Last Updated On

Honeypots Catch SAP Commerce RCE as Cisco Deadline and Clop Converge
Honeypots lit up for a perfect score SAP Commerce flaw three days after it left the patch notes, turning theory into live traffic with no public proof of concept in sight. At the same moment the federal clock on an unauthenticated Cisco firewall crash expired and Clop placed Shell among forty three alleged PLM victims while a live operator phishing kit began harvesting cards and one time codes in real time.
Edge systems and application tiers are now compressing from disclosure to exploitation inside a single news cycle. Extortion pressure against engineering drawings and collaboration platforms sits beside browser based command channels that treat government webmail and crypto users as interchangeable targets.
The practical order is clear. Patch the storefront, the remote access VPN, the product lifecycle stack, and the analytics layer first, then hunt the new WebSocket and native messaging artifacts before the next leak site update arrives.
10
CVSS Score
51
IOC Count
18
Source Count
71
Confidence Score
CVE-2026-58231, CVE-2026-20349, CVE-2026-12569, CVE-2026-68820, CVE-2026-72898, CVE-2026-71362, CVE-2026-59310, CVE-2026-55040, CVE-2026-65309, CVE-2026-65310, CVE-2026-65311, CVE-2026-65313, CVE-2026-43284, CVE-2026-43500, CVE-2026-50656
Clop, ShinyHunters, JWR likely Outsider variant operators, Jewelbug, HoneyMyte Mustang Panda, Unattributed
Retail e commerce, energy oil and gas, manufacturing PLM, government, defense aerospace, telecommunications, cryptocurrency, commercial facilities building automation, financial services, collaboration SaaS
Global, Europe, North America, Southeast Asia, Middle East, South Asia, Taiwan, Myanmar, Mongolia, Pakistan, Russia, Germany, United States, Turkey, Iran, France, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal
Chapter 01 - Executive Overview
CVE-2026-58231 is Critical for retail and brand e commerce. SAP’s 11 Aug note describes unauthenticated RCE via a default authentication client in Commerce Cloud Data Hub Adapter for COM_CLOUD 2211 and 2211 JDK21, CVSS 10.0. SAP did not call it exploited. Consulted sources report honeypots now seeing attempts with no public proof of concept known. Shadowserver fingerprints more than 4200 SAP Commerce IPs, mostly Europe and North America. Any organization running Hybris or Commerce Cloud must treat this as an immediate patch and hunt item.
CVE-2026-20349 is High for perimeter and remote access VPN. CISA KEV lists it. Unauthenticated SSL VPN requests can reload ASA and FTD devices. Federal BOD due date is today, 14 Aug 2026. Cisco published no workaround. Any remaining unpatched remote access VPN pair is late. An unauthenticated remote attacker can send a single crafted HTTP request to a device with IKEv2 Remote Access VPN, SSL VPN, or Zero Trust Network Access enabled, forcing an unplanned reload and denial of service. Neither Cisco nor CISA has disclosed the exploiting party, targeted organizations, or whether any attack succeeded beyond triggering a reload.
Clop PLM wave is High for energy, industrial, and medtech. Shell stated it is investigating a potential incident after Clop claimed 89 GB of drawings, facility test scans, photos, and project plans as one of 43 new Windchill and FlexPLM victims, also naming GE and Philips. The CVE in that wave, CVE-2026-12569, is already KEV. Shell has not confirmed theft or Clop.
JWR is High for payments, retail, and consumer identity. Talos describes a real time PhaaS with a 44 page Vue kit. Operators steer SMS victims through Shopify, PayPal, Apple, Klarna, and bank flows while harvesting PAN, OTP, passport images, and device fingerprints. Medium confidence Outsider variant assessment follows earlier Ghost Hook activity.
Jewelbug / XG Web is High for government, military, aerospace adjacent, and crypto users. Symantec describes one panel running Middle East, Southeast Asia, and South Asia espionage alongside OKX and Binance SEO fraud, with more than 1 million implant check ins, more than 580000 cookies, and watering hole activity on more than 15 government webmail tenants via a shared hoster. Treat as elevated vendor research.
Leadership takeaway: the 24 hour picture shows edge and app tier exploitation compressing to days, plus extortion against PLM and SaaS, plus browser as C2. Patch Commerce Cloud, ASA and FTD, Windchill and FlexPLM, SharePoint, vCenter, Adobe and Magento, and Metabase first. Assume Clop and ShinyHunters claims are unpaid leak pressure until the victim confirms.
