SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

2026-08-16T20:51:37Zd7b72099d50778116a57e3e5792671c36ee2504faef9c8da9985a50f69433c69
CVE-2026-58231CVE-2026-65400APT36CoolClientGeoServerGoogle Sheets C2Mustang PandaPATCHCORDSAP Commerce Cloudactive exploitationcritical vulnerabilitycryptominingdata breachexpired domainskernel rootkitmacOSmalware deliverymercenary spywaretaxpayer datazero-day

What happened

Security Affairs roundup covering active exploitation of critical vulnerabilities, zero-day probing, advanced malware and rootkits, espionage campaigns, data breaches, mercenary spyware, and abuse of expired domains for malware delivery. The most urgent items are SAP Commerce Cloud CVE-2026-58231 exploitation, macOS Screen Sharing CVE-2026-65400 exploitation, and an unpatched GeoServer zero-day potentially enabling SQL injection and remote code execution.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d7b72099d50778116a57e3e5792671c36ee2504faef9c8da9985a50f69433c69
Enrichment time
2026-08-16T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.