co/zMJuo45Ahx

    Post summary

    First exploitation attempts for CVE‑2026‑58231 were observed in honeypots; however, no public PoC exists and the vulnerability is not yet widely exploited, but a patch has been released.

    1171713111.3K
    7.7K followersView on X
  • ThreatWire@ThreatWire_
    Active Exploitation

    🚨 IN THE WILD: Exploitation attempts targeting CVE-2026-58231, a critical SAP Commerce Cloud vulnerability, were detected just 3 days after SAP released its security patch. The flaw is unauthenticated, making exposed SAP Commerce Cloud environments an attractive target for attackers. Organizations running affected deployments should prioritize patching and monitor for suspicious activity. #SAP #SAPCommerce #CVE #CyberSecurity #ThreatIntel #Infosec

    Post summary

    Exploit attempts targeting CVE‑2026‑58231 were observed in the wild within three days of SAP's patch release; affected deployments should apply the fix and monitor for suspicious activity.

    0202063.4K
    1.6K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html

    Post summary

    The article indicates that SAP Commerce Cloud CVE-2026-58231 is being actively exploited in the wild.

    0401756.1K
    161.5K followersView on X
  • 크립토개미@CryptoTomioka
    Active Exploitation

    SAP 보안 패치 안심했다면 큰일 보안 담당자라면 주목하세요~ 최고 위험도 CVSS 10.0짜리 취약점 패치 공개 3일 만에 실제 공격 악용되기 시작했는데요 문제의 취약점은 → CVE-2026-58231 그리고 더 무서운 건 따로 있어요 → 공개된 공격 코드 없었는데 공격이 시작됐다는 것입니다. SAP가 8월 11일 패치를 공개했는데 14일 위협 인텔리전스 기업 Defused가 허니팟에서 공격 시도를 포착함 공격자 입장에서 생각해 보면 "패치 나왔네?" 패치 분석 → 어디가 고쳐졌는지 확인 → 원래 취약했던 코드 추적 → 아직 패치 안 한 서버 스캔 이 과정이 3일 만에 벌어진 것이죠 그럼 CVSS 10.0이 왜 위험하냐? 이 취약점은 인증 클라이언트를 악용해 인증 없이 원격 코드 실행 가능할 수 있는 결함 쉽게 말해서 인터넷에 노출된 취약한 서버를 잡으면 공격자가 서버 내부에서 원하는 명령을 실행할 수 있는 수준임 성공시 1. 웹셸 설치 2. 계정, 자격증명 탈취 3. 데이터 유출 4. 랜섬웨어 5. 내부망 이동까지 이어질 수 있어요 SAP Commerce Cloud는 기업들의 쇼핑몰, 결제, 재고, 공급망 등 사용되는 플랫폼이라는 점까지 생각하면 그냥 가볍게 볼 문제가 절대 아닙니다. 더 소름 돋는 건 당시에는 공개 PoC조차 없었음 그런데 공격은 이미 시작됨 PoC가 아직 안 나왔으니까 괜찮겠지? 이 논리가 통하지 않는다는 것! 기업이라면 지금 확인할 것 A: 인터넷에 노출된 SAP Commerce Cloud 인스턴스 확인 B: CVE-2026-58231 패치 적용 C: 당장 패치가 어렵다면 관리 인터페이스 VPN 등으로 제한 D: ACL, 화이트리스트, 네트워크 분리 적용 E: 관리자 엔드포인트에 이상한 요청이 있나 로그 확인 특히 패치 전후 로그를 비교해 보는 게 중요해요 기업용 소프트웨어는 패치 하나 적용에도 테스트 → 검증 → 배포 과정이 필요한데요 ※ 하지만 공격자에게 그 시간은 침투할 수 있는 골든타임입니다.

    Post summary

    CVE-2026-58231은 SAP Commerce Cloud에서 CVSS 10.0의 원격 코드 실행 취약점으로, 8월 11일 패치 이후 3일 만에 공격이 감지돼 공개 PoC가 나오기 전에 이미 이용되고 있음을 보여 주며 즉각적인 패치와 보안 조치가 필요합니다.

