Weekly Threat Awareness ReportSharePoint RCE Exploited · Tomcat Command Injection · npm-Hosted ClickFix Lures
Another actively exploited SharePoint flaw leads this week - an input-validation bug that lets an attacker run code on the server, with proof-of-concept code already public on GitHub. It is joined by a years-old Apache Tomcat command-injection flaw still being exploited against Windows servers, and a Microsoft Defender information-disclosure issue that belongs in the regular patch cycle. On the campaign side, an actor is using the npm registry and its mirrors as free, trusted hosting for fake Cloudflare CAPTCHA pages that funnel victims into ClickFix, and SOCRadar has mapped AnonyMousKIT, an AI-driven phishing platform built to strip Activation Lock from stolen Apple devices. The through-line: attackers are borrowing trust - from developer infrastructure, from brand support channels, and from software that organizations assume is long since patched.
Vaughn Thomas
Compliance Engineer & Threat Researcher · SOClogix Cyber Group
Technical review: William Johnson, VP of Security Operations
About the Analyst
Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.
Full bio and published research LinkedIn200+
Threat groups tracked
50+
Intel feeds monitored
3 yrs
Threat research tenure
This Week's Threat Landscape Mindmap
Threat landscape for August 24 - August 28, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Vulnerabilities at a Glance
Exploitation status and required action for each client-facing CVE covered this week.
| CVE | Product | Severity | Exploitation Status | Fix | Priority |
|---|---|---|---|---|---|
CVE-2026-63520 | Microsoft SharePoint | High | Active - public PoC; 10+ IOCs | Patch without delay | URGENT |
CVE-2019-0232 | Apache Tomcat CGI Servlet (Windows) | High | Active - public exploits; 8 IOCs | Update Tomcat; disable CGI | URGENT |
CVE-2026-50657 | Microsoft Defender | Medium | Local access required; exploitation not reported | Next Defender update | This cycle |
CVEs Affecting Client Assets
Vulnerabilities identified this week with direct relevance to common enterprise environments. Two are under active exploitation with public exploit code.
CVE-2026-63520 New this week Actively exploited Public PoCMicrosoft SharePoint - Remote Code Execution
Improper Input Validation (CWE-20) · Unauthorized · Remote · Actively exploited
A high-severity flaw in Microsoft SharePoint lets an unauthorized attacker execute malicious code remotely over a network. It stems from improper input validation: SharePoint fails to properly check the data it receives, so an attacker can disguise malicious commands as standard input that the system then executes. Exploitation could lead to full system compromise, unauthorized data access, or ransomware deployment, and gives attackers a foothold inside the organization's internal infrastructure. The flaw is being exploited in the wild, and proof-of-concept exploit code on GitHub lowers the barrier to entry. No state-sponsored APT groups have been linked to it yet, but more than 10 identified indicators of compromise and significant social-media discussion show a high level of active interest.
Recommended Actions
- Patch SharePoint environments without delay - the exploit is already circulating publicly
- Sweep SharePoint servers for the published indicators of compromise to confirm they were not reached before patching
- Watch for unexpected processes spawned by SharePoint and for new files in its web directories
CVE-2019-0232 Actively exploited Public PoCApache Tomcat CGI Servlet - OS Command Injection on Windows
OS Command Injection (CWE-78) · Remote · Windows with enableCmdLineArguments enabled
A high-severity flaw in the Common Gateway Interface (CGI) Servlet of various Apache Tomcat versions lets attackers run unauthorized commands on Windows servers. The root cause is a mismatch between how the Java Runtime Environment passes command-line arguments and how Windows parses them, so special characters are not properly neutralized. Exploitation grants code execution with the same privileges as the Tomcat server - enough for data theft, malware installation, or total control of the server. Any organization running Tomcat on Windows with the enableCmdLineArguments option active is at high risk. Although the flaw dates to 2019, it is actively exploited in the wild, with numerous public proofs of concept and exploit scripts available for download. No APT groups have been explicitly linked, but the ready availability of tooling makes it a target for opportunistic attackers, and 8 indicators of compromise are known.
