Skip to main content
All Threat Briefings
Weekly Threat AwarenessSeptember 3, 2026|Vol. 1 · Issue 11

Weekly Threat Awareness ReportSharePoint RCE Exploited · Tomcat Command Injection · npm-Hosted ClickFix Lures

Another actively exploited SharePoint flaw leads this week - an input-validation bug that lets an attacker run code on the server, with proof-of-concept code already public on GitHub. It is joined by a years-old Apache Tomcat command-injection flaw still being exploited against Windows servers, and a Microsoft Defender information-disclosure issue that belongs in the regular patch cycle. On the campaign side, an actor is using the npm registry and its mirrors as free, trusted hosting for fake Cloudflare CAPTCHA pages that funnel victims into ClickFix, and SOCRadar has mapped AnonyMousKIT, an AI-driven phishing platform built to strip Activation Lock from stolen Apple devices. The through-line: attackers are borrowing trust - from developer infrastructure, from brand support channels, and from software that organizations assume is long since patched.

VT

Vaughn Thomas

Compliance Engineer & Threat Researcher · SOClogix Cyber Group

Technical review: William Johnson, VP of Security Operations

About the Analyst

Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.

Full bio and published research LinkedIn

200+

Threat groups tracked

50+

Intel feeds monitored

3 yrs

Threat research tenure

This Week's Threat Landscape Mindmap

Threat landscape for August 24 - August 28, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Threat landscape mindmap, August 24-28, 2026. Weekly assessment: the software build layer is the battleground. Top threats: Rust crate supply chain proc-macro1 typosquat, SharePoint SharpViewStateKing webshell framework, ITG27 (Mustang Panda) India energy espionage, Manic Android banking and spyware malware.
Weekly assessment: the software build layer is the battleground. Priority: audit dependencies across all ecosystems, treat AI assistants and extensions as privileged insiders, and rotate developer and cloud credentials before build-time compromise cascades. View full size

Vulnerabilities at a Glance

Exploitation status and required action for each client-facing CVE covered this week.

CVEProductSeverityExploitation StatusFixPriority
CVE-2026-63520Microsoft SharePointHighActive - public PoC; 10+ IOCsPatch without delayURGENT
CVE-2019-0232Apache Tomcat CGI Servlet (Windows)HighActive - public exploits; 8 IOCsUpdate Tomcat; disable CGIURGENT
CVE-2026-50657Microsoft DefenderMediumLocal access required; exploitation not reportedNext Defender updateThis cycle

CVEs Affecting Client Assets

Vulnerabilities identified this week with direct relevance to common enterprise environments. Two are under active exploitation with public exploit code.

HighCVE-2026-63520 New this week Actively exploited Public PoC
10+IOCs

Microsoft SharePoint - Remote Code Execution

Improper Input Validation (CWE-20)  ·  Unauthorized · Remote  ·  Actively exploited

Series context: SharePoint leads this briefing for the third week running, after CVE-2026-50522 (Aug 20) and CVE-2026-55040 (Aug 27). This week's mindmap also flags the SharpViewStateKing webshell framework actively exploiting CVE-2025-53770 - on-premises SharePoint remains a priority target.

A high-severity flaw in Microsoft SharePoint lets an unauthorized attacker execute malicious code remotely over a network. It stems from improper input validation: SharePoint fails to properly check the data it receives, so an attacker can disguise malicious commands as standard input that the system then executes. Exploitation could lead to full system compromise, unauthorized data access, or ransomware deployment, and gives attackers a foothold inside the organization's internal infrastructure. The flaw is being exploited in the wild, and proof-of-concept exploit code on GitHub lowers the barrier to entry. No state-sponsored APT groups have been linked to it yet, but more than 10 identified indicators of compromise and significant social-media discussion show a high level of active interest.

Recommended Actions

  • Patch SharePoint environments without delay - the exploit is already circulating publicly
  • Sweep SharePoint servers for the published indicators of compromise to confirm they were not reached before patching
  • Watch for unexpected processes spawned by SharePoint and for new files in its web directories
HighCVE-2019-0232 Actively exploited Public PoC
8IOCs

Apache Tomcat CGI Servlet - OS Command Injection on Windows

OS Command Injection (CWE-78)  ·  Remote  ·  Windows with enableCmdLineArguments enabled

A high-severity flaw in the Common Gateway Interface (CGI) Servlet of various Apache Tomcat versions lets attackers run unauthorized commands on Windows servers. The root cause is a mismatch between how the Java Runtime Environment passes command-line arguments and how Windows parses them, so special characters are not properly neutralized. Exploitation grants code execution with the same privileges as the Tomcat server - enough for data theft, malware installation, or total control of the server. Any organization running Tomcat on Windows with the enableCmdLineArguments option active is at high risk. Although the flaw dates to 2019, it is actively exploited in the wild, with numerous public proofs of concept and exploit scripts available for download. No APT groups have been explicitly linked, but the ready availability of tooling makes it a target for opportunistic attackers, and 8 indicators of compromise are known.