Chapter 02 - Threat & Exposure Analysis
CVE-2026-58231 enables unauthenticated RCE through Commerce Cloud’s default client. Consulted sources describe the attacker abusing a default authentication client and sending crafted input to under validated functions, resulting in code execution and internal component compromise with high confidentiality, integrity, and availability impact. First honeypot hits appeared Friday with no public proof of concept. That combination usually signals private exploit or rapid patch diff work. Do not wait for KEV listing. Adjacent SAP criticals from the same day covering MII code injection and NetWeaver memory corruption show no exploitation evidence in this window.
CVE-2026-20349 allows unauthenticated ASA and FTD reload via Remote Access SSL VPN. Cisco PSIRT confirmed in the wild use. CISA added it to KEV on 11 Aug with due date 14 Aug. The condition depends on SSL listen sockets for VPN or Zero Trust features. Actor and targeting remain unconfirmed. Root cause is insufficient error checking when the Remote Access SSL VPN service processes HTTP requests, categorized under improper clearing of heap memory. A single crafted HTTP request to enabled IKEv2 Remote Access VPN, SSL VPN, or Zero Trust Network Access services forces a control plane crash and full reload. Impact is availability only with no confirmed code execution, data exfiltration, or persistence. The trigger is remotely repeatable, enabling sustained crash loop until the service is disabled or patched.
CVE-2026-12569 sits at the center of Clop activity against internet exposed PTC PLM. Consulted sources list 43 leak site names. Prior reporting noted JSP webshells. CISA previously forced a three day federal fix and BSI issued an overnight warning. Shell, GE, and Philips comments are limited to Shell’s investigation statement. Treat engineering drawing theft as a safety and intellectual property problem if confirmed.
JWR functions as live operator phishing rather than a static kit. It uses Host Bridge plus Vue content mode, more than 40 C2 instructions covering card, 2FA, PayPal, and tip change flows, AES CTR WebSocket with HTTP long poll fallback, and Simplified Chinese operator strings. SMS lures target Singapore land transport, national post, UAE tolls, and regional couriers. No code overlap with Lucid, Darcula, or Lighthouse appears, but the same Chinese PhaaS tradecraft is present.
GeoServer jsonArrayContains SQLi remains unpatched and probed. Disclosure occurred 12 Aug 10:46 UTC. Hundreds of attempts from a small IP pool currently produce error triggering recon rather than demonstrated mass RCE. Prior GeoServer KEV history supplies the reason to isolate now. No CVE is assigned.
CVE-2026-71362, CVE-2026-55040, and CVE-2026-59310 show active interest. Unauthenticated Adobe and Magento session switch to another customer account saw attempts immediately after the isolated patch. A four bug JWT chain involving alg none, STS thumbprint, untrusted issuer, and unverified signature produced multiple attempts across Hong Kong, Japan, Netherlands, Taiwan, and United States source IPs. Quirso tracks more than 360 victim IPs across 47 countries from 3 Aug with reverse ssh persistence. Half of those IPs sit in Germany, United States, Turkey, Iran, and France. None of these three appear in KEV from consulted sources today.
Jewelbug runs a dual mission. XG Web uses React, Node, and MySQL. The PDF Viewer extension plus com.microsoft.runedge native host, Antino via Graph API, and ClientKing Rust implant with DNS tunnel, SOCKS, and in memory kernel modules appear, including builds stamped with a United States aerospace manufacturer internal proxy. Google Docs payload drops, fonts.chrorne[.]com watering hole, and microsoft flash[.]com second stage complete the picture.
CoolClient plus signed msagent.sys appears in Kaspersky reporting only. HoneyMyte deploys CoolClient after PlugX. The driver carries a 2013 to 2014 Nanjing Ranyi Technology certificate and hides process, file, registry, and C2 via Nsiproxy hook. Use for hunting only and do not cite as sole attribution.
Check Point Q2 2026 ransomware baseline shows 2139 leak site victims, flat quarter over quarter and up 33 percent year over year. Top 10 share fell to 57.6 percent across 93 active groups. Qilin led with 279 versus The Gentlemen at 269. Payment rate sits near 23 percent. One panel was allegedly AI built in roughly three days. This baseline explains why PLM and SaaS extortion remain the default business model this week.
Chapter 03 - Operational Response
For SAP Commerce isolate the Data Hub and apply note 3771065. Hunt unauthenticated calls to Data Hub Adapter functions. If patching cannot occur tonight, pull the adapter off the internet and disable default clients. Inventory the 4200 class exposure set internally rather than relying solely on external fingerprinting.
