Summary & highlights
SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign. Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish). ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses.
Highlights
- TL-2026-2026 — ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses
- TL-2026-2027 — "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- TL-2026-2028 — Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS
- TL-2026-2029 — AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control
- TL-2026-2030 — AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape, PyPI Supply-Chain Package, and Artifactory Zero-Day Abuse
Theme of the day
Nightmare Eclipse's ShieldBreak zero-day bypasses Defender for SYSTEM access, while Akira exploits Safe Mode to disable EDR and PhaaS platforms scale AiTM MFA-bypass attacks.
- credential-theft
- cybercrime-forum
- data-breach
- dark-web-marketplace
- social-engineering
Threats published
14 threat lines in the 2026-08-16 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables Unauthenticated RCE via PostGISCRITICAL
- CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command ExecutionCRITICAL
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation (update)CRITICAL
- ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and BusinessesHIGH
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and OthersHIGH
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCSHIGH
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote ControlHIGH
- AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape, PyPI Supply-Chain Package, and Artifactory Zero-Day AbuseHIGH
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- Apple Issues Mercenary Spyware Threat Notifications to Users in 110 CountriesHIGH
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud GenerationHIGH
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked) (update)HIGH
- SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing CampaignMEDIUM
- Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish)MEDIUM
Techniques observed
125 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1014
- T1021
- T1021.005
- T1027
- T1027.002
- T1036
- T1036.004
- T1036.005
- T1041
- T1048
- T1053
- T1053.003
- T1055
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1069.003
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1078
- T1078.004
- T1082
- T1087
- T1087.004
- T1090
- T1090.001
- T1098
- T1102.002
- T1105
- T1110
- T1110.003
- T1113
- T1114
- T1119
- T1125
- T1133
- T1136.001
- T1140
- T1185
- T1187
- T1190
- T1195.001
- T1197
- T1199
- T1203
- T1204
- T1204.002
- T1204.004
- T1211
- T1213
- T1219
- T1221
- T1222.002
- T1417
- T1429
- T1430
- T1485
- T1496
- T1505.003
- T1512
- T1539
- T1543.004
- T1547
- T1547.001
- T1547.009
- T1548.003
- T1548.004
- T1548.006
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.007
- T1553.001
- T1555
- T1555.001
- T1555.003
- T1556.006
- T1560
- T1562.001
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1573
- T1583.001
- T1583.006
- T1583.008
- T1584.005
- T1585.001
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.001
- T1592.002
- T1593
- T1595
- T1595.002
- T1602.002
- T1608.001
- T1611
- T1614
- T1620
- T1621
- T1622
- T1650
- T1657
- T1665
- T1684.001
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- Russia
- Pakistan
Threat categories
- DATA_BREACH
- MALWARE
- THREAT_INTEL
- SUPPLY_CHAIN
- VULNERABILITY
Severity breakdown
- critical3
- high9
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- entity 73
- network 46
- infrastructure 35
- file 30
- tool 27
- malware 23
- behavioral 5
- package 3