Home  /  Episodes  /  Aug 17, 2026

Episode show notes

Aug 17's Top Cyber News NOW! - Ep 1196

Aired Aug 17, 2026 Daily Cyber Threat Brief Hosted by Dr. Gerald Auger

At a glance

SAP Commerce Cloud faces active exploitation of a critical RCE flaw patched only days ago. Shell confirmed a data breach affecting 670,000+ individuals after a sophisticated attack. Threat actors continue evolving tactics—from Linux botnets to AI-powered social engineering—forcing practitioners to compress patch windows and rethink defense strategies.

Stories covered

Is SAP Commerce Cloud's maximum-severity RCE being weaponized in the wild?

What happened: A critical remote code execution vulnerability in SAP Commerce Cloud's core data hub adapter extension is now under active attack, just three days after patching. The flaw allows unauthenticated, low-complexity exploitation leading to arbitrary code execution.

Why it matters: This represents the collapsing window between patch release and weaponized exploitation. Vulnerability management teams face testing and validation delays while threat actors deploy working exploits at scale. Delay equals exposure.

What to do: If running SAP Commerce Cloud, prioritize this patch immediately despite testing overhead. For all practitioners: treat max-severity unauthenticated RCE as a stop-the-line incident. Establish expedited patch testing protocols for critical infrastructure.

---

How is a new Mirai variant improving its botnet stealth and persistence?

What happened: EVU onebot, a Linux malware variant based on Mirai code, adds encryption, honeypot detection, and credential harvesting to the established botnet framework. It targets internet-exposed routers and IoT devices from Alcatel, D-Link, Netgear, Tenda, and others via known unpatched vulnerabilities.

Why it matters: Mirai remains a persistent threat despite its 2016 origin. Successive variants show threat actors continuously improving operational security—encrypted C2, detection evasion—making botnet command infrastructure harder to disrupt. Scale matters: hundreds of thousands of bots report to centralized C2.

What to do: Audit internet-facing IoT and networking devices; change default credentials immediately. Implement network segmentation and VLANs for choke-point monitoring. Review Mirai source code and historical campaigns to understand worm propagation mechanics relevant to your infrastructure.

---

Why did Shell's critical data exposure follow a predictable vulnerability-to-exploitation timeline?

What happened: Klopp ransomware gang claimed theft of 89GB from Shell, including engineering drawings, facility photos, and project plans. Shell is one of 43 listed victims. The attack exploited a CVE in PTC Windchill and Flex PLM instances; patch released June 17, CISA warned of active exploitation June 26, and Klopp weaponized it within weeks.

Why it matters: Klopp's modus operandi—find vulnerability, exploit at scale, exfiltrate data—demonstrates the ransomware-as-data-theft business model. Unlike encryption-based ransomware, Klopp steals and publishes; victims must decide whether to negotiate. The nine-day vulnerability-to-active-exploitation window is now the norm.

What to do: Establish zero-slack patch cadence for internet-exposed assets. Subscribe to CISA alerts and threat intel feeds to catch active exploitation signals. Implement metrics around time-to-patch for critical vulnerabilities. Assume your organization is in a foot race with threat actors who have accelerated tools.

---

What makes France's tax authority breach a template for social engineering at scale?

What happened: France's Tax Administration Office confirmed a breach affecting 670,000+ individuals and businesses. Attackers stole personal data including names, addresses, income figures, and family circumstances—but not passwords or account credentials—via what officials called an unusually sophisticated attack.

Why it matters: Stolen metadata, not access credentials, powers high-ROI social engineering. Threat actors can sort exfiltrated databases by income and target high-value individuals with personalized phishing tied to real life events. This data feeds identity theft, credit fraud, and convincing pretexting campaigns.

What to do: Educate end users that any unexpected contact claiming account fraud or unusual activity is suspect, regardless of personalization. Verify through official channels using known numbers, not provided callbacks. Assume your organization's data is already in criminal databases; treat all unsolicited contact with skepticism.

---

How are Pakistani threat actors using Google Sheets for command-and-control infrastructure?

What happened: APT36 (Transparent Tribe) delivered compiled C/C++ backdoors and a Go-based implant called "sheet cord" via fake VPN installers impersonating Afghan telecom and Indian infrastructure entities. The sheet cord implant uses Google Sheets as a C2 channel, receiving commands from infrastructure linked to Pakistan-aligned actors.

