Cyber Threat Brief — August 13 2026

⚠️ This report is AI-generated. Always validate findings.

1. VMware vCenter Mass Exploitation — CVE-2026-59310

TL;DR: QUIRSO confirmed active exploitation of the vCenter Syslog directory-traversal RCE (CVSS 9.8) with 361 victim IPs across 47 countries since August 3 — five days after disclosure. Attackers deploy reverse_ssh for persistent backdoor access via cron jobs.

What’s New:

  • QUIRSO published August 12 findings: 343 of 361 victims compromised by August 5, rapid acceleration from August 3 start
  • Top affected countries: Germany, US, Turkey, Iran, France (185 IPs, ~51% of victims)
  • Post-exploitation: malicious cron job deploys reverse_ssh (open-source SSH reverse-shell framework) for connect-back persistence
  • Suspected APT-level actor; outbound SSH tunnels bypass perimeter firewalls
  • Previously covered July 30 as “no ITW exploitation” — now mass-exploited

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
reverse_ssh binary on vCenter applianceToolT1219EDR / file integrityHunt for unauthorized binaries in /usr/bin, /tmp, /var/tmp
Malicious cron job entryPersistenceT1053.003/var/log/cron, auditdReview all crontab entries on vCenter appliances
Outbound SSH to unknown external IPsC2T1572Firewall/NSM (Zeek ssh.log)Alert on vCenter → external SSH connections
Path traversal in Syslog serverInitial AccessT1190vCenter vpxd.log, reverse proxyInspect for ../ sequences in Syslog-related HTTP requests
vCenter versions < 9.1.0.0300 / 9.0.2.0100 / 8.0 U3kVulnAsset inventoryPatch to VMSA-2026-0006.1 fixed versions immediately

Detection

SourceRuleGap
Splunk ESCUNoneNo vCenter Syslog traversal or reverse_ssh detection rule
ElasticNoneNo vCenter-specific exploitation detection
SigmaNoneNeed: unauthorized binary on vCenter appliance, anomalous outbound SSH from vCenter management IP

Sources: QUIRSO GmbH — Active exploitation of CVE-2026-59310 · GBHackers · The Hacker News · Rapid7 ETR


2. ShieldBreak Defender Patch Bypass — CVE-2026-50656

TL;DR: Chaotic Eclipse released ShieldBreak on August 12, a full bypass of the July 2026 RoguePlanet patch (CVE-2026-50656), restoring SYSTEM-level privilege escalation on fully patched Windows 11 25H2 and Server 2025. No patch available.

What’s New:

  • ShieldBreak uses Cloud Filter API (cfapi) user-mode callback hooks during Defender cloud-hydration scans — entirely different technique from original RoguePlanet filesystem race condition
  • 100% success rate on Windows 11 25H2, Canary channel, and Server 2025; Windows 10 vulnerable but PoC not yet adapted
  • Will Dormann (Tharros) confirmed exploit works; requires Defender enabled
  • Kevin Beaumont published KQL detection queries for Defender for Endpoint
  • This is the 9th Defender/Windows zero-day from Nightmare Eclipse since April 2026

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CfCreatePlaceholders / CfConnectSyncRoot API calls from non-OneDrive processesExploitationT1068Sysmon EID 1 (process creation), ETWHunt for Cloud Filter API abuse outside legitimate sync providers
Suspicious MsMpEng.exe child processesPost-exploitT1068Sysmon EID 1Alert on Defender engine spawning cmd/powershell/conhost
Integrity level jump (Medium → System) in MsMpEng contextPrivescT1068Windows Security EID 4688Correlate token elevation events with Defender process tree
PoC repo: git.projectnightcrawler.dev/NightmareEclipse/ShieldBreakIntelBlock/monitor access in proxy logs

Detection

SourceRuleGap
Splunk ESCUAnalytics Story: RoguePlanet (partial — ADS :WDFOO, MsMpEng child proc)Does not detect cfapi callback vector; needs Cloud Filter API abuse rule
ElasticUAC Bypass via Fodhelper (adjacent)No ShieldBreak-specific cfapi detection
Sigmatechnoherder BlueHammer suite (7 rules, partial)Missing: CfCreatePlaceholders from non-sync process, Defender cloud-hydration hook
MDE KQLGossiTheDog ShieldBreak.kqlBest current coverage — deploy immediately

Sources: BleepingComputer · The Hacker News · Arctic Wolf · Security Affairs


Status Updates

  • CVE-2026-20349 (Cisco ASA/FTD VPN DoS): CISA KEV federal deadline TOMORROW August 14. Active exploitation via crafted HTTP to RAVPN causing device reload. August 12 brief.
  • CVE-2026-68820 (Windows AFD.sys / Lazarus): Patched August 11 Patch Tuesday. CISA KEV. Lazarus FudModule v3.1 rootkit deployment ongoing. No new IOCs. August 12 brief.
  • CVE-2026-72898 (Metabase SQLi): CISA KEV added August 11. Framework, n8n, Tally, Kilo Code confirmed breached. Security Arsenal Sigma rules available. August 12 brief.
  • CVE-2026-18577 (N-able N-central): Storm-1175 deploying StormEncryptor ransomware via Take Control pivot. Hotfix 2 (2026.3.1.10) released August 10. Federal deadline passed August 6. August 11 brief.
  • CVE-2026-6875 (Confluence Data Center): Active exploitation entering eighth week. Fortune 500 and critical infrastructure victims. Still not on CISA KEV.