Info
2026-08-17 14:03Z · last 4h · 37 findings
· glm-5.2:cloud
Threat Brief — 2026-08-17 — Zero-Days Outpace Patches
Executive summary: Multiple unpatched zero-days are under active exploitation today — GeoServer SQLi-to-RCE and a WordPress XSS2Shell flaw affecting 11,000+ sites lead the pack. A China-nexus APT is chaining a VMware vCenter flaw into Babuk-derived ransomware, while the PATCHCORD backdoor quietly targets South Asian critical infrastructure. On the mobile front, an Unisoc VoLTE exploit chain grants full Android kernel access with no vendor fix, and the DragonDoll spyware campaign has spread across 26 countries. Enterprise AI adopters should note a new MCP server secret-exposure advisory and the first court precedent punishing hidden prompt injection in legal filings.
Top items
- GeoServer zero-day under active exploitation (no CVE, no patch). An unpatched SQL injection flaw in the open-source GeoServer platform is being exploited on production servers for remote code execution. watchTowr confirmed attempts within hours of disclosure. No fix is available. (src: The Hacker News) · (src: SecurityLab)
- XSS2Shell vulnerability hits 11,000+ WordPress login pages. A newly disclosed flaw enables server-level access via WordPress login pages without any account. Attackers are actively targeting a large fleet of sites. (src: Anquanke)
- China-nexus APT exploits VMware vCenter, deploys Babuk-derived ransomware. CVE-2026-59310KEV·R (CVSS 9.8) in Broadcom VMware vCenter is being exploited by a suspected China-linked APT to drop Babuk-derived ransomware. The flaw was recently patched — apply immediately if not already done. (src: The Hacker News)
- Unisoc VoLTE video-call exploit chain gives full Android kernel access — no fix available. SSD Secure Disclosure published a two-stage exploit chain targeting Unisoc modem firmware via a VoLTE video call, achieving full kernel access. The chipset maker has not issued a fix. (src: The Hacker News)
- PATCHCORD backdoor targets Afghan telecom and Indian critical infrastructure. A previously undocumented backdoor dubbed PATCHCORD is being deployed against Afghan telecom providers and South Asian critical infrastructure in an ongoing campaign. (src: The Hacker News)
- Chrome DevTools Protocol technique enables live session hijacking on Windows. A post-exploitation method activates CDP inside a running Chrome or Edge process on Windows, giving operators access to cookies, saved credentials, and authenticated sessions in real time. (src: The Hacker News)
- Critical AMD processor vulnerability disclosed with no fix forthcoming. A single-bit flaw collapses AMD chip protections; no exploit existed prior to disclosure, but no security fixes are planned. (src: SecurityLab)
- DragonDoll Android spyware infected devices across 26 countries. Disguised as a Chrome update, DragonDoll abuses Android accessibility services to read Telegram, WhatsApp, and Signal messages. Campaign spans 26 countries. (src: SecurityLab)
- macOS Safari tab-reading flaw — third-party apps silently read open tabs. Third-party macOS applications can read other apps' Safari tabs without permission prompts or system warnings. Patch now. (src: SecurityLab)
- MCP servers can expose enterprise secrets via plaintext configs, over-permissioned access, and prompt injection. As organisations adopt AI agents, MCP servers are leaking credentials before security teams know they're running. (src: The Hacker News)
- Clop ransomware claims data theft from Philips and GE. Both conglomerates confirmed they are investigating Clop's breach and data-theft claims. (src: BleepingComputer)
- French tax authority (DGFiP) data breach exposes 678,000 individuals. An attacker accessed DGFiP systems and stole personal data belonging to 678,000 people. (src: BleepingComputer)
- Large-scale recruitment phishing uses BitB windows to steal Google/Facebook credentials. CTM360 uncovered 3,000+ phishing URLs using Browser-in-the-Browser fake windows and fake interview-scheduling pages. (src: The Hacker News)
- First court precedent: hidden AI prompt injection in legal filing punished. A court banned a plaintiff from electronic filing after discovering a hidden prompt designed to manipulate AI tools processing the document. (src: SecurityLab)
- Windows Server 2022 reaches end of mainstream support in 60 days. Microsoft reminded IT admins that mainstream support ends October 2026, after which it shifts to extended support only. (src: BleepingComputer)
Themes
- Patch-gap exploitation is the dominant pattern. GeoServer (no patch), Unisoc (no fix), AMD (no fix), and VMware vCenter (patched but actively exploited) all illustrate attackers moving faster than vendors. Prioritise edge-facing services and apply available patches immediately.
- Mobile and endpoint attack surface is expanding. Unisoc VoLTE kernel exploit, DragonDoll spyware, Safari tab-reading, and Chrome DevTools session hijacking all target the client side — particularly Android and macOS — often with no user interaction required.
- AI tooling is becoming both attack vector and legal risk. MCP server secret exposure and the first prompt-injection court precedent signal that AI-adjacent infrastructure now carries tangible security and compliance liabilities.
