Threat Brief — 2026-08-14 — Active exploitation and breach fallout
Executive summary: A maximum-severity SAP Commerce Cloud RCE patched just three days ago is now confirmed under active attack — if you haven't patched, treat it as imminent. RingCentral disclosed a ShinyHunters breach affecting 1.6 million accounts, and Shell is investigating Clop's claim of 89 GB stolen. On the research side, an unpatchable hardware flaw in Loongson processors leaks AES keys from the kernel, and New Zealand's intelligence service exposed a Chinese plan to covertly militarise a civilian telescope.
Top items
- SAP Commerce Cloud CVE-2026-582 (CVSS 10.0) now actively exploited. The unauthenticated RCE patched on 2026-08-12 has moved from "patch available" to in-the-wild attacks per threat-intel firm Defused. This is a genuine escalation from the initial disclosure. Any internet-facing SAP Commerce Cloud instance remains a high-priority target. (First reported 2026-08-12 by The Hacker News; developing — active exploitation now confirmed.) (src: BleepingComputer)
- RingCentral breach exposes 1.6 million accounts. ShinyHunters stole personal information from 1.6M RingCentral accounts after compromising the company in July, per Have I Been Pwned. Extortion group involvement and the scale make this a notable data-theft event. (src: BleepingComputer)
- Shell investigates Clop ransomware data-theft claim (89 GB). Shell confirmed it is investigating a potential incident after Clop claimed 89 GB of stolen data. Whether Clop has deployed ransomware or is pursuing pure extortion is not yet clear. (src: BleepingComputer)
- LoongLeak: unpatchable hardware flaw in Loongson processors leaks kernel AES keys. A new L1-cache side-channel vulnerability bypasses ASLR and extracts AES keys from the Loongson kernel. Because it is a hardware bug, there is no microcode or software patch — mitigation requires architectural redesign. Relevant to any deployment using Loongson CPUs in sensitive or multi-tenant environments. (src: SecurityLab)
- Bybit sues North Korean government over $1.5B crypto theft. Bybit filed suit in US court, which has blocked transfer of a portion of the stolen assets. A US court blocking crypto movement is a rare legal development in state-sponsored theft cases. (src: SecurityLab)
- NZSIS exposes Chinese plan to convert New Zealand telescope into military spy post. New Zealand's intelligence service revealed a Chinese observatory's covert plan to collect military data under the cover of civilian astronomy — a notable state-espionage disclosure in the Pacific region. (src: SecurityLab)
- ChatGPT "Computer History" tracks all Mac activity. OpenAI's new feature lets ChatGPT record everything a user does on their Mac. The privacy implications for enterprise environments where ChatGPT desktop clients are installed are significant — this warrants a review of endpoint AI assistant policies. (src: SecurityLab)
Themes
Patch-to-exploit window keeps shrinking. SAP Commerce Cloud went from patch to active exploitation in under three days, mirroring the pattern seen with SharePoint and VMware vCenter earlier this week. The window for patching critical internet-facing flaws is effectively zero.
Breach disclosure cascade. RingCentral (1.6M accounts), Shell (89GB claimed), and the Bybit legal action all landed in the same cycle — extortion groups (ShinyHunters, Clop) and state actors (Lazarus/ DPRK) are simultaneously pressuring major organisations, each through different playbooks.
Hardware trust assumptions challenged. LoongLeak follows the malicious-SIM research from earlier this week, underscoring that silicon-level and baseband trust models remain underexplored attack surfaces with no software remediation path.
