Threat Brief — 2026-08-18 — WMIC finally killed, GeoServer patched
Executive summary: Microsoft has begun permanently removing WMIC from Windows 11 builds, closing a long-abused living-off-the-land vector that malware has exploited for years. The GeoServer SQL injection zero-day that was actively exploited with no fix now has a patch available — prioritise deployment. A Microsoft 365 search outage is degrading Outlook, SharePoint, and OneDrive functionality for some tenants. Separately, testing reveals DeepSeek hallucinates misinformation about Taiwan at twice the rate of ChatGPT, a reminder that model selection carries disinformation risk.
Top items
- GeoServer SQL injection zero-day — patch now available (DEVELOPING). A critical CVSS 9.8 SQLi flaw in GeoServer's GeoTools PostGIS
jsonArrayContainsfunction remains actively exploited, but a patch is now available where none existed yesterday. User-supplied values are interpolated directly into PostgreSQLjsonb_path_exists(), enabling RCE if the DB connects as superuser. Technical exploitation details are public. First reported 2026-08-17 by The Hacker News when no patch existed; the patch release is today's development. (src: The Hacker News)
- Microsoft permanently removes WMIC from Windows 11. Microsoft has pulled the Windows Management Instrumentation Command-line utility from Windows 11 24H2, 25H2, and beta builds. WMIC has been a favourite LOLBin for malware authors for years — its removal closes a loophole that allowed attackers to execute commands that antivirus treated as legitimate administrative activity. Organisations should audit any operational dependencies on WMIC before upgrading and migrate scripts to PowerShell
Get-CimInstanceequivalents. (src: BleepingComputer)
- Microsoft 365 search outage affecting Outlook, SharePoint, and OneDrive. Microsoft has confirmed an active outage degrading search functionality across Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. No security root cause has been indicated; this is an availability event but may prompt users to seek workarounds that bypass security controls. (src: BleepingComputer)
- DeepSeek produces Taiwan misinformation at 2× the rate of ChatGPT. NewsGuard testing found that Chinese chatbot DeepSeek feeds users inaccurate or propagandistic information about Taiwan twice as often as ChatGPT. For organisations evaluating Chinese-origin LLMs for internal use, this underscores the need to treat model outputs as untrusted and to implement fact-checking guardrails. (src: SecurityLab)
- Bot traffic surpasses human traffic globally for the first time. A TechCloud report indicates automated bot traffic now exceeds human internet traffic — a milestone with implications for credential stuffing, scraping, API abuse, and the diminishing reliability of volume-based DDoS and traffic metrics. Security teams should validate that rate-limiting and bot-management controls are calibrated for a bot-majority traffic baseline. (src: Anquanke)
Themes
LOLBin era contracting. Microsoft's removal of WMIC follows a pattern of the company slowly eliminating legacy dual-use utilities (VBScript deprecated earlier this year). Attackers who relied on WMIC for lateral movement and execution will need to adapt; defenders should expect short-term spikes in alternative techniques as adversaries retool.
AI trust surface expanding. Between DeepSeek's measurable disinformation bias, the Anthropic agent turf-war findings (ongoing), and a new AI-security weekly report from 360 TIC, the AI trust surface — model bias, agent autonomy, supply-chain risk — continues to generate novel threat vectors distinct from traditional cyber risks.
