The gap between “patch released” and “exploited in the wild” keeps shrinking. Today’s digest has a maximum-severity SAP flaw getting probed days after the fix shipped, an unrelated zero-day with no fix at all seeing the same treatment, and a macOS bug patched last week already farming cryptocurrency on internet-facing Macs. Add a SaaS breach whose stolen data just went live and a fresh round of nation-state spyware alerts, and the pattern for mid-August is clear: assume active exploitation starts the moment a vulnerability becomes public, not weeks later.
Vulnerability watch: SAP Commerce Cloud’s 10.0-severity flaw is under attack days after the patch — and an unpatched GeoServer zero-day is getting hit in parallel
CVE-2026-58231, rated a maximum 10.0 on CVSS, affects the Data Hub Adapter component that SAP Commerce Cloud uses to exchange and import data with external systems. Insufficient authorization checks let an unauthenticated attacker abuse a default authentication client and submit crafted input to functions that don’t validate it, reaching arbitrary code execution with no credentials needed. Honeypot telemetry from Defused Cyber shows exploitation attempts started hitting its sensors just three days after SAP shipped the patch. The Hacker News · BleepingComputer
Separately and unrelated to SAP, an unpatched GeoServer zero-day — a SQL injection flaw in the open-source geospatial data server that can lead to remote code execution — is also seeing active exploitation attempts, first disclosed August 12. No fix exists yet, so if you run GeoServer, the only mitigation right now is restricting network exposure and watching for anomalous query patterns until an update lands. The Hacker News
If you run SAP Commerce Cloud, patching CVE-2026-58231 is not optional-this-week — three days from patch to exploitation attempts is barely enough time to schedule a maintenance window, let alone complete one. Check Data Hub Adapter logs for unexpected import calls regardless of patch status. If GeoServer sits anywhere in your stack, take it off the public internet until SAP — sorry, until the GeoServer maintainers — ship a fix.
Endpoint watch: A macOS Screen Sharing bug patched last week is already being farmed for Monero
CVE-2026-65400 (CVSS 7.1) is a flaw in screensharingd, the daemon behind macOS’s built-in remote desktop feature, in its implementation of Secure Remote Password authentication. Any Mac with port 5900 reachable from the internet is exploitable pre-authentication, giving an attacker root. The Netherlands’ National Cyber Security Centrum reports observing active abuse in the wild: attackers gaining root and dropping a Monero miner in every confirmed case. Apple shipped fixes last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. BleepingComputer · Security Affairs
A crypto miner is the visible symptom, not the real risk — anyone who got root via this path could have planted something worse and simply chose not to. If you manage any Macs with Screen Sharing enabled, patch now, confirm port 5900 isn’t exposed to the internet, and use VPN or SSH tunneling for remote access going forward instead of leaving the service reachable directly.
Incident watch: RingCentral’s ShinyHunters breach data is live, and 1.6 million accounts just landed in Have I Been Pwned
RingCentral disclosed on July 28 that a “sophisticated social engineering campaign” compromised systems separate from its core platform. The ShinyHunters extortion group claimed the breach and, after RingCentral declined to pay, published the stolen archive. Have I Been Pwned added the data on August 13 after verifying it: 1.6 million unique email addresses along with names, physical addresses, and phone numbers. ShinyHunters claims the full haul is far larger — more than 30 million rows including over a million Social Security numbers, 7.5 million dates of birth, and tens of millions of client notes and medical-order records tied to RingCentral’s healthcare-sector customers. BleepingComputer · SecurityWeek · The Register
Contact details this fresh and this complete are built for vishing, not just phishing — expect callers who already have a name, address, and phone number to sound convincing. If your organization uses RingCentral, check whether your domain shows up in the HIBP dataset and brief your team that a call referencing accurate personal detail isn’t proof the caller is legitimate.
Also noted: Apple’s mercenary-spyware alerts now cover 110 countries
Apple sent a fresh round of Threat Notifications on August 13 to users it believes were individually targeted by mercenary spyware, this time spanning 110 countries — up from the roughly 90-country scope of earlier rounds. The alert now appears directly on the Lock Screen and in Settings, in addition to email and Apple Account notifications, specifically to make a high-risk warning harder to dismiss or miss. Apple has sent these notifications since late 2021; mercenary spyware campaigns are expensive, narrowly targeted, and aimed at a small number of specific individuals rather than the general public. The Hacker News · BleepingComputer
Most organizations will never see one of these alerts fire, but if you have executives, journalists, activists, or anyone handling sensitive negotiations in your user base, make sure they know what a genuine Apple threat notification looks like — on the Lock Screen, not a link in a text message — so a spoofed version doesn’t work as a social-engineering opener.
Final thought
Every item today traces back to the same operational reality: the window between disclosure and exploitation is measured in days, sometimes hours, and attackers are watching patch notes as closely as defenders are. A maximum-severity SAP bug and an unrelated GeoServer zero-day got hit almost simultaneously, a week-old macOS patch didn’t save exposed Macs, and a July breach’s fallout is still landing in inboxes and phone calls in mid-August. If you want tighter visibility into what’s exposed and exploitable in your own environment before it shows up in tomorrow’s digest, see our how-to guides or book a discovery call.