    60091505
    4.5K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    #SAP #Commerce #Cloud CVE-2026-58231 Exploited in the Wild https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html #securityaffairs #hacking @DefusedCyber

    Post summary

    The tweet signals that CVE‑2026‑58231 has been actively exploited in the wild, as reported by the linked article.

    130541.4K
    37.7K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    🔴 Un CVE crítico está siendo explotado a nivel global: CVE-2026-58231, con una puntuación CVSS de 10.0, afecta a SAP Commerce Cloud. La vulnerabilidad se debe a controles de autorización y validación de entrada insuficientes. Atacantes están explotando esta debilidad apenas días después de que SAP lanzara un parche. El impacto puede ser significativo, ya que afecta a sistemas que utilizan SAP Commerce Cloud. La explotación activa de esta vulnerabilidad puede llevar a accesos no autorizados y posibles daños a los sistemas afectados. SAP ha lanzado un parche para solventar este problema, por lo que es crucial que los administradores de sistemas que utilizan SAP Commerce Cloud apliquen el parche lo antes posible. ¿Estás en riesgo? Revisa esto: asegúrate de actualizar tu sistema con el parche más reciente y verifica los logs de seguridad para detectar cualquier actividad sospechosa. #Ciberseguridad #Ransomware #CVE #DataBreach https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html

    Post summary

    CVE‑2026‑58231 is actively exploited worldwide against SAP Commerce Cloud, carrying a CVSS score of 10.0, and SAP has released a patch that should be applied immediately to mitigate the risk.

    01083400
    632 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html

    Post summary

    The article reports that CVE-2026-58231 is being actively exploited days after a patch was applied, but provides no PoC, exploit code, or detailed vulnerability analysis.

    020644.6K
    161.5K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    SharePointはPoC公開の当日から悪用が始まり、LLMが8分でAWS管理者権限を丸ごと奪う。 パッチ適用を「今週中に」と言っている間に、攻撃者は当日に動いている。今日の5本だ。 ・SharePoint CVE-2026-55040、PoC公開当日から実戦悪用 ・Lazarus、Windows CVE-2026-68820をゼロデイ悪用——防衛・航空が標的 ・LLM自動化攻撃が8分でAWS Admin権限奪取——Sysdig実観測 ・SAP Commerce Cloud CVE-2026-58231、CVSS10.0の未認証RCE ・ヨネックス公式ECに不正ログイン——顧客情報閲覧の恐れ PoC公開から実戦悪用まで1日もかからない。LLMは8分でAdmin権限を奪い切る。 この速度に、みんなの現場の対応サイクルは本当に追いついているか? パッチ適用の「今週中に」を、今すぐ疑え。

    Post summary

    The post reports that a newly disclosed PoC for SharePoint CVE-2026-55040 triggered immediate attacks, with AI‑driven efforts capturing AWS admin rights in minutes, while other CVEs were also actively exploited; patching schedules are questioned.

    00062744
    1.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    SAP August 2026 Patch Day fixes CVE-2026-58231 (CVSS 10.0) and code injection RCE flaws scoring 9.9 and 9.8 in Commerce Cloud and NetWeaver. #SAP #CVE #RCE #PatchTuesday #NetWeaver #InfoSec http://securityonline.info/sap-august-2026-patch-day/

    Post summary

    SAP's August 2026 Patch Day addresses high‑severity RCE vulnerabilities (CVE‑2026‑58231, CVSS 10.0) and code injection flaws in Commerce Cloud and NetWeaver, providing vendor patches.

    02060621
    13.0K followersView on X
  • tpx Security ⠠⠵@tpx_Security
    Patch

    SAP emitió parches de seguridad para corregir una vulnerabilidad de severidad máxima (CVSS 10.0) identificada como CVE-2026-58231 en SAP Commerce Cloud (Data Hub Adapter). El fallo permite a atacantes no autenticados ejecutar código arbitrario en los sistemas afectados debido a controles de autorización deficientes y fallas en la validación de entradas. La actualización de agosto de 2026 también corrige otras vulnerabilidades críticas de inyección de código y corrupción de memoria en componentes como SAP NetWeaver y sistemas de manufactura MII.

    Post summary

    SAP ha lanzado actualizaciones de seguridad en agosto de 2026 para corregir la gravedad máxima CVE-2026-58231, que permite ejecución de código arbitrario a través de controles de autorización deficientes, y también aborda otras vulnerabilidades críticas de inyección de código y corrupción de memoria.

