The Lyceum: Cyber Intelligence Daily — Aug 13, 2026
Photo: lyceumnews.com
Thursday, August 13, 2026
The Big Picture
The freshest attacks share one uncomfortable theme: attackers are not inventing new trust relationships so much as borrowing the ones organizations already created. SharePoint identity tokens, Magento customer sessions, public Salesforce portals, and “privacy” extensions all became ways to enter through doors users and administrators had been taught to trust.
What Just Dropped
- CVE-2026-20349 — Cisco Secure Firewall ASA and Secure Firewall Threat Defense: patched and actively exploited; no NVD score yet. A crafted request can force affected firewalls to reload, temporarily interrupting VPN and firewall operations; CISA’s federal remediation deadline remains active through August 14.
- CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock: patched and actively exploited; no NVD score yet. An attacker with an existing foothold can escalate to SYSTEM privileges, as observed in the Lazarus Group’s defense-sector campaign.
- CVE-2026-72898 — Metabase: patched and actively exploited; no NVD score yet. The SQL-injection flaw can give an unauthenticated attacker access to connected databases and stored credentials; CISA’s federal deadline remains active through August 14.
Today's Stories
SharePoint’s Authentication Bypass Has Made the Jump From PoC to Attacks
Rapid7 published technical analysis and proof-of-concept code for CVE-2026-55040, a Microsoft SharePoint vulnerability that allows an unauthenticated attacker to forge JSON Web Tokens—the signed credentials SharePoint uses to establish identity. Reporting published August 12 says attackers began using the technique shortly after the code appeared, with eight of 12 recorded attempts occurring across August 12 and 13. [DEVELOPING]
That changes the problem from “patch a serious bug” to “assume exposed authentication boundaries are being tested.” A successful attacker can impersonate SharePoint users, including administrators, without stealing their passwords first.
Organizations that move quickly can close the direct path and examine pre-patch activity for forged-token use. Failure looks like a patched server with an already-established intruder behind it; the signal will be downstream reports of data theft, persistence, or administrator activity that cannot be tied to a legitimate login.
Adobe Commerce Stores Are Already Seeing Account-Hijacking Attempts
Adobe’s August 11 bulletin fixed CVE-2026-71362, an authorization flaw affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe said it knew of no exploitation when the bulletin was published, but BleepingComputer subsequently reported that Sansec had observed exploitation attempts against customers. [DEVELOPING] (Adobe Commerce Stores Are Already Seeing Account-Hijacking Attempts)
The flaw can let an unauthenticated attacker interfere with customer identity inside a session, potentially exposing account information or enabling fraudulent changes and orders. For merchants, the winning move is not merely installing Adobe’s update; it is pairing the patch with a review of address changes, unfamiliar sessions, account edits, and suspicious purchases.
If attempted exploitation becomes confirmed account compromise, patch-only closure will have failed. The observable signal will be Adobe or affected merchants reporting hijacked accounts created before the update was installed. (Adobe Commerce Stores Are Already Seeing Account-Hijacking Attempts)
The City-Forum Campaign Found the Data Organizations Accidentally Made Public
US-based SaaS security company Reco disclosed an ongoing campaign it calls City-Forum, which automates data collection from Salesforce Experience Cloud and ServiceNow portals configured to reveal records to anonymous visitors. Reco says this is not a vulnerability in Salesforce or ServiceNow: customer-controlled guest permissions created the opening.
Reco associated activity against telecommunications companies, banks, software vendors, security companies, and public-sector portals with a shared network fingerprint. One Salesforce target recorded more than 560,000 requests connected to guest-user enumeration—the systematic discovery of records available without logging in.
Organizations that audit guest sharing rules, file access, search interfaces, and public APIs can shut the filing cabinet before someone finishes emptying it. Non-adoption will look like victim disclosures and regulatory notices; that would turn a configuration problem into a recognizable class of SaaS breach.
Chrome’s Fake VPN Problem Was Really a Browser-Traffic Interception Network
The Hacker News reports that researchers identified 737 Chrome extensions routing browser traffic through SOCKS5 proxies controlled by the operation behind them. The extensions accumulated 75,486 installations, while 274 impersonated 66 VPN and privacy brands, including Proton VPN, NordVPN, Surfshark, ExpressVPN, and Cloudflare’s 1.1.1.1.
A proxy sits directly in a user’s traffic path. That makes this more consequential than a collection of misleading icons: affected extensions could redirect browsing sessions through infrastructure users neither selected nor understood.
Google removals can reduce immediate exposure, but the campaign succeeds if publishers can simply return with new names and extension IDs. The deciding signal will be whether the same proxy infrastructure or developer identities reappear inside productivity, password-management, or security-themed extensions.
⚡ What Most People Missed
- Gunra’s Fortinet access route: Infosecurity Magazine’s August 12 reporting reinforces the joint U.S.–South Korean warning that Gunra is exploiting CVE-2024-55591 and CVE-2025-24472 against Fortinet devices. It did not receive another full slot because the core campaign was covered on August 11 and no material operational change was verified inside this edition’s window.
- Microsoft Office CVE-2026-21509: Microsoft’s emergency Office patch and the reported APT28 exploitation remain important, but the underlying disclosure predates this 24-hour edition. No fresh change was verified, so the story remains a patch priority rather than recycled headline copy.
- Langflow’s exploited RCE: CVE-2026-9198 can give an unauthenticated attacker code execution on exposed Langflow AI workflow servers. CISA’s action and the core exploitation evidence predate this edition; the continuing risk is forgotten laboratory deployments holding model API keys, database passwords, and cloud credentials.
- Cisco’s August 14 deadline: The federal remediation clock for CVE-2026-20349 is still running. Because the flaw can reload Cisco ASA and FTD firewalls, defenders should also check whether outages coincide with login attempts or configuration changes—the crash may be distraction rather than destination.
- Metabase’s deadline is also still live: Federal agencies have through August 14 to remediate CVE-2026-72898. An internal analytics server can hold credentials for several downstream databases, making one neglected Metabase instance a surprisingly efficient map of an organization’s data estate.
From the Foreign Press
No fresh foreign-language item without English coverage cleared the operational threshold for this edition. Xakep’s new Russian-language entries covered VPS setup, a business book, and JavaScript license-check analysis—not new threat actors, exploitation, malware, or incident intelligence worth padding a 24-hour briefing with.
📅 What to Watch
- If SharePoint exploitation produces persistent access after servers are patched, it means public PoC release has already created a downstream incident wave rather than a scanning spike.
- If Adobe confirms successful CVE-2026-71362 compromises, merchants will need to invalidate sessions and investigate customer-account changes instead of treating the update as closure.
- If City-Forum victims begin notifying customers, SaaS guest permissions will become a breach-response category rather than an annual configuration-review item.
- If the Chrome extensions return under new publisher identities but reuse the same proxies, Google’s takedowns will have removed listings without disrupting the operation.
- If CVE-2026-68820 appears in commodity intrusion frameworks, Lazarus’s privilege-escalation tool will have crossed from targeted espionage into routine criminal tradecraft.
The Closer
A forged SharePoint badge, a Magento customer mask, and a “privacy” extension feeding the browser through someone else’s basement: trust had a visually complicated Thursday.
Meanwhile, the public SaaS portal continues insisting the filing cabinet was technically outside.
Check the guest account.
Forward this to whoever still thinks browser extensions are the harmless kind of add-on.