// daily digest Β· 2026-08-16
Sunday·16 August 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

6 stories5 sectors5 sourcesAU/NZ watchlist active

Executive Summary

Sunday's digest is led by a maximum-severity SAP Commerce Cloud flaw under active exploitation attempts, international arrests closing a multi-year German banking heist, and a Vietnam-linked criminal enterprise spending ~US$7 million on expired domains to build an illegal streaming, gambling and malware operation. First, CVE-2026-58231 (CVSS 10.0) β€” an unauthenticated arbitrary-code-execution vulnerability in SAP Commerce Cloud that lets an attacker abuse a default authentication client to submit input lacking validation β€” has drawn exploitation attempts in the wild within days of SAP's patch. Vendor analysis from Onapsis and honeypot telemetry from Defused Cyber indicate attempts began as little as three days after the fix shipped; there is no public PoC, and prior SAP flaws (CVE-2025-31324) have been weaponised by China-nexus espionage clusters and cybercrime groups alike. Second, German (BKA) and Brazilian federal police announced multiple arrests this week over a November 2023 hack that drained an estimated €30 million (US$34.7 million) from German online-banking accounts β€” exploiting a payment-provider vulnerability and cloned payment cards, then laundering proceeds through Brazil and four European countries. A Rio de Janeiro city-council candidate was identified as having used illicit funds in his 2024 campaign. Third, DNS intelligence firm Infoblox detailed an operation it calls Sable Squirrel, based in Vietnam, that has spent nearly US$7 million acquiring expired ("dropcatch") domains so their inherited reputation, traffic and backlinks could be repurposed for illegal sports streaming, online gambling promotion and, in parallel, as malware command-and-control for 31,000+ samples including Quasar RAT, AsyncRAT and Remcos RAT.

The SAP Commerce Cloud critical flaw is the clear patching obligation for Australian organisations this weekend. CVE-2026-58231 scores a maximum 10.0 and carries an unauthenticated pre-auth remote-code-execution profile β€” exactly the class of internet-facing vulnerability ACSC's Essential Eight targeting and patch-prominence guidance, and the ASD Information Security Manual, tell local firms to remediate immediately. Its exploitation within days of the patch mirrors this week's dominant patch-to-weaponisation conveyor (the macOS screen-sharing zero-day, SharePoint and Metabase flaws), reinforcing the ACSC's standing advice to treat public Cloud/Commerce deployments as high-priority attack surfaces. The German banking-heist arrests are a regulatory and fraud-analogue for Australian institutions: the attack exploited a payment-provider vulnerability and cloned cards to drain accounts, a TTP overlapping the contactless/NFC payment fraud and APRA CPS 234 safeguarding obligations Australian banks manage. ACSC's homepage continues to lead with AI-agent guidance and CI Fortify OT material rather than new advisories β€” no fresh ACSC publication this cycle. The Sable Squirrel operation explicitly targets users in Australia via a traffic-distribution system redirecting social-media traffic to illicit streaming and gambling brands, and has planted Android apps for its betting brands through compromised Google Play developer accounts β€” a direct consumer-fraud relevance for Australian regulators and platform-enforcement teams.

Two structural threads tighten further this Sunday. The patch-to-exploitation conveyor remains the defining operator risk of the week. CVE-2026-58231's move from fix to attempted exploitation within three days joins this digest's and last week's slate of bugs that travelled from advisory to active targeting almost immediately β€” the macOS screen-sharing zero-day reaching root-and-crypto-miner weaponisation, the SharePoint authentication bypass, Metabase SQLi in CISA's KEV, and the VMware/LibWeb entries. The consistent pattern is attackers sweeping for internet-facing, immediately-reachable, under-patched commerce and remote-access surfaces rather than pursuing novel TTPs, which sharpens the relevance of CISA's KEV and the BOD 26-04 two-week federal patch directive for all Five Eyes defenders. Meanwhile, criminal and state-sponsored supply-chain and infrastructure abuse continues to expand. Sable Squirrel's weaponisation of expired-domain reputation, compromised Google Play accounts and streaming fronts for malware C2, alongside the earlier LiteLLM/Trivy credential supply-chain exposure, shows adversaries commoditising trust signals and trusted distribution channels. The German banking-raid closures β€” securing arrests across Brazil and several European states with asset seizures β€” represent a notable law-enforcement win against a cross-border card-cloning fraud network, and follow the week's broader regulatory momentum (the US private-sector offensive-operations memo, Germany's spy-law overhaul, CISA's Gunra StopRansomware advisory). Expect continued urgency on internet-facing commerce and remote-access patching, sustained infrastructure-abuse campaigns spanning streaming, gambling and malware, and deepening police-led closures against large financial-fraud pipelines in the week ahead.