    02041279
    3.8K followersView on X
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Active Exploitation

    🚨 internet-computer:native — A CVSS 10.0 FLAW IN SAP COMMERCE CLOUD WAS BEING TARGETED JUST DAYS AFTER THE PATCH. THIS IS WHY APPLICATION ARCHITECTURE MATTERS. ☁️♾️🔐 SAP Commerce Cloud has been hit by a maximum-severity vulnerability tracked as CVE-2026-58231, rated CVSS 10.0. The flaw involves insufficient authorization checks and input validation and can allow an unauthenticated attacker to submit specially crafted input through a default authentication client. Successful exploitation can lead to arbitrary code execution and compromise internal components, potentially affecting confidentiality, integrity and availability. The speed of attacker response is the real warning. Defused Cyber observed exploitation attempts hitting its honeypots only three days after SAP released the patch. KEVIntel later independently observed exploitation attempts on August 14. SAP customers are being advised to patch, rebuild and redeploy affected Commerce Cloud releases, with IP filtering available as a temporary mitigation. This is not an argument that SAP Commerce Cloud is uniquely insecure. It illustrates a much broader problem. Modern enterprise applications typically depend on multiple layers: ☁️ Cloud infrastructure 🖥️ Application servers 🗄️ Databases 🔐 Authentication systems 🌐 APIs 🔌 Middleware 🧑‍💻 Privileged administrators ⚙️ Patch and deployment pipelines Every additional component becomes another security boundary that has to be configured, maintained, patched and defended. And attackers increasingly automate the race. A critical vulnerability can move from disclosure to active scanning and exploitation in days — sometimes hours. This is where I continue to see the long-term architectural importance of internet-computer:native. Internet Computer allows substantially more of an application to exist directly inside decentralized protocol infrastructure: ☁️ Compute 🗄️ Persistent state ⚙️ Backend logic 🌐 Direct web serving 🔐 Cryptographic authentication 🔗 Cross-chain interaction 🤖 Onchain AI That does NOT mean ICP eliminates software vulnerabilities. Code can still contain bugs. The important difference is reducing the number of external infrastructure layers that an application must depend upon. Instead of automatically building: Application + cloud VM + database + API gateway + centralized authentication + middleware + hosting + RPC infrastructure... ICP is moving toward applications where much of that stack can exist within one cryptographically verifiable decentralized environment. That reduces architectural complexity. And in cybersecurity, complexity creates attack surface. SAP will patch this vulnerability. Then another enterprise product will disclose another one. The strategic question is bigger: HOW MUCH INFRASTRUCTURE SHOULD AN APPLICATION NEED TO TRUST IN THE FIRST PLACE? That is why internet-computer:native matters. Not because it makes software invulnerable. Because it is attempting to redesign the stack itself. ☁️♾️🔥 ICP donations: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362 #ICP #InternetComputer #DFINITY #CyberSecurity #SAP #CloudSecurity #CVE202658231 #Blockchain #SovereignCloud #Web3 https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html

    Post summary

    CVE‑2026‑58231, a critical flaw in SAP Commerce Cloud, is actively exploited in the wild shortly after patch release, with SAP advising customers to apply the patch and offer IP filtering as a temporary mitigation.

    00060182
    1.7K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Attackers are actively exploiting CVE-2026-58231 in SAP Commerce Cloud days after the patch, enabling unauthenticated arbitrary code execution and likely targeting high-impact confidentiality, integrity, and availability losses. https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html

    Post summary

    The post confirms that CVE-2026-58231 is being actively exploited in SAP Commerce Cloud, allowing unauthenticated arbitrary code execution and posing serious confidentiality, integrity, and availability risks.

    01031931
    22.9K followersView on X
  • SOCRadar®@socradar
    Patch

    Perfect 10.0 CVSS alert for SAP Commerce Cloud. 🚨 CVE-2026-58231 allows unauthenticated arbitrary code execution via the Data Hub Adapter (affects v2211). If your import functionality is internet-facing, you are a prime target. Apply SAP Security Note 3771065 and redeploy immediately to mitigate the threat and strengthen your posture. Don't wait on this one! 🛠️ 🔍 Read more: https://hubs.la/Q04sJSNk0

    Post summary

    The post highlights a CVE that allows unauthenticated RCE on SAP Commerce Cloud and urges immediate application of Security Note 3771065 to mitigate the threat.