Why it matters: Using legitimate third-party services (Google Sheets) for C2 evades traditional network detection and complicates attribution. Any internet-accessible service can become C2. The campaign demonstrates targeting of critical infrastructure in specific geographies—a precursor to potential broader campaigns.

What to do: Monitor ISACs (Information Sharing and Analysis Centers) for early threat warnings specific to your sector and geography before public disclosure. Educate users against installing unexpected VPN or management tools; enforce application whitelisting via zero-trust controls. Alert on anomalous Google Sheets API usage tied to non-business accounts.

---

What does the $30M bank heist arrest wave reveal about ransomware's ROI decline?

What happened: German and Brazilian authorities arrested seven suspects connected to a November 2023 attack that drained €30M from German bank accounts via cloned payment cards and exploitation of a payment provider vulnerability. Authorities seized €20M in assets, vehicles, and property. One suspect was running for elected office using stolen funds.

Why it matters: Threat actors are reverting to financial crime (card cloning, account takeover) as ransomware defense improves (immutable backups, incident response, cyber insurance). The shift signals that encryptive ransomware ROI has collapsed; criminals are chasing older playbooks for better yields.

What to do: Monitor for legacy financial crime TTPs even as ransomware remains a threat. Implement controls on unauthorized fund transfers, anomalous payment processor activity, and cross-border wire patterns. Assume your organization may face dual threats—ransomware and financial fraud—simultaneously.

---

Can AI identify photo locations accurately enough to personalize phishing at scale?

What happened: Researchers at McAfee Labs warn that AI can identify locations in photos with up to 90% accuracy using background architecture, signage, shadows, and environmental cues—without metadata. Threat actors can correlate social media photos with spoofed bank alerts to create highly targeted phishing tied to when and where victims traveled.

Why it matters: Personalization anchors phishing campaigns in verifiable reality. A fraudulent alert claiming "unusual activity at Slice of Heaven pizza in Vegas last week" is far more credible to a victim who posted a photo there. OSINT-powered social engineering combines public digital footprints with AI geolocation.

What to do: Advise users to avoid posting location-specific photos with architectural landmarks, signage, or unique identifiers. Teach end users that even generic-seeming alerts claiming activity at places they visited recently should be verified through official channels. Treat any alert tied to real-world events as a red flag pending independent verification.

---

Is China spying through space infrastructure in New Zealand?

What happened: New Zealand's Security Intelligence Service accused Chinese entities—specifically the Purple Mountain Observatory—of building space-based facilities in New Zealand to collect military intelligence. The country hosts space infrastructure due to its geographic advantage for satellite tracking.

Why it matters: Nation-state espionage through civilian infrastructure is a geopolitical fact, not novel cyber threat. This is strategic positioning rather than cyber-specific attack, but signals broader intelligence competition for space domain awareness.

What to do: Monitor for now. This story is primarily geopolitical signaling, not a cyber threat vector for most practitioners. Relevance increases only if you work in space, defense, or critical infrastructure sectors in Five Eyes nations.

---

Key takeaways

  • Patch windows are compressing: nine days from disclosure to active weaponization is now routine. Treat critical unauthenticated RCE as stop-the-line priority.
  • Threat actors are reverting to financial crime and data exfiltration as ransomware defense improves. Expect dual-threat operations targeting both data and funds.
  • AI geolocation from social media photos enables hyper-personalized phishing. Attackers pair stolen metadata with publicly observable travel patterns to anchor social engineering in verifiable reality.
  • Command-and-control infrastructure now uses legitimate third-party services (Google Sheets, Telegram). Traditional network detection fails; monitor for anomalous API usage and unusual service integrations.
  • ISACs provide early warning before public disclosure. Subscribe to sector-specific threat sharing to compress your response window relative to attackers.

Topics covered

ransomware, SAP Commerce Cloud, CVE, critical infrastructure, Mirai botnet, IoT devices, PTC Windchill, Klopp ransomware, patch management, vulnerability management, France tax breach, social engineering, phishing, APT36, Google Sheets C2, Pakistan threat actors, financial crime, card cloning, geolocation AI, OSINT, photo forensics

Show notes generated from the live transcript using AI on Mon, 17 Aug 2026 17:50:54 GMT. Errors? Open the YouTube replay for the source of truth.

Want the live experience? The Daily Cyber Threat Brief airs live every weekday at 5am PT / 8am ET on YouTube. 400+ practitioners join the chat in real time.