2
Global (Macro)
1
Defence
1
Government
1
Financial Services
1
Retail & Entertainment & Sport

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
2
Korea
1
China
1
Japan
1
Germany
1

5 countries Β· 6 stories Β· click a country for its stories. Interactive map loads on the hosted site.

🎯 Geo-attribution: 5/6 stories located directly from text (83%). Low-confidence (region-bucket only, check): United States.

🎯 Geo-attribution: 5/6 stories located directly from text (83%). Low-confidence (region-bucket only, check): United States.

Global (Macro) 2 stories

1

Critical SAP Commerce Cloud Vulnerability Targeted in Active Exploitation Attempts Days After Patch

CVE-2026-58231 (CVSS 10.0) allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to SAP Commerce Cloud functions lacking sufficient validation, enabling arbitrary code execution. Vendor analysis from Onapsis and honeypot telemetry from Defused Cyber documented exploitation attempts against the flaw beginning approximately three days after SAP shipped its fix. No public PoC exists, and prior SAP flaws (notably CVE-2025-31324 in NetWeaver) have historically been weaponised by both China-nexus espionage clusters (UNC5221, UNC5174) and cybercrime groups (BianLian, RansomExx). Onapsis urges patching to fixed Commerce Cloud release levels and re-deploying, with IP-Filter restrictions on the vulnerable endpoint as a temporary workaround. **Verification: Reported** (vendor honeypot telemetry and analysis; no government confirmation of victim compromise).

The Hacker News● Tier 2/4 β€” Established cyber journalism2026-08-15
2

New Evooo1Bot Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code

Researchers at FortiGuard Labs detail Evooo1Bot, a previously undocumented Linux-based botnet derived from the Mirai codebase that has been actively exploiting unpatched bugs in internet-facing routers and hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare for at least a month. Beyond Mirai's conventional distributed denial-of-service capability, Evooo1Bot adds encrypted command-and-control communications, a scanner that detects SSH honeypots and skips them, a credential "sniffer" looking for unchanged default logins, and β€” most operationally significant β€” abuse of the SOCKS protocol to turn compromised routers, firewalls and IP cameras into persistent proxies attackers can use to conceal their origin and pivot into internal networks. FortiGuard telemetry shows concentration across North America, South America, Europe, India, China and Japan. **Verification: Verified** (vendor technical analysis with named device targets and capabilities).**

The Record● Tier 2/4 β€” Established cyber journalism2026-08-13
Also notable
  • AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS β€” Jamf Threat Labs details a Rust-based macOS stealer spread via a fake GitHub download page and ClickFix-style Terminal lure that harvests Keychain, browsers, Apple Notes and Telegram, then grants operators live, interactive control of the victim's authenticated browser sessions via the Chrome DevTools Protocol. (The Hacker News, 2026-08-13)
  • Summary: β€” Researchers at FortiGuard Labs detail Evooo1Bot, a previously undocumented Linux-based botnet derived from the Mirai codebase that has been actively exploiting unpatched bugs in internet-facing routers and hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare for at least a month. Beyond Mirai's conventional distributed denial-of-service capability, Evooo1Bot adds encrypted command-and-control communications, a scanner that detects SSH honeypots and skips them, a credential "sniffer" looking for unchanged default logins, and β€” most operationally significant β€” abuse of the SOCKS protocol to turn compromised routers, firewalls and IP cameras into persistent proxies attackers can use to conceal their origin and pivot into internal networks. FortiGuard telemetry shows concentration across North America, South America, Europe, India, China and Japan. Verification: Verified (vendor technical analysis with named device targets and capabilities).**
  • Source: β€” [The Record](https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code)
  • Reliability: β€” Tier 2/4 β€” Established cyber journalism
  • Date: β€” 2026-08-13