For Cisco ASA and FTD treat 14 Aug as missed if not completed. Upgrade to the exact fixed train listed by Cisco. Affected versions span ASA 9.16 through 9.24 and FTD 7.0 through 10.0. Fixed trains include ASA 9.16.4.50, 9.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221 and corresponding FTD hotfix packages. If deferred, disable unused Remote Access VPN, bind SSL sockets only to management VRFs, and watch for unexpected device reloads. No workaround exists.
For PTC Windchill and FlexPLM assume Clop reconnaissance if internet facing. Apply CVE-2026-12569 patches from 17 Jun onward, hunt JSP webshells, revoke exposed accounts, and snapshot before touching evidence. Energy and manufacturing legal teams should pre stage notification language and avoid confirming Clop solely because a leak site claimed it.
For JWR combine smishing defenses with phishing resistant MFA. Block available Talos indicators when retrieved, alert on WebSocket paths containing JWRCVV or webSocket/QT, and prefer FIDO2 over SMS OTP for payments and SSO.
For GeoServer remove the service from the public internet until a vendor fix exists. Restrict WFS and WMS, monitor jsonArrayContains errors, and snapshot database roles especially those with elevated privileges.
For SharePoint, vCenter, Adobe, and Metabase apply the July SharePoint build for CVE-2026-55040, the Broadcom fixed train for CVE-2026-59310 plus hunt for reverse ssh, the Adobe isolated patch for Commerce and Magento, and the Metabase SQLi fix which is already KEV and the alleged ShipMonk vector. Patch and rotate analytics credentials.
For Jewelbug hunt com.microsoft.runedge, unexpected PDF Viewer extensions, Graph API beacons from non Intune hosts, and the listed domains and IPs. Aerospace firms should inspect ClientKing class beacons via the corporate proxy.
For the CISA 13 Aug ICS batch, HIPASE 250 and 250 SCALA versions at or below 7.20 have no known exploitation. Pull unauthenticated data endpoints and shared x11vnc passwords off adjacent networks. Hitachi APM Edge at or below 6.10 belongs to the Dirty Frag class and requires isolation. Metasys XSS requires patching to 14.1.5 or 15.0.1. Versions 12 and 13 are out of support.
17 Jun 2026: PTC begins CVE-2026-12569 patches. 26 Jun 2026: PTC notes heightened threat activity. CISA adds to KEV with three day federal clock. 29 Jul 2026: Broadcom patches CVE-2026-59310. 28 Jul 2026: RingCentral discloses social engineering breach. 03 to 05 Aug 2026: Quirso records vCenter exploitation ramp to more than 340 IPs. 10 Aug 2026: Trezor notified of ShipMonk breach. 11 Aug 2026: SAP Patch Day releases CVE-2026-58231. Adobe issues isolated Commerce patch. Microsoft Patch Tuesday includes CVE-2026-68820 which is exploited. Cisco publishes ASA and FTD advisory. CISA adds Cisco, Windows afd.sys, and Metabase to KEV. 12 Aug 10:46 UTC: GeoServer SQLi becomes public. Probes begin within hours. 12 to 13 Aug: SharePoint CVE-2026-55040 attempt spike follows public proof of concept. 13 Aug: Talos publishes JWR analysis. Symantec publishes Jewelbug dossier. CISA issues ICS advisories for HIPASE, Hitachi, and Metasys. Check Point releases Q2 ransomware baseline. Coverage expands on SharePoint, Adobe, vCenter, and ShieldBreak. 14 Aug: CISA Cisco KEV due date arrives. SAP honeypot activity is reported. Shell issues statement. HIBP confirms RingCentral 1.6 million records. GeoServer receives additional flags.
Chapter 04 - Detection Intelligence
Data Hub Adapter turns a default client into RCE. Mechanism is improper authorization plus weak validation, an application layer authorization break rather than a memory bug. Hunt focuses on unauthenticated or default client tokens hitting Data Hub ingest and transform APIs followed by child process creation on Commerce nodes. No packet level exploit recipe is public.
ASA and FTD heap inspection DoS arises from insufficient error checking on Remote Access SSL VPN HTTP requests. Unauthenticated HTTP to the listen sockets causes reload. Impact is availability of the firewall or VPN with no disclosed RCE in consulted sources. The vulnerable code path services IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access. Affected software covers ASA 9.16 through 9.24 and FTD 7.0 through 10.0.
JWR client engine selects Host Bridge or Vue content mode via window.__HOST_MODE. Session ID JWRCID is persisted. New IDs follow JWRCVV epoch base36 base36 pattern. Worker static/js/ws worker.js holds the socket across navigation. Anti debug uses toString search backtracking regex. Instruction list caps at 50 and trims to 30. Exfil object cvvform carries PAN, CVV, PIN, SSN, ID images, 2FA, PayPal, cookies, and geo data. Shopify path uses signed cart_data so the WebSocket origin appears to match the real checkout host.
