DJBSEC's CyberNews 2026-08-17
Today’s daily news covers the following categories: Vulnerability Malware Data Breach Authentication Privacy Nation-State/APT Threat Intelligence
Critical SAP Commerce Cloud Flaw Exploited Days After Patch
Vulnerability
Attackers are actively exploiting CVE-2026-58231, a maximum-severity SAP Commerce Cloud vulnerability, just days after SAP released a security update. The CVSS 10.0 flaw results from insufficient authorization checks and input validation and can allow an unauthenticated attacker to execute arbitrary code and compromise internal application components. Researchers at Defused Cyber detected exploitation attempts against their honeypots only three days after the patch was released, despite no public proof-of-concept exploit being available. The identity of the attackers remains unknown, although critical SAP vulnerabilities have historically attracted both nation-state groups and ransomware operators. Organizations running affected SAP Commerce Cloud environments should prioritize the available security update because exploitation is already occurring in the wild.
AmnesiaStealer Gives Attackers Live Control of macOS Browser Sessions
Malware
A new macOS information stealer called AmnesiaStealer goes beyond traditional credential theft by allowing attackers to remotely control a victim’s already authenticated browser sessions. Distributed through ClickFix attacks using fake GitHub download pages, the malware steals passwords, cryptocurrency wallets, Apple Notes, documents, Keychain data, Telegram sessions, and information from 16 Chromium-based browsers. Its standout capability clones a victim’s Chromium profile into a hidden browser and uses the Chrome DevTools Protocol to give attackers live keyboard, mouse, navigation, and cookie control. Because the hidden browser operates on the infected Mac, attackers can preserve the victim’s browser, device, and network characteristics while accessing authenticated websites. Researchers say it is the first documented macOS malware combining cloned Chromium profiles with this type of interactive remote browser control.
Azure Credential Theft Campaign Exposes Millions of Corporate Records
Data Breach
A threat actor known as TheHatman claims to be selling millions of corporate directory records obtained from Azure and Entra environments belonging to major global companies. Listings reportedly include more than 1.7 million records associated with McDonald’s, roughly 800,000 from Tata Consultancy Services, 425,000 from Vodafone, and additional records linked to several other large enterprises. The exposed information reportedly includes names, corporate email addresses, phone numbers, job titles, reporting structures, service accounts, and in some cases Global Administrator information. Researchers have identified infostealer-compromised Azure credentials associated with several affected organizations, although the exact initial-access method remains unconfirmed. The structured directory information could provide attackers with valuable intelligence for spear-phishing, business email compromise, privilege escalation, and future ransomware operations.
AWS Ending Email Validation for Public TLS Certificates
Authentication
AWS Certificate Manager is phasing out email-based domain validation for public TLS certificates as the industry moves toward stronger DNS-based verification. Starting March 31, 2027, AWS will no longer allow newly requested certificates to use email validation, with automated email-based renewals ending September 30 of that year. The change follows the CA/Browser Forum’s decision to eliminate email validation, with major browsers scheduled to distrust certificates validated through email beginning March 15, 2028. Email validation has long presented security concerns because compromised mail routing, intercepted verification messages, and outdated administrative contacts can potentially undermine domain ownership verification. AWS is allowing customers to transition existing certificates to DNS validation without reissuing them or changing certificate identifiers attached to services such as load balancers and CloudFront.
Microsoft Moves Toward Unified Consumer and Enterprise Copilot App
Privacy
Microsoft is continuing to consolidate its consumer and enterprise Copilot experiences into a more unified application spanning AI chat, productivity applications, files, collaboration, and AI agents. The Microsoft 365 Copilot app brings together Word, Excel, PowerPoint, Outlook, PDFs, cloud files, Copilot Chat, and custom agents, while Microsoft’s consumer Copilot experience is also being updated. Microsoft says personal accounts and organizational accounts managed through Entra will remain separated, with enterprise security, compliance, tenant administration, and commercial data protections continuing to apply. The unified interface nevertheless makes identity switching, data classification, file-sharing permissions, and employee awareness of account boundaries increasingly important for security teams. Microsoft is also retiring several consumer Copilot features, including Group Chat, Podcasts, and Deep Research, beginning August 18.
Attackers Buy Expired Domains to Deliver Malware and Hide C2 Infrastructure
Malware
Cybercriminals are increasingly purchasing expired domains because their established histories can help malicious infrastructure appear more trustworthy to security systems and users. Infoblox says roughly 65,000 previously owned domains are re-registered each day, and these so-called dropcatch domains represented nearly 20 percent of new registrations during the first half of 2026. Expired domains can retain reputation signals, backlinks, residual web traffic, incoming email, and lingering DNS relationships that attackers can exploit for scams, malware distribution, and command-and-control infrastructure. Researchers highlighted a threat actor called Sable Squirrel that has reportedly spent nearly $7 million acquiring expired domains and controls more than 10,000 of them. Some of that infrastructure has been connected to malware families including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
Mustang Panda Adds Kernel Rootkit to CoolClient Espionage Malware
Nation-State/APT
China-linked threat group Mustang Panda has upgraded its CoolClient backdoor with a signed kernel-mode driver designed to make the malware significantly more difficult to detect and remove. The driver can hide malicious processes, files, and registry entries while communicating directly with the user-mode backdoor through IOCTL requests. CoolClient already supports capabilities including keylogging, clipboard theft, credential harvesting, file management, reconnaissance, and a plugin architecture, making the new kernel-level stealth particularly significant. Kaspersky observed the updated malware in intrusions involving Pakistan, Mongolia, and Myanmar, while the broader victim set includes government entities and systems in Russia. In one campaign, attackers also created fake Windows Defender directories and added Defender exclusions before using DLL sideloading to execute the malware.
Large-Scale DDoS Attacks Cause Major Threema Outages
Threat Intelligence
Secure messaging provider Threema suffered a series of large-scale distributed denial-of-service attacks that caused significant service disruptions and intermittent outages. The service was unavailable for roughly four hours Tuesday evening, with additional problems continuing into Wednesday as attackers repeatedly changed their sources and attack patterns. Threema’s colocation provider, Nine, was also targeted, although organizations using the self-hosted Threema On-Prem product were unaffected. The company deployed additional upstream DDoS protection on August 14 to filter malicious traffic before it reached its infrastructure. Threema says it remains unclear whether it was the primary target or one of several organizations affected by the campaign.
China’s Zhipu Claims GLM-5.3 Outperforms U.S. AI Models at Vulnerability Discovery
Threat Intelligence
Chinese AI company Zhipu says its new GLM-5.3 model can outperform leading American AI systems on certain cybersecurity vulnerability-discovery tasks. According to company-provided benchmark results, GLM-5.3 surpassed Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol on CyberGym, which measures performance against real-world cybersecurity challenges. Zhipu says testing across 269 real-world projects identified 2,436 vulnerabilities, including 1,097 medium-to-high severity issues, with some previously undiscovered flaws reportedly dating back decades. The company says the model demonstrated an ability not only to identify individual vulnerabilities but also to reason across multiple stages and construct complete exploitation chains. GLM-5.3 performed worse than competing Western models on some other coding and security benchmarks, but its results illustrate how rapidly advanced offensive and defensive AI capabilities are spreading globally.
Enjoy Reading This Article?
Here are some more articles you might like to read next: