Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

2026-08-16T02:51:37Zdd997a9e4ede0266da5d335dc85979b48f5a9f45230d395bb04f2fc04eee8882
CVE-2026-20349CVE-2026-58231CVE-2026-65400CVE-2026-71362Adobe CommerceAmnesiaStealerCisco Secure FirewallGeoServerMetabaseSAP Commerce CloudWindowsaccount-hijackingactive-exploitationcommand-and-controlcryptominingdata-scrapingexpired-domain-abuseinfostealerknown-exploited-vulnerabilitiesmacOSmalware-deliverymercenary-spywarezero-day

What happened

Security Affairs RSS coverage from August 13–15, 2026 reports active exploitation of critical SAP Commerce Cloud, macOS Screen Sharing, and Adobe Commerce vulnerabilities; probing of an unpatched GeoServer zero-day; macOS infostealer activity; expired-domain abuse for malware and command-and-control; mercenary spyware targeting; and data exposure through scraping. CISA also added Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
dd997a9e4ede0266da5d335dc85979b48f5a9f45230d395bb04f2fc04eee8882
Enrichment time
2026-08-16T02:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.