Weekly review

ThreatNoir Weekend Brief — August 15

2026-08-15Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 15, 2026

The threat landscape continues to intensify as critical vulnerabilities across enterprise software platforms face active exploitation within days of disclosure. Organizations worldwide are grappling with a mounting wave of zero-day and recently patched flaws that attackers are leveraging at an accelerating pace.

Max Severity SAP Commerce Cloud Flaw Now Targeted in Attacks

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud has entered active exploitation just three days after a patch became available. Threat intelligence company Defused has confirmed that attackers are already weaponizing the flaw against production environments. The vulnerability, tracked as CVE-2026-22732 along with related CVEs CVE-2026-34263, CVE-2026-44761, and CVE-2026-58231, represents a critical supply chain risk given SAP's widespread deployment across enterprise organizations globally. Source: Max severity SAP Commerce Cloud flaw now targeted in attacks

APT Group HoneyMyte Upgrades CoolClient With Kernel-Level Windows Rootkit

Advanced persistent threat group HoneyMyte has significantly enhanced its CoolClient backdoor with a sophisticated kernel-mode rootkit driver capable of hiding malicious processes, files, and network connections from security monitoring tools and threat analysts. This evolution demonstrates the group's commitment to maintaining persistent access and evading detection on compromised systems. The upgraded malware employs multiple techniques including process injection, command-line interface capabilities, and persistence mechanisms to establish deep system-level control. Source: APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Hackers Exploiting Unpatched GeoServer Zero-Day

Active exploitation of an unpatched zero-day vulnerability in GeoServer has been confirmed in the wild. The security defect is an SQL injection flaw that enables attackers to achieve remote code execution on vulnerable instances. The rapid weaponization of this open-source vulnerability underscores the continued risk posed by unpatched systems in critical infrastructure environments. Source: Hackers Exploiting Unpatched GeoServer Zero-Day

Global Threat Campaign Hits Critical VMware vCenter Flaw

A widespread global threat campaign has been actively exploiting CVE-2026-59310, a critical vulnerability in VMware vCenter, since earlier this month. Security researchers warn that patching alone may prove insufficient to fully mitigate the threat, suggesting that attackers may have already established persistent footholds in compromised environments prior to patch deployment. Organizations running affected vCenter instances should assume potential compromise and conduct thorough forensic investigations beyond standard patching procedures. Source: Global Threat Campaign Hits Critical VMware vCenter Flaw

The convergence of multiple critical vulnerabilities under active exploitation demands immediate action from security teams. Organizations must prioritize rapid vulnerability assessment, expedited patching cycles, and comprehensive threat hunting to identify and remediate any existing compromise.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
MITRE ATT&CK5
  • IOCTL command dispatcher for driver communication
  • Command execution via wmic for Defender exclusions
  • DLL Side-Loading (renaming Sangfor executable to defender.exe)
  • Scheduled task for AutoRun persistence
  • Process Injection into synchost.exe
Malware2
  • CoolClient
    Backdoor family updated with kernel-mode rootkit
  • PlugX
    Used as initial post-compromise implant to deploy CoolClient