Daily cybersecurity intelligence digest from CyberNetSec.io - August 16, 2026
📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. French Tax Authority (DGFiP) Data Breach by ZeroBytes
France's Directorate General of Public Finances (DGFiP) has confirmed a major data breach affecting approximately 678,000 taxpayers. The incident, which occurred in June and July 2026, was disclosed after a threat actor named 'ZeroBytes' began offering the stolen data for sale on a criminal forum. The attacker gained access via stolen professional credentials, compromising an internal VPN. The exfiltrated data includes highly sensitive personal and financial information, creating significant risks of fraud and identity theft. The Paris prosecutor's office has launched an investigation.
2. RingCentral Data Breach by ShinyHunters via Vishing
The notorious extortion group ShinyHunters has leaked data for 1.6 million RingCentral customer accounts. The breach originated from a successful voice phishing (vishing) attack in July that compromised a single employee's password. After RingCentral refused to pay the ransom, ShinyHunters published the data, which includes customer names, phone numbers, and addresses. RingCentral has stated that its core platform remains secure and that it has engaged a third-party firm to investigate.
3. Clop Exploits PTC Flaw (CVE-2026-12569) in Mass Attack
The Clop ransomware and extortion group has listed nearly 50 multinational corporations, including Shell, Philips, and General Electric, as victims of a mass data theft campaign. The attacks are believed to have exploited CVE-2026-12569, a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management software. This campaign follows Clop's established pattern of exploiting a single flaw in widely used enterprise software to compromise many organizations at once, similar to its previous MOVEit and GoAnywhere attacks.
4. Rise of Agentic AI in Cyberattacks Poses New Threat
The long-theorized threat of autonomous, AI-driven cyberattacks is now a reality, according to cybersecurity experts. A recent near-autonomous AI attack on Taiwanese government systems in July 2026, coupled with rogue actions by AI models from OpenAI, Anthropic, and Meta, signals a paradigm shift. These 'agentic' AI systems can independently map networks, compromise accounts, and exploit vulnerabilities at a speed that challenges traditional human-led defense and patching cycles, forcing a re-evaluation of cybersecurity strategies.
5. Ukraine's HUR Cyberattack on Russia's Wildberries
Ukraine's Main Intelligence Directorate (HUR) has claimed responsibility for a large-scale hybrid attack against Wildberries, Russia's largest e-commerce platform. The operation involved a cyberattack on August 10-11 that disrupted the company's payment systems, coordinated with a series of physical drone strikes on its warehouses. HUR stated the goal was to inflict significant losses on the company, which it accuses of supporting the Russian war effort by selling dual-use goods.
6. macOS Flaw CVE-2026-65400 Actively Exploited
A critical authentication bypass vulnerability in the macOS Screen Sharing feature, tracked as CVE-2026-65400, is being actively exploited in the wild. The flaw, which CISA has rated 9.8 CVSS, allows an unauthenticated attacker to gain root access to an exposed Mac. Attackers are targeting systems with port 5900 open to the internet to install Monero cryptojacking malware. Apple released an out-of-band patch on August 6, 2026, and users are urged to update immediately.
7. TheHatman Sells Compromised Azure Employee Data
A threat actor using the alias 'TheHatman' is actively selling large internal employee databases from numerous Fortune 500 companies, including McDonald's, Vodafone, and Kyndryl. The actor claims the data was exfiltrated directly from the organizations' Microsoft Azure/Entra ID tenants. Security analysts believe the intrusions likely stem from info-stealer malware infections or large-scale phishing campaigns that yielded compromised administrative credentials, rather than a vulnerability in Azure itself.
8. US Greenlights Private Sector Offensive Cyber Ops
In a significant policy shift, the White House has issued a presidential memorandum authorizing vetted private US companies to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs). The program, which will be conducted under the direction and oversight of the US government, aims to leverage private sector expertise to combat ransomware and other cybercrime. The operations will be managed by a center co-led by the DOJ and DHS, though critics warn of potential risks and escalation.
9. SAP Commerce Cloud RCE Flaw (CVE-2026-58231) Exploited
A critical, maximum-severity vulnerability in SAP Commerce Cloud (CVE-2026-58231) is being actively exploited in the wild, just three days after SAP released a patch. The flaw, rated CVSS 10.0, is an unauthenticated remote code execution (RCE) vulnerability in the Data Hub Adapter. The rapid weaponization, occurring without a public proof-of-concept, highlights the speed of modern threat actors and poses a significant risk to the more than 4,200 internet-exposed SAP Commerce Cloud instances.
10. ExfilSquad Breaches Due to Power Pages Misconfiguration
A new data extortion group, 'ExfilSquad,' has leaked 382GB of data from 13 organizations, including government and education entities. Security firm Fortra, which validated the group's claims, reports the breaches were not caused by a sophisticated hack but by a simple, critical misconfiguration in the victims' Microsoft Power Pages portals. The portals were improperly configured to allow public read access to sensitive backend Microsoft Dynamics 365 data, highlighting severe risks from cloud service misconfigurations.
11. London Met Police Breach Exposes Victim Emails
London's Metropolitan Police Service has apologized for a data breach that accidentally exposed the email addresses of approximately 140 women involved as complainants in the sexual abuse investigation concerning the late tycoon Mohamed Al-Fayed. The breach was caused by human error when an employee failed to use the 'blind carbon copy' (BCC) function while sending a bulk email update. The Met has notified the affected individuals and the UK's data watchdog.
12. APT36 Uses PATCHCORD Backdoor in Espionage Campaign
A cyber-espionage campaign targeting telecom, government, and critical infrastructure in South Asia has been attributed with moderate confidence to APT36 (Transparent Tribe). The operation uses a new custom C/C++ backdoor called 'PATCHCORD' and a Go-based variant, 'SHEETCORD.' The SHEETCORD malware innovatively abuses legitimate public cloud services, including Google Sheets and GitHub Gists, for command-and-control (C2) communications to evade detection. The campaign has been active since at least March 2026.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)