    11021592
    7.1K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2025-55182 CVE-2026-2796 CVE-2026-2768 CVE-2026-34910 CVE-2026-34909 CVE-2026-58231 CVE-2026-48907 ..🧵👇

    Post summary

    The post lists seven CVEs in an ExploitGrid digest with no further details on exploitation, patches, or technical characteristics.

    11020162
    47 followersView on X
  • Cyber Edition@CyberEdition
    Active Exploitation

    🚨 SAP Commerce Cloud flaw CVE-2026-58231 is already being probed just 3 days after patching. The CVSS 10.0 RCE needs no authentication, making exposed systems a prime target. #CyberSecurity #SAP Read more: https://thecyberedition.com/critical-sap-commerce-cloud-rce-flaw-cve-2026-58231-draws-active-exploitation-attempts/

    Post summary

    CVE-2026-58231 is a high‑severity RCE in SAP Commerce Cloud that is already being actively probed within days of patch release, highlighting real‑world attack attempts.

    00040199
    768 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・SAP Commerce Cloudの脆弱性が悪用される(CVE-2026-58231) https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html ・GeoServerの未修正ゼロデイが悪用される https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/ ・macOSの画面共有における脆弱性、モネロマイナーの展開に悪用される(CVE-2026-65400) https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/ ・SAP Commerce Cloudの脆弱性、パッチ適用から数日で悪用される(CVE-2026-58231) https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html <マルウェア・その他脅威> ・macOS狙う新種のマルウェアAmnesiaStealer、リモート操作でブラウザを乗っ取るhttps://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/ ・Appleが110か国のユーザーに警告 個人を狙う傭兵型スパイウェアの標的になった恐れ https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html ・脅威アクターMustang Panda、CoolClientマルウェアにカーネルルートキットを追加 https://securityaffairs.com/197274/apt/mustang-panda-upgrades-coolclient-with-a-kernel-rootkit.html ・大規模なDDoS攻撃により暗号化メッセージサービスThreemaが一時停止 https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-threema-secure-messaging-service/ <ランサムウェア> ・シェル社、Cl0pによるデータ侵害主張に関するインシデントを調査中 https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/ <データ侵害/サイバー犯罪> ・仏税務当局が高度なサイバー攻撃受け、納税者67万8千人分のデータが流出 https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html ・ハードウェアウォレットTrezor、配送業者ShipMonkのデータ侵害で顧客1万4千人に影響 https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/ ・英企業BeaconのCRMで発生したデータ侵害、1,000超の慈善団体に影響 https://www.securityweek.com/over-1000-charities-hit-by-beacon-crm-data-breach/ ・ポーランドの大手電子カルテシステムMyDrから患者データ1,800万人分が盗まれたか https://badcyber.com/hackers-claim-to-have-stolen-the-data-of-more-than-18-million-poles-from-mydr/ ・企業向けコミュニケーションプラットフォームRingCentral、データ侵害受け160万人に影響か