Defence 1 story

1

Pentagon Hands Palantir Up to $244M in No-bid Work

The Pentagon has awarded Palantir contracts worth up to US$244 million in no-bid work, reported by Defense One, extending a pattern of sole-source awards to the data-analytics firm for defence-adjacent systems and intelligence workloads. The award deepens the week's broader shift toward private-sector commercial firms taking on state security and offensive-operations roles β€” set against the US memo authorising private-sector offensive hacking operations β€” and raises procurement-oversight and supply-chain-consolidation considerations for Five Eyes partners watching the commercialisation of US defence intel. **Verification: Verified** (contract award reported by established defence outlet).**

Defense One● Tier 2/4 β€” Established cyber journalism2026-08-13

Government 1 story

1

Tech Contractor for Brightly Software Sentenced to 2 Years in Prison for Insider Attack

Cameron Nicholas Curry, a 27-year-old North Carolina data-analyst contractor for Siemens-owned asset-management software firm Brightly Software, was sentenced to two years in prison plus one year of supervised release for an elaborate insider data-theft-and-extortion attack over late 2023 to early 2024. Curry stole corporate data including sensitive employee and compensation information, sent more than 60 threatening emails to staff and executives β€” including a claim the payroll data showed significant pay inequity β€” and attempted to extort Brightly for about US$2.5 million, ultimately receiving US$7,540.92. Authorities identified him quickly after he linked the Coinbase ransom account to his mother's and sister's debit cards; the victim company notified the FBI in December 2023. **Verification: Verified** (court sentencing reported by established outlet with court filings). **Breach: Confirmed breach** (adjudicated insider-theft and extortion; victim disclosed to FBI).**

CyberScoop● Tier 2/4 β€” Established cyber journalism2026-08-13

Financial Services 1 story

1

Investigation of German Banking Hack Leads to Arrests in Germany, Brazil

German (BKA) and Brazilian federal police announced multiple arrests this week linked to a hack that drained an estimated €30 million (US$34.7 million) from German online-banking accounts over four days in November 2023. The attackers exploited a vulnerability in a payment provider and used cloned payment cards, per Brazilian authorities, then moved and laundered funds through networks in Brazil and four European countries. BKA said three suspects were charged in Europe (to be prosecuted in Spain and Bulgaria); Brazil's OperaΓ§Γ£o Klonen arrested four others and executed 21 search-and-seizure warrants, seizing financial assets, vehicles and real estate worth more than US$20 million. Local media report the affected bank was Commerzbank, which did not respond to requests for comment; a person identified in the probe and a 2024 city-council candidate in Rio de Janeiro allegedly used illicit funds in his campaign. **Verification: Verified** (official police announcements).

The Record● Tier 2/4 β€” Established cyber journalism2026-08-15

Retail & Entertainment & Sport 1 story

1

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

DNS intelligence firm Infoblox disclosed an operation it calls Sable Squirrel, based in Vietnam, that has spent nearly US$7 million acquiring expired ("dropcatch") domains to inherit their registration history, backlinks, residual traffic and reputation for criminal purposes. The infrastructure underlies a large Asian sports-piracy network (brands including Xoilac, Cakhia, 90phut, Socolive and MiTom), promotes gambling brands (VSBet, ColaScore, 8xbet), and simultaneously functions as malware command-and-control β€” 31,000+ samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT and njRAT and HiddenTear-signature artifacts have communicated with the infrastructure. A traffic-distribution system redirects users in Vietnam, South Korea, Japan, Taiwan, Singapore and Australia to illicit sites, with Android apps for the betting brands distributed through compromised Google Play developer accounts. The operator hoards more than 10,000 domains, 94% weaponised within two weeks of acquisition. **Verification: Verified** (vendor three-part technical analysis with named infrastructure).

Infoblox● Tier 1/4 β€” Official / first-party (vendor technical analysis)2026-08-14

Analytics

Sector distribution

Global (Macro)
2
Defence
1
Government
1
Financial Services
1
Retail & Entertainment & Sport
1

Source breakdown

The Record
2
The Hacker News
1
Defense One
1
CyberScoop
1
Infoblox
1
6stories
Global (Macro) 2
Defence 1
Government 1
Financial Services 1
Retail & Entertainment & Sport 1

Source Reliability Index

TierLabelDescription
● Tier 1Very HighOfficial / first-party
● Tier 2HighEstablished cyber journalism
● Tier 3ModerateGeneral tech/news media
● Tier 4LowSocial / unverified