Recommended Actions
- Update to the latest patched version of Apache Tomcat - the primary action to permanently close the gap
- Disable the CGI Servlet unless it is strictly necessary
- Verify that enableCmdLineArguments is turned off on every Windows Tomcat instance
- Inventory Tomcat on Windows specifically, including copies bundled inside third-party applications
CVE-2026-50657 New this weekMicrosoft Defender - Exposure of Private Personal Information
Exposure of Private Personal Information (CWE-359) · Local access required
A moderate-severity issue in Microsoft Defender may unintentionally reveal sensitive details to someone who should not have access to them on the local computer. An attacker with local access to a machine could view private data that Defender is intended to protect, creating a privacy risk for any individual or organization relying on the tool to secure sensitive information and potentially leading to unauthorized disclosure of user-specific data. Because local access is required, this is not an emergency change - but it should not be skipped either.
Recommended Actions
- Apply upcoming Microsoft Defender updates as part of the regular maintenance schedule
- Confirm Defender platform and engine updates are actually landing across the fleet, not just signature updates
Active Threats & Campaigns
Threat actor activity and disclosed tradecraft with immediate defensive relevance.
npm/unpkg Fake Cloudflare CAPTCHA ClickFix Campaign
A threat actor is using the npm registry and its mirrors as free, trusted hosting for fake Cloudflare CAPTCHA pages that funnel victims into ClickFix social engineering. Because some of these platforms let individual files inside npm packages be opened directly in a browser, they effectively become free web hosting for phishing pages on a reputable domain. OX Security found 24 packages carrying a single index.html lure that redirects visitors to attacker infrastructure. None run code at install time - developers are not the target; the people clicking the links are. After Chrome flagged the original Microsoft typosquat, the actor switched to api.keyval.org as a dead drop resolver, swapping destinations without republishing a single package. The technique was first spotted in July by researcher inf0stache in a "china_airlines" npm package that used a fake Cloudflare verification page, and was also reported by IntelFusions.
Recommended Actions
- Treat direct browser requests for HTML pages on npm mirror domains as potentially suspicious
- Review web proxy logs for lookups of api.keyval.org, which the actor uses as a dead drop resolver
- Train users that no legitimate CAPTCHA asks them to paste or run a command on their computer
Campaign Profile
Source: OX Security
Hosting: npm registry and mirrors (e.g. unpkg)
Packages: 24, each carrying one index.html lure
Lure: Fake Cloudflare CAPTCHA → ClickFix
Install-time code: None
Dead drop: api.keyval.org
AnonyMousKIT - AI-Powered PhaaS Targeting Stolen Apple Devices
SOCRadar's Threat Research Unit (STRU) conducted an inside-out analysis of AnonyMousKIT, a credit-metered, AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. The platform automates credential harvesting through a five-channel pipeline: email, SMS, WhatsApp, recorded voice, and conversational AI voice agents impersonating "Alice from Apple Support". By exploiting a bare-relative-path coding flaw in the kit, STRU unraveled a shared-codebase reseller supply chain spanning 506 domains, 168 storefront brands, and 30 confirmed backend installations active since February 2024. Unlike a traditional centralized threat group, AnonyMousKIT operates as a decentralized enterprise structured across four specialized tiers of a cybercrime supply chain.
Recommended Actions
- Warn staff that contact about a lost or stolen Apple device - by email, text, WhatsApp, or a convincing AI voice call - may be an attempt to harvest their Apple Account credentials
- Verify any "Apple Support" contact through official channels before sharing credentials or codes
- Keep corporate Apple devices enrolled in MDM with Activation Lock managed, and report losses through IT immediately
Threat Profile
Source: SOCRadar Threat Research Unit
Goal: Remove Activation Lock from stolen Apple devices
Model: Credit-metered, AI-powered PhaaS
Channels: Email, SMS, WhatsApp, voice, AI voice agent
Footprint: 506 domains, 168 brands, 30 backends
Active since: February 2024
Sources
Primary reporting behind this week's briefing.
- · Microsoft Security Update Guide - CVE-2026-63520, CVE-2026-50657
- · Apache Tomcat security advisory - CVE-2019-0232
- · OX Security - npm fake Cloudflare CAPTCHA research
- · inf0stache and IntelFusions - earlier "china_airlines" npm lure reporting
- · SOCRadar Threat Research Unit - AnonyMousKIT analysis
Protect your environment
Vaughn Thomas
Compliance Engineer & Threat Researcher, SOClogix
Technical review: William Johnson, VP of Security Operations
Vaughn Thomas
Compliance Engineer
SOClogix Cyber Group
200+
Threat groups tracked
50+
Intel feeds monitored
52×
Reports per year
Get Weekly Briefings Free
This Week at a Glance
Get Vaughn's Briefing Every Week
Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.
Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.