RingCentral Dump, a SAP 10.0 and a macOS Root Flaw (08/14/2026)
- › ShinyHunters dumped data on 1.6 million RingCentral accounts, and Have I Been Pwned confirmed the set today.
- › SAP Commerce Cloud flaw CVE-2026-58231 scores a maximum 10.0 and came under attack three days after the patch, before any public proof of concept existed.
- › macOS Screen Sharing flaw CVE-2026-65400 gives a network attacker root with no credentials, and it is being used to plant a Monero miner.
- › A SharePoint authentication bypass patched in July is now being exploited, with most observed attempts landing in the two days after a public proof of concept.
- › France's tax authority confirmed a breach after an actor claimed data on more than 600,000 people.
Three of today’s five stories are the same story told in different products: something was reachable from the internet that did not need to be. SAP Commerce Cloud went from patch to attack in three days with no public exploit code to copy, macOS Screen Sharing is handing out root to anyone who can reach port 5900, and the RingCentral set that ShinyHunters dumped this morning is 1.6 million records nobody at the company has yet explained the path into.
Top 5 Critical Security Alerts
1. ShinyHunters Dumps 1.6 Million RingCentral Accounts
ShinyHunters published data covering 1.6 million RingCentral accounts, including names, email addresses, phone numbers, and physical addresses. Have I Been Pwned confirmed the set today. RingCentral disclosed the incident on July 28, described it as a sophisticated social engineering campaign, and has still not said how the attackers got in. BleepingComputer
Operator Note: Names paired with phone numbers and street addresses make a working voice phishing kit. Your finance team is about to get calls from people who can recite their own office address back to them, so tell them now rather than after the first wire.
2. A Maximum Severity SAP Flaw Was Attacked in Three Days
CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter scores a 10.0 on the Common Vulnerability Scoring System (CVSS), the top of the scale. An unauthenticated attacker abuses a default authentication client to reach functions that never validated their input, and gets arbitrary code execution. SAP patched it on August 11. Defused caught exploitation in honeypots on August 14, before any public proof of concept existed, with more than 4,200 SAP Commerce Cloud instances exposed to the internet. BleepingComputer
Operator Note: Three days with no public exploit means somebody built their own from the patch diff. If your patch window for a 10.0 on an internet-facing commerce platform is measured in weeks, the window is the vulnerability.
3. macOS Screen Sharing Hands Over Root With No Credentials
CVE-2026-65400 lets a network attacker take full control of a Mac through the Screen Sharing service on TCP port 5900, without valid credentials. The Dutch National Cyber Security Centre reports active abuse on multiple systems with that port exposed, dropping a Monero miner. Apple fixed it on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. BleepingComputer
Operator Note: A miner shows up first because it pays the day it lands. The same access gives root, so work any hit as a full compromise. Go find the Macs in your estate with 5900 answering from outside, starting with the ones somebody enabled for remote support and never turned off.
4. SharePoint Bypass Goes From Proof of Concept to Attack
CVE-2026-55040 is a 9.1 authentication bypass in SharePoint. It chains four weaknesses in JSON Web Token (JWT) validation so an attacker can forge a token and impersonate users or administrators, then read files and modify data. Microsoft patched it in July. Rapid7 published a proof of concept in early August, and of 12 exploitation attempts tracked since July 19, eight landed on August 12 and 13 from eight IP addresses across five countries. The Hacker News
Operator Note: Two thirds of the attack volume arrived inside 48 hours of the exploit going public. That is the shape of the curve now, and it is the argument for patching on Microsoft’s schedule rather than on the researcher’s.
5. France’s Tax Authority Confirms a Breach
The Direction Generale des Finances Publiques confirmed that attackers reached systems holding data on individuals and businesses, and that it cut the access in late June. An actor using the alias ZeroBytes claims more than 600,000 victims, with names, tax identification numbers, email addresses, family circumstances, and tax status. The agency has not verified that count. The Record
Operator Note: Read the described path twice. Identity misuse for the foothold, internal servers to reach the Virtual Private Network (VPN), then an internal search tool to do the collection. No exploit anywhere in that chain. Every step used tooling the agency built and sanctioned, operated by someone who should not have had it.
Additional Security Alerts
Threat Intelligence
- HoneyMyte adds a kernel rootkit: The Advanced Persistent Threat (APT) group upgraded its CoolClient backdoor with a kernel-mode rootkit driver that hides processes, files, and network connections from security tooling. Securelist
- Jewelbug runs espionage and crypto theft from the same panel: Broadcom researchers found the Chinese group doing state collection and financially motivated crypto heists through one web panel, so attribution by motive no longer sorts cleanly. Infosecurity Magazine
- A new Mirai variant turns edge devices into proxies: Evooo1Bot builds on the Mirai framework and converts compromised edge devices into persistent relay infrastructure. The Record
- Autonomous AI attacks called a clear and present danger to critical infrastructure: The framing follows the near autonomous agents that hit Taiwan’s nuclear safety agency this week. The Register
- What is known about the Iranian water utility intrusions: A consolidated account of the attacks across at least seven states, with Forescout counting more than 2,800 controllers in US water systems exposed online. TechCrunch
Security Breaches & Incidents
- Scotland’s prosecution service is examining a supplier: An unnamed third party spotted suspicious activity, with staff names, roles, and email addresses potentially exposed, and the third party may have serviced other agencies too. Dark Reading
- Shell is investigating Clop’s claim of 89GB: The company confirmed it is looking into a potential incident after the group claimed it stole 89GB of data. BleepingComputer
- ExfilSquad’s access confirmed across 13 organizations: Researchers verified the extortion group holds sensitive data from at least 13 victims after it published the datasets over torrents. Infosecurity Magazine
- A data analyst got two years for extorting his employer: A former contractor at Brightly Software stole company data and ran a $2.5 million extortion scheme, which is the insider case that starts with legitimate access. BleepingComputer
Security Tools & Best Practices
- Akira disabled endpoint detection and response through Safe Mode and then failed to encrypt: Huntress documented an affiliate rebooting into Safe Mode with Networking to kill the Endpoint Detection and Response (EDR) agent, stealing the data, and botching the payload. Theft is the reliable half of the business. BleepingComputer
- Passwords in a public Google Doc turned up in search results: A developer spotted a hostname and a credential string surfacing in search autocomplete. The Register
Emerging Security Technologies
- NIST turns to AI to keep up with AI-generated bug volume: The agency is looking at machine assistance for a backlog that human triage is not clearing. Dark Reading
- Google Cloud sets 2027 for its first major post-quantum milestone: The target covers store-now-decrypt-later exposure, with wider migration goals running through 2028. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.