This day 02:08 06:08 10:09 14:09 18:05 22:05
⚠ exploit status: CVE-2026-59310 · KEV·R
Info  2026-08-12 10:09Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-12 — Exploited Criticals and Supply-Chain Backdoors

Executive summary: Today's intake is dominated by actively exploited critical vulnerabilities and supply-chain compromises. VMware vCenter (CVSS 9.8) and SAP Commerce Cloud (CVSS 10.0) both have patches available but are seeing or risk in-the-wild exploitation, while a malicious open-source VPN manager backdoored 650+ servers. A Microsoft Defender patch-bypass zero-day PoC surfaced, and Cisco ASA/FTD VPN devices are being crashed by attackers in the field. Patch velocity matters more than usual this cycle.

Top items

Themes

Exploitation before patches stick. Multiple critical vulnerabilities (vCenter, Cisco ASA/FTD, Microsoft Defender) are being exploited in the wild either before or despite patch availability. The window between disclosure and exploitation continues to narrow — prioritise patching internet-facing infrastructure within hours, not days.

Supply-chain trust erosion. FirewallFalcon (open-source VPN manager), LiteLLM (PyPI), and RadarTrevog (mobile app) all demonstrate attackers compromising the software distribution layer itself. Verify integrity signatures and audit package provenance for any externally sourced tooling.

Legitimate services as C2 channels. CAV3RN's use of Google Apps Script for command-and-control follows an established pattern of adversaries abusing trusted cloud platforms to blend with normal traffic. Egress monitoring for Google Apps Script and similar APIs warrants attention.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db