THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
GitHub expands Dependabot malware alerts to eight additional package ecosystems

GitHub says it is widening its Dependabot malware alert coverage beyond npm to include PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer packages. The update closes a visibility gap where teams could pull tainted dependencies from ecosystems that weren’t previously monitored by the same malware detection. For security teams, this is a strong reminder to pair dependency alerts with SBOMs, allowlisting, and CI/CD gating for all language stacks—not just Node.js.

Source: Help Net Security


macOS Screen Sharing (CVE-2026-65400) actively exploited to drop Monero miners

The Dutch National Cyber Security Centre confirmed ongoing exploitation of a critical macOS authentication flaw tracked as CVE-2026-65400 (CVSS 9.8). Attackers are reportedly using exposed Screen Sharing on port 5900 to gain root access and deploy Monero mining malware. Organizations should verify whether the fix has been applied, restrict or disable Screen Sharing where possible, and review for persistence and miner-related process/activity.

Source: Security Affairs


GeoServer zero-day already being probed—no patch available yet

A newly disclosed GeoServer zero-day is reportedly drawing active reconnaissance and exploitation attempts, with researchers warning it can enable SQL injection and potentially RCE. Because no patch is available at the time of reporting, the immediate risk-reduction playbook becomes exposure management: audit internet-facing GeoServer instances, restrict access by IP/VPN, and consider temporary compensating controls. This is another example of “discover-to-exploit” timelines compressing for widely deployed software.

Source: Security Affairs


SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) exploited in the wild

Attackers are actively exploiting CVE-2026-58231, a maximum-severity SAP Commerce Cloud vulnerability, just days after SAP released a patch. The issue involves insufficient authorization checks and input validation, creating a direct path for abuse. Teams using SAP Commerce Cloud should prioritize patching, verify that compensating controls are in place for any remaining unpatched environments, and monitor for web-layer exploitation patterns.

Source: Security Affairs


PATCHCORD: APT36 suspected backdoor using fake VPN tooling and Google Sheets C2

Acronis researchers documented PATCHCORD, a stealthy backdoor attributed to suspected APT36 activity targeting Afghan telecom and South Asian infrastructure. The campaign reportedly uses social engineering and “fake VPN tools,” while command-and-control is carried out through Google Sheets—an unusual but effective disguise that can blend into normal web traffic. Defenders should strengthen controls around user-downloaded tooling and monitor for outbound connections and suspicious access patterns to cloud document services.

Source: Security Affairs


Dropcatch/expired domains used for malware delivery and C2 infrastructure

Threat intelligence reports highlight a growing abuse pattern: attackers re-register expired domains to leverage residual reputation, historical DNS behavior, and trust signals. These “dropcatch domains” are then used for malware delivery, scams, and command-and-control infrastructure. Security teams should review domain monitoring coverage, tighten DNS and email controls, and prioritize detections for newly registered domains that suddenly begin delivering payloads or spoofing high-value brands.

Source: Security Affairs


ChainDrop worm variant enters npm supply chain and evades standard defenses

A reported ChainDrop “Shai-Hulud” variant poisons 444 npm packages by abusing tarball workflows and developer tool hooks, enabling spread through dependency updates. The key warning is that attackers are adapting to common supply-chain protections and trying to slip past “standard defenses.” Maintain strict dependency update controls, watch for suspicious post-install behaviors, and ensure your CI/CD environment validates both package metadata and execution outcomes.

Source: The Register


You May Also Be Interested In...
How to tell if your AI platforms’ accounts have been hacked
So much solar: Digging into the list of every US power plant that went online this year
Ukraine strikes major Russian rocket factory with cruise missiles
Cybersecurity — August 16, 2026 | Briefing24