Weekly Security Roundup — week ending 16 August 2026

Security Stories — Week Ending 16 August 2026

Active Exploitation

macOS Screen Sharing flaw under active exploitation — Dutch NCSC confirmed; attackers deploying Monero miners on internet-exposed systems with port 5900 open. Patch immediately.

Max-severity SAP Commerce Cloud RCE exploited within 3 days of patch — Sets a benchmark: ~72 hours from disclosure to active exploitation for critical enterprise flaws.

GeoServer zero-day under active exploitation — SQL injection enabling RCE; no patch available. Apply network mitigations.

Supply Chain

ChainDrop npm worm evades standard defences — New Shai-Hulud variant poisons hundreds of packages while leaving minimal traces in source repositories.

Trivy, not LiteLLM, behind 2,500-org compromise — The open-source vulnerability scanner was the actual vector; 95%+ of victims compromised before malicious LiteLLM packages appeared.

Breaches

RingCentral: 1.6M accounts exposed by ShinyHunters — Social engineering attack in July; PII now publicly dumped.

French tax authority breach — 2M taxpayer records stolen — Breach in June; advertised on criminal forum by alias ZeroBytes.

Trezor: 14,000 customers' shipping data via ShipMonk breach — Physical targeting risk for hardware wallet owners.

1,000+ UK charities hit by Beacon CRM breach — Root cause: AWS key exposed in public JS build artifacts.

Scottish Crown Office: 300 staff data exposed via supplier breach

APT & Nation-State

HoneyMyte (Mustang Panda) adds kernel-level rootkit to CoolClient backdoor — Major capability upgrade for Chinese APT active across Asia.

Apple sends new mercenary spyware threat notifications — New wave of targeted alerts; recipients should treat as confirmed compromise.

Autonomous AI agents used to hack government and energy systems — Open-source AI agents autonomously attacked critical infrastructure in early July. No longer theoretical.

New Zealand NZSIS: China using space facilities for intelligence gathering


Key Themes

Patch velocity: 72 hours or less from disclosure to active exploitation is now standard. Monthly patch cycles for internet-facing systems are no longer defensible.

Supply chain depth: ChainDrop evades detection, Trivy as a vector, AWS keys in build artifacts — organisations inherit risk they cannot fully audit.

Autonomous AI attacks: The shift from AI-assisted to fully autonomous offensive operations happened this week in documented incidents. Defensive frameworks have not kept pace.


CISA KEV — No New Additions This Week

Last entries: 11 August 2026 — CVE-2026-68820 (Windows kernel, Lazarus), CVE-2026-20349 (Cisco ASA), CVE-2026-72898 (Metabase RCE).

View the full CISA KEV catalogue →

Show Comments