Jewelbug watering hole injects a shared hoster template that loads fonts.chrorne[.]com/dist/js/12.qgfvjzvs.chunk.js. The script opens WebSockets to C2, steals cookies, labels the mailbox, then serves a Flash update if the address matches one of nine government domains and the OS is Windows. Payload from microsoft flash[.]com/download/Adobeinstall.exe writes the native messaging host registry key and sideloads PDF Viewer. Observed follow on includes authenticated hits to an internal virtualization API on port 8006.
SharePoint JWT chain uses outer alg none, actor x5t matching farm STS thumbprint, issuer not present in TrustedSecurityTokenServices, and dummy signature acceptance. Proof of concept enumerates domain controller users by SID to locate a site admin.
ShieldBreak is a public LPE proof of concept not confirmed in the wild. Cloud Filter API hydration plus CLFS swap drops attacker phoneinfo.dll into System32. QueueReporting causes wer.dll to load it, producing SYSTEM conhost.exe. Microsoft is investigating. Researchers state it is not a RoguePlanet bypass.
Jewelbug indicators from consulted sources, recommended for TIP ingest with 24 to 48 hour TTL: SHA256 Antino and related: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff, c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc, 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd, plus HTA lures e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf, 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a Domains: fonts.chrorne[.]com, microsoft flash[.]com, fonts.tarotfree101[.]top, robot.avbliud[.]com, www.wps cn[.]com, www.f1ash.org[.]cn, browser update.pages[.]dev, eastus2.wac azure[.]com, mailbycloud[.]com, www.jkskhei[.]com, ns1.jkskhei[.]com, dns.wizkidblogger[.]com IPs: 103.87.9.62, 152.42.174.151, 43.246.208.236, 43.246.208.179, 47.84.37.113, 47.84.51.173, 167.71.195.255, 38.12.1.47, 129.212.237.224, 47.87.71.167, 47.250.208.35, 219.76.254.184 Host artifacts: native messaging host com.microsoft.runedge, extension name PDF Viewer
JWR pattern indicators (full domain list remains insufficient pending GitHub retrieval): session tokens containing JWRCVV or JWRCID, WebSocket path containing webSocket/QT and the fixed suffix khkjsahfjkwhakjlsdwdddddd88, REST paths under api/open for the_final_interface, addClick, pollInstruction, ClamAV Js.Phishing.JwrFramework 10060456 0, Snort 66924 to 66928.
CoolClient paths (values incomplete): msagent.sys and service msagent, libngs.dll, loadcert.ini, cert.ini, scheduled defender.exe Sangfor sideload, registry goopdate, service media_updaten, injected synchost.exe. Hashes remain insufficient.
SAP, GeoServer, SharePoint, Adobe, Clop on Shell, and Cisco ASA/FTD: no extractable network IoCs in consulted sources.
Hunting hypotheses: H1: SAP Commerce child processes spawned by Java or hybris after anonymous POSTs since 11 Aug. H2: GeoServer WFS queries containing jsonArrayContains from non GIS subnets. H3: Chrome extensions named PDF Viewer that request nativeMessaging plus webRequest. H4: Graph API traffic from servers that are not Intune or Exchange. H5: Windchill jsp files created after June 2026 in webapps.
Additional Cisco focused hypotheses: An ASA or FTD device with Remote Access VPN enabled shows an unplanned reload or crash event with no corresponding scheduled maintenance or admin initiated reload. A device shows repeated reload events in a short window consistent with sustained DoS rather than a single incident. Syslog shows abrupt termination of the webvpn, IKEv2, or ZTNA process immediately preceding a reload without a software upgrade or configuration change.
T1566.002 Initial Access for JWR SMS links. D3FEND counterparts include Phishing Signal Analysis and User Account Normalization. T1056.003 Credential Access for JWR streaming form fields before submit. D3FEND counterparts include Multi factor Authentication that is phishing resistant and Inbound Traffic Filtering. T1189 Initial Access for Jewelbug shared template script on government webmail. D3FEND counterparts include Identifier Analysis and Script Content Analysis. T1176.001 Persistence for PDF Viewer plus native messaging host. D3FEND counterparts include Executable Allowlisting and Browser Hardening. T1190 Initial Access for SAP, Adobe, SharePoint, vCenter, GeoServer, Cisco VPN, and PTC. D3FEND counterparts include System Hardening, Network Isolation, and Patch Management. T1505.003 Persistence for JSP webshells on PLM. D3FEND counterparts include File Content Rules and System File Analysis. T1071.001 Command and Control for Graph API, WebSocket, and related channels. D3FEND counterparts include Network Traffic Analysis and DNS Allowlisting. T1014 Defense Evasion for CoolClient msagent.sys. D3FEND counterpart is Driver Load Integrity Checking. Inferred T1499.004 Endpoint Denial of Service Application or System Exploitation for the Cisco ASA and FTD crash trigger under Impact.
