Loki Intelligence — Security Briefs · Published
Daily Security Brief: Active Exploitation Hits SharePoint, vCenter, Commerce
Multiple enterprise platforms are facing active or likely exploitation shortly after disclosure, with collaboration, commerce, virtualization, and firewall systems all in scope. Teams should prioritize emergency patching, exposure review, identity monitoring, and validation of compensating controls.
Signal 01 · The Hacker News
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The Hacker News reports that attackers are exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass, after public proof-of-concept details became available.
Why it matters: Internet-facing SharePoint servers should be treated as high priority for patching, access review, log inspection, and monitoring for suspicious authentication activity.
Source: The Hacker News
Signal 02 · BleepingComputer
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
BleepingComputer says exploitation attempts are targeting CVE-2026-71362 in Adobe Commerce and Magento, with potential impact to customer account integrity.
Why it matters: E-commerce teams should apply vendor fixes quickly, review account takeover signals, strengthen customer session protections, and watch for abnormal checkout or profile changes.
Source: BleepingComputer
Signal 03 · The Hacker News
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
The Hacker News cites findings that CVE-2026-59310 in VMware vCenter is being used to obtain persistent remote access on vulnerable systems.
Why it matters: vCenter is a control plane for critical infrastructure, so teams should patch immediately, restrict management access, and investigate for unauthorized persistence or configuration changes.
Source: The Hacker News
Signal 04 · The Hacker News
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP patched CVE-2026-58231, a maximum-severity SAP Commerce Cloud Data Hub Adapter issue that could allow unauthenticated arbitrary code execution.
Why it matters: Organizations using SAP Commerce should confirm patch status, reduce public exposure, and review application and integration logs for unexpected execution or data access patterns.
Source: The Hacker News
Signal 05 · BleepingComputer
Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer reports that Lazarus actors exploited CVE-2026-68820, a Windows zero-day, in attacks aimed at defense-sector organizations under the Operation Dream Job theme.
Why it matters: Defense and adjacent suppliers should prioritize Windows updates, harden endpoint detection, and increase scrutiny of recruiting-themed lures and unusual process activity.
Source: BleepingComputer
Signal 06 · BleepingComputer
Hackers leverage new Microsoft SharePoint exploit in attacks
BleepingComputer separately notes that attackers moved quickly to use a newly published SharePoint exploit associated with the same critical vulnerability class.
Why it matters: The short window between disclosure and attacks means SharePoint owners need rapid asset discovery, patch verification, and post-patch compromise assessment.
Source: BleepingComputer
Signal 07 · The Hacker News
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
The Hacker News reports Cisco has warned that CVE-2026-20349 in ASA and FTD firewall software has been exploited and can cause remote denial of service.
Why it matters: Firewall outages can disrupt remote access and perimeter enforcement, so network teams should patch, validate HA failover readiness, and monitor device stability and crash events.
Source: The Hacker News
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.