https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/ ・2,500以上の組織が影響受けた攻撃、LiteLLMではなくTrivyの侵害が原因か https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/ <AI関連> ・AIプラットフォームのアカウントにおけるハッキングの有無を見分ける方法 https://techcrunch.com/2026/08/15/how-to-tell-if-your-ai-platforms-accounts-have-been-hacked/ ・アンソロピックがClaudeのAI生成テキストにウォーターマークを導入へ その方法とは https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/ ・米裁判所のAI使用を疑い、原告が訴訟に勝つため書類にプロンプトを挿入 https://arstechnica.com/tech-policy/2026/08/suspecting-court-of-using-ai-man-injected-prompts-in-filings-to-try-to-win-case/ ・自律型AIによる攻撃、重要インフラに「明白かつ差し迫った危険」をもたらす https://www.theregister.com/security/2026/08/14/autonomous-ai-attacks-pose-clear-and-present-danger-to-critical-infrastructure/5287594 <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・欧州・ブラジルでインターネットバンキングのハッキング容疑者を複数逮捕 https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil ・パキスタンでベトナム人・中国人の詐欺師258名を逮捕 氏名とパスポート情報も公開 https://ministryofcyberaffairs.com/news/pakistan-arrests-258-vietnamese-chinese-scammers-in-islamabad-for-running-transnational-scam-operations-6039eb03-cf86-4750-92e8-8eebf6acc100 ・OpenAI、ゴールドマン・サックス社員の犯罪計画に関するChatGPTの履歴をFBIに通報 https://futurism.com/artificial-intelligence/openai-reports-goldman-sachs-analyst-fbi-horrifying-chatgpt-conversations <リサーチ/攻撃手法/TTP> ・公開されている証明書ログから社内アプリを特定する https://naveensrinivasan.com/posts/2026-08-07-finding-hidden-internal-apps-through-public-certificate-logs/ ・n8nで特定のschemaNameからリモートコード実行を実践する方法(CVE-2026-33696) https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce ・LiteLLMサプライチェーン攻撃 — TeamPCPグループ使用の「SANDCLOCK」をTrivy GitHub Actionに仕込み、CI/CD環境から認証情報盗むキャンペーン https://www.resecurity.com/blog/article/the-litellm-supply-chain-attack-teampcp-sandclock-cicd-credential-harvesting-campaign-via-a-backdoored-trivy-github-action ・Cookie窃取が再び可能に https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/ ・Google SheetsをC2サーバーにしたPATCHCORDのスパイ活動、APT36が関与か https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html ・新たなLinuxボットネットEvooo1Bot、ルーターを通信中継ノードに https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/ ・Chrome DevToolsの悪用でWindowsの起動中ブラウザから認証済みセッションが乗っ取り可能に https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html <その他> ・Namecheapの大規模障害について https://jestr.ai/blog/namecheap-meltdown ・米司法当局、2029年から盗聴におけるハッキングツールの使用状況を公表へ https://www.scworld.com/brief/u-s-judiciary-to-publicly-disclose-use-of-hacking-tools-in-wiretaps-starting-2029 ・Google Cloud、2029年に移行完了を目標としたポスト量子暗号ロードマップを発表 https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/ ・米司法当局、政府のスパイウェア使用頻度を公表へ https://techcrunch.com/2026/08/14/us-courts-will-start-publishing-how-often-the-government-uses-spyware/

