Loki Intelligence — Security Briefs · Published

Daily Security Brief: Active Exploitation Hits SharePoint, vCenter, Commerce

Multiple enterprise platforms are facing active or likely exploitation shortly after disclosure, with collaboration, commerce, virtualization, and firewall systems all in scope. Teams should prioritize emergency patching, exposure review, identity monitoring, and validation of compensating controls.

Signal 01 · The Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News reports that attackers are exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass, after public proof-of-concept details became available.

Why it matters: Internet-facing SharePoint servers should be treated as high priority for patching, access review, log inspection, and monitoring for suspicious authentication activity.

Source: The Hacker News

Signal 02 · BleepingComputer

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

BleepingComputer says exploitation attempts are targeting CVE-2026-71362 in Adobe Commerce and Magento, with potential impact to customer account integrity.

Why it matters: E-commerce teams should apply vendor fixes quickly, review account takeover signals, strengthen customer session protections, and watch for abnormal checkout or profile changes.

Source: BleepingComputer

Signal 03 · The Hacker News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker News cites findings that CVE-2026-59310 in VMware vCenter is being used to obtain persistent remote access on vulnerable systems.

Why it matters: vCenter is a control plane for critical infrastructure, so teams should patch immediately, restrict management access, and investigate for unauthorized persistence or configuration changes.

Source: The Hacker News

Signal 04 · The Hacker News

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP patched CVE-2026-58231, a maximum-severity SAP Commerce Cloud Data Hub Adapter issue that could allow unauthenticated arbitrary code execution.

Why it matters: Organizations using SAP Commerce should confirm patch status, reduce public exposure, and review application and integration logs for unexpected execution or data access patterns.

Source: The Hacker News

Signal 05 · BleepingComputer

Lazarus hackers exploited Windows zero-day to target defense firms

BleepingComputer reports that Lazarus actors exploited CVE-2026-68820, a Windows zero-day, in attacks aimed at defense-sector organizations under the Operation Dream Job theme.

Why it matters: Defense and adjacent suppliers should prioritize Windows updates, harden endpoint detection, and increase scrutiny of recruiting-themed lures and unusual process activity.

Source: BleepingComputer

Signal 06 · BleepingComputer

Hackers leverage new Microsoft SharePoint exploit in attacks

BleepingComputer separately notes that attackers moved quickly to use a newly published SharePoint exploit associated with the same critical vulnerability class.

Why it matters: The short window between disclosure and attacks means SharePoint owners need rapid asset discovery, patch verification, and post-patch compromise assessment.

Source: BleepingComputer

Signal 07 · The Hacker News

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

The Hacker News reports Cisco has warned that CVE-2026-20349 in ASA and FTD firewall software has been exploited and can cause remote denial of service.

Why it matters: Firewall outages can disrupt remote access and perimeter enforcement, so network teams should patch, validate HA failover readiness, and monitor device stability and crash events.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.