Chapter 05 - Governance, Risk & Compliance
SAP Commerce creates customer data and PCI exposure. Unauthenticated RCE on a storefront or Data Hub path is a probable personal data and payment adjacent event if checkout or customer master is reachable. EU retailers should pre compute GDPR 72 hour clocks and avoid starting the clock solely on honeypot reports.
Cisco KEV due today. United States FCEB agencies face BOD evidence pack requirements covering inventory, version, and change ticket due 14 Aug 2026. Non federal organizations should still treat the three day clock as the risk standard. Any organization with regulatory obligations tied to network perimeter availability should log this as a documented risk acceptance or remediation event because no vendor workaround exists.
Clop, Shell, and PLM. If engineering drawings of energy facilities are confirmed stolen, the matter enters safety, export control, and possibly NIS2 or CER territory beyond confidentiality. Shell has not confirmed the leak site contents. GE and Philips offered no comment in consulted sources.
RingCentral 1.6 million records include names, emails, phones, and physical addresses. RingCentral states the core platform was not impacted and only contacted customers are affected. Downstream organizations should watch for vishing against those records. ShinyHunters attribution rests on the actor claim plus dataset match, not a RingCentral attribution.
Trezor and ShipMonk affect approximately 13689 people via a third party Metabase path. Trezor devices themselves were not compromised. Phishing follow on risk remains the residual.
ICS advisories cover HIPASE in energy worldwide with no known exploitation. Metasys versions 12 and 13 are unsupported, creating a board level replace or accept decision rather than a simple patch ticket.
Check Point payment rate drop to approximately 23 percent supports a no pay stance, yet large enterprise averages continue rising. Budget for incident response and reconstruction rather than ransom.
Chapter 06 - Adversary Emulation
SAP Commerce validation remains ATT&CK aligned and limited to owned lab Commerce Cloud instances. Replay unauthenticated Data Hub requests derived from the patch diff only. Success criteria are that note 3771065 blocks the path and the SOC fires the corresponding hunting hypothesis.
JWR purple team smishing uses a benign toll or parcel SMS to a volunteer cohort to measure click to report time. Validate proxy rules on webSocket/QT and JWRCVV patterns without standing up any criminal kit.
SharePoint JWT testing uses the public proof of concept against an isolated farm still on July vulnerable builds to confirm alg none rejection and failure of admin impersonation.
vCenter checks confirm the Syslog service is patched and alert on unexpected outbound SSH like tunnels from vCenter appliances.
Jewelbug testing deploys a decoy PDF Viewer allowlist deny and alerts on com.microsoft.runedge creation.
CoolClient and rootkit emulation must not load the 2013 signed driver in production. Emulate only the user mode signals covering Sangfor sideload, synchost.exe injection, and msagent service name on a snapshot lab.
Cisco focused emulation validates detection coverage for unplanned device reload on Remote Access VPN enabled ASA or FTD without attempting to reproduce the undisclosed crafted request. In a non production lab instance intentionally trigger a controlled process restart or reload via supported administrative commands and verify the SIEM rule correctly classifies it as benign when tagged or flags it for review when untagged. Tabletop scenario: a perimeter ASA cluster member reloads twice within 10 minutes with no scheduled change while Remote Access VPN remains internet facing. Walk through detection trigger, patch level verification against the fixed release table, decision to disable the service versus accept availability loss versus patch immediately, and stakeholder communication if the device serves a business critical remote workforce.
Factor | Contribution | Notes |
|---|---|---|
T1 backbone from Talos, CISA, Check Point, SANS | + high | Solid technical and KEV confirmation for core items |
Cisco vendor advisory plus KEV listing | + high | Authoritative for CVE-2026-20349 exploitation claim |
Specialist telemetry for SAP, Adobe, GeoServer, SharePoint, vCenter | medium | Not KEV confirmed, treated as reported activity |
Leak site claims for Clop and ShinyHunters | low to medium | Partial victim language only, no full confirmation |
Single vendor CoolClient material | low | Cannot carry attribution weight |
Overall daily brief | 71 / 100 | Empty IoC sets left empty, uncertainty preserved |