    Post summary

    The article highlights that CVE-2026-58231 and CVE-2026-65400 are actively exploited in the wild, with patches applied but still vulnerable. No sample PoC or exploit code is shared, and no false positive claims are made.

    100212.3K
    1.3K followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: SAP Commerce Cloud CVE-2026-58231 (CVSS 10) under active exploit — patch now. macOS screensharingd 0-day grants root, fueling cryptomining on ~40K hosts. Lazarus rides AFD.sys kernel UAF vs defense contractors — CISA deadline Aug 25. Gov: IFP's 23-pt AI R&D blueprint (1,100+ backers) pushes 72-hr disclosure, 4x CAISI funding. Strategic: OpenAI's eval agents escaped sandbox, breached Hugging Face undetected 2.5 days — ungoverned agentic risk. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260816/

    Post summary

    The briefing highlights that SAP Commerce Cloud CVE‑2026‑58231 is being actively exploited worldwide with a CVSS 10 severity, while also reporting several zero‑day and kernel vulnerabilities; patches are now available for the flagged CVE.

    02020665
    18.9K followersView on X
  • AlexAImaginator@TraffAlex
    Active Exploitation

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — August 15, 2026 1️⃣ MACOS SCREEN SHARING FLAW EXPLOITED FOR MONERO MINING Attackers are actively exploiting CVE-2026-65400, a vulnerability in Apple's macOS Screen Sharing feature, to install Monero cryptocurrency miners on compromised systems. The flaw affects Macs with port 5900 exposed to the internet, allowing unauthenticated remote access. Apple has already released emergency updates to patch the vulnerability, but security researchers warn that many internet-facing machines may remain unpatched and at risk. System administrators should immediately verify their macOS installations are up to date and ensure VNC ports are not unnecessarily exposed. 🔹 @TheHackersNews 2️⃣ SABLE SQUIRREL SPENDS $7 MILLION ON EXPIRED DOMAINS FOR CYBERCRIME A sophisticated cybercrime group known as Sable Squirrel has been identified spending nearly $7 million acquiring expired domains to build a massive infrastructure for malicious operations. The group now controls over 10,000 domains that facilitate illegal streaming services, online gambling platforms, and malware command-and-control communications. At least 31,000 distinct malware samples have been observed communicating with these domain networks, making it one of the largest domain-based cybercrime infrastructures documented to date. 🔹 @TheHackersNews 3️⃣ SAP COMMERCE CLOUD CRITICAL FLAW SEEKING ACTIVE EXPLOITATION CVE-2026-58231, a CVSS 10.0 critical vulnerability in SAP Commerce Cloud, is already under active exploitation attempts just three days after the patch was released. The flaw allows unauthenticated attackers to execute arbitrary code remotely on affected systems. Security researchers emphasize that this is a race against time — organizations running SAP Commerce Cloud must apply the vendor patch immediately, as the exploit code is circulating in threat actor communities and being actively leveraged in targeted campaigns. 🔹 @TheHackersNews 4️⃣ GEOSERVER PATCHES ACTIVELY TARGETED SQL INJECTION REGRESSION GeoServer has released a patch for an actively exploited SQL injection vulnerability affecting PostGIS-backed deployments. The flaw is a regression of CVE-2023-25158, meaning organizations that previously fixed the original issue may have been re-exposed by subsequent updates. The vulnerability allows attackers to execute arbitrary SQL commands against the database backend, potentially leading to full data compromise. All GeoServer administrators using PostGIS should update immediately and verify their deployment is no longer vulnerable. 🔹 @TheHackersNews 5️⃣ HACKERS ARRESTED OVER €30 MILLION BANK FRAUD Law enforcement agencies have arrested several individuals responsible for a €30 million bank fraud scheme that exploited a vulnerability in a critical service provider's infrastructure. The attackers leveraged the flaw to intercept and manipulate financial transactions across multiple banking institutions. The arrests highlight the growing importance of securing third-party service providers in the financial supply chain, as a single compromised vendor can cascade into massive losses across their entire customer base. 🔹 @BleepinComputer 6️⃣ SANDWORM DEPLOYS TROJANIZED WIREGUARD AGAINST UKRAINIAN IT WORKERS The Sandworm threat group, linked to Russian military intelligence, has launched a targeted campaign against Ukrainian IT professionals using trojanized WireGuard VPN clients. Operating through its UAC-0145 cluster, the group is conducting fake job interviews to distribute the compromised software. This social engineering approach makes the attack particularly effective, as victims believe they are participating in legitimate recruitment processes. The use of WireGuard — typically a trusted open-source VPN tool — demonstrates adversaries' increasing sophistication in weaponizing legitimate software. 🔹 @Huntio 7️⃣ EVOOO1BOT LINUX BOTNET TURNS ROUTERS INTO TRAFFIC RELAY NODES A new Mirai-based Linux botnet called Evooo1Bot is targeting internet-facing gateways and compromising routers to convert them into SOCKS5 traffic relay nodes. This modular malware allows attackers to route their malicious traffic through compromised infrastructure, making attribution and blocking significantly more difficult. Network operators should ensure their gateway devices are running firmware with the latest security patches and monitor for unusual outbound traffic patterns that may indicate infection. 🔹 @BleepinComputer 💭 The threat landscape this week demonstrates a clear pattern: attackers are weaponizing trust. Whether it's trojanized open-source VPN software, expired domains that look legitimate, or service providers whose customers assume are secure — the common thread is exploiting relationships and tools that organizations rely on without question. Defenders need to shift from trusting by default to verifying continuously. Which of these threats should your organization prioritize patching first? 👇 #Cybersecurity #InfoSec #ZeroDay #DataBreach #ThreatIntelligence #OpenSource #Privacy

    Post summary

    The post highlights multiple CVEs—especially macOS Screen Sharing (CVE-2026-65400) and SAP Commerce Cloud (CVE-2026-58231)—that are already being actively exploited in the wild, with vendors issuing patches. Organizations should prioritize immediate patching and verification to mitigate these critical threats.

    01030284
    2.7K followersView on X

Explore more