Threat Brief — 2026-08-12 — Exploited Criticals and Supply-Chain Backdoors
Executive summary: Today's intake is dominated by actively exploited critical vulnerabilities and supply-chain compromises. VMware vCenter (CVSS 9.8) and SAP Commerce Cloud (CVSS 10.0) both have patches available but are seeing or risk in-the-wild exploitation, while a malicious open-source VPN manager backdoored 650+ servers. A Microsoft Defender patch-bypass zero-day PoC surfaced, and Cisco ASA/FTD VPN devices are being crashed by attackers in the field. Patch velocity matters more than usual this cycle.
Top items
- VMware vCenter CVE-2026-59310KEV·R (CVSS 9.8) — actively exploited. A directory-traversal flaw in Broadcom VMware vCenter is being leveraged by threat actors for persistent remote access. Patches are available; prioritise vCenter upgrades immediately given active exploitation confirmed by QUIRSO. (src: The Hacker News)
- SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) — unauthenticated RCE. A maximum-severity flaw in the Data Hub Adapter allows unauthenticated arbitrary code execution. SAP has released patches; any internet-facing Commerce Cloud instance should be treated as high-priority. (src: The Hacker News)
- Cisco ASA/FTD VPN DoS — exploited in the wild. A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software is being actively exploited to trigger remote denial-of-service against VPN endpoints. No KEV listing confirmed yet, but Cisco's own advisory confirms wild exploitation. (src: The Hacker News)
- ShieldBreak — Microsoft Defender patch bypass PoC. A researcher released a proof-of-concept for a zero-day in Microsoft Defender that bypasses recent patches and yields SYSTEM-level access. Treat as unpatched until Microsoft confirms and issues a fix. (src: The Hacker News)
- FirewallFalcon VPN manager backdoor — 650+ servers compromised. A free open-source VPN manager was tampered with to subvert subscription checks and give attackers control over client traffic. Over 650 servers are linked to the campaign. Organisations running FirewallFalcon should audit their deployments immediately. (src: SecurityLab)
- Malicious LiteLLM PyPI releases — 2,100+ orgs exposed. Two malicious LiteLLM packages on PyPI carried credential-stealing code targeting cloud keys, SSH keys, Kubernetes tokens, and database passwords. The packages lived for ~40 minutes in March but the blast radius is significant. Review pip logs and rotate secrets if installed. (src: The Hacker News)
- Microsoft August Patch Tuesday — 400 vulns, 3 zero-days. This month's Patch Tuesday addresses roughly 400 vulnerabilities including three zero-days. Combined with the ShieldBreak Defender PoC, endpoint patching cadence is the priority this week. (src: SecurityLab)
- Delta Wi-Fi deauth attack on DEF CON attendee flight. Delta Air Lines is investigating a rogue Wi-Fi network ("Delta WiFi Fast") detected on flight 591 from Las Vegas to Atlanta carrying DEF CON attendees. Likely a deauth/evil-twin attempt; a reminder to disable auto-connect on conference travel. (src: Xakep)
- Kazakhstan massive data leak — 15M people affected. A dark-web archive containing 47M rows across 187 tables with passport, phone, and job data for approximately 15M Kazakhstanis (~75% of the population) has surfaced. (src: SecurityLab)
- CAV3RN chameleon virus — Google Apps Script C2. Kaspersky discovered a virus that uses Google Apps Script for command-and-control, swapping communication channels on the fly to evade antivirus detection. Novel abuse of legitimate Google infrastructure for C2. (src: SecurityLab)
- RadarTrevog drone-raid app leaked bank codes. An app marketed to protect against drone raids was actually exfiltrating bank codes and seizing smartphone control from its users. (src: SecurityLab)
Themes
Exploitation before patches stick. Multiple critical vulnerabilities (vCenter, Cisco ASA/FTD, Microsoft Defender) are being exploited in the wild either before or despite patch availability. The window between disclosure and exploitation continues to narrow — prioritise patching internet-facing infrastructure within hours, not days.
Supply-chain trust erosion. FirewallFalcon (open-source VPN manager), LiteLLM (PyPI), and RadarTrevog (mobile app) all demonstrate attackers compromising the software distribution layer itself. Verify integrity signatures and audit package provenance for any externally sourced tooling.
Legitimate services as C2 channels. CAV3RN's use of Google Apps Script for command-and-control follows an established pattern of adversaries abusing trusted cloud platforms to blend with normal traffic. Egress monitoring for Google Apps Script and similar APIs warrants attention.