Recommended Actions

  • Update to the latest patched version of Apache Tomcat - the primary action to permanently close the gap
  • Disable the CGI Servlet unless it is strictly necessary
  • Verify that enableCmdLineArguments is turned off on every Windows Tomcat instance
  • Inventory Tomcat on Windows specifically, including copies bundled inside third-party applications
MediumCVE-2026-50657 New this week

Microsoft Defender - Exposure of Private Personal Information

Exposure of Private Personal Information (CWE-359)  ·  Local access required

A moderate-severity issue in Microsoft Defender may unintentionally reveal sensitive details to someone who should not have access to them on the local computer. An attacker with local access to a machine could view private data that Defender is intended to protect, creating a privacy risk for any individual or organization relying on the tool to secure sensitive information and potentially leading to unauthorized disclosure of user-specific data. Because local access is required, this is not an emergency change - but it should not be skipped either.

Recommended Actions

  • Apply upcoming Microsoft Defender updates as part of the regular maintenance schedule
  • Confirm Defender platform and engine updates are actually landing across the fleet, not just signature updates

Active Threats & Campaigns

Threat actor activity and disclosed tradecraft with immediate defensive relevance.

ClickFix PhishingOX Security · inf0stache · IntelFusions New this week

npm/unpkg Fake Cloudflare CAPTCHA ClickFix Campaign

A threat actor is using the npm registry and its mirrors as free, trusted hosting for fake Cloudflare CAPTCHA pages that funnel victims into ClickFix social engineering. Because some of these platforms let individual files inside npm packages be opened directly in a browser, they effectively become free web hosting for phishing pages on a reputable domain. OX Security found 24 packages carrying a single index.html lure that redirects visitors to attacker infrastructure. None run code at install time - developers are not the target; the people clicking the links are. After Chrome flagged the original Microsoft typosquat, the actor switched to api.keyval.org as a dead drop resolver, swapping destinations without republishing a single package. The technique was first spotted in July by researcher inf0stache in a "china_airlines" npm package that used a fake Cloudflare verification page, and was also reported by IntelFusions.

Recommended Actions

  • Treat direct browser requests for HTML pages on npm mirror domains as potentially suspicious
  • Review web proxy logs for lookups of api.keyval.org, which the actor uses as a dead drop resolver
  • Train users that no legitimate CAPTCHA asks them to paste or run a command on their computer

Campaign Profile

Source: OX Security

Hosting: npm registry and mirrors (e.g. unpkg)

Packages: 24, each carrying one index.html lure

Lure: Fake Cloudflare CAPTCHA → ClickFix

Install-time code: None

Dead drop: api.keyval.org

AI Phishing-as-a-ServiceSOCRadar Threat Research Unit New this week

AnonyMousKIT - AI-Powered PhaaS Targeting Stolen Apple Devices

SOCRadar's Threat Research Unit (STRU) conducted an inside-out analysis of AnonyMousKIT, a credit-metered, AI-powered Phishing-as-a-Service platform engineered to disable Apple's Activation Lock on stolen devices. The platform automates credential harvesting through a five-channel pipeline: email, SMS, WhatsApp, recorded voice, and conversational AI voice agents impersonating "Alice from Apple Support". By exploiting a bare-relative-path coding flaw in the kit, STRU unraveled a shared-codebase reseller supply chain spanning 506 domains, 168 storefront brands, and 30 confirmed backend installations active since February 2024. Unlike a traditional centralized threat group, AnonyMousKIT operates as a decentralized enterprise structured across four specialized tiers of a cybercrime supply chain.

Recommended Actions

  • Warn staff that contact about a lost or stolen Apple device - by email, text, WhatsApp, or a convincing AI voice call - may be an attempt to harvest their Apple Account credentials
  • Verify any "Apple Support" contact through official channels before sharing credentials or codes
  • Keep corporate Apple devices enrolled in MDM with Activation Lock managed, and report losses through IT immediately

Threat Profile

Source: SOCRadar Threat Research Unit

Goal: Remove Activation Lock from stolen Apple devices

Model: Credit-metered, AI-powered PhaaS

Channels: Email, SMS, WhatsApp, voice, AI voice agent

Footprint: 506 domains, 168 brands, 30 backends

Active since: February 2024

Sources

Primary reporting behind this week's briefing.

  • · Microsoft Security Update Guide - CVE-2026-63520, CVE-2026-50657
  • · Apache Tomcat security advisory - CVE-2019-0232
  • · OX Security - npm fake Cloudflare CAPTCHA research
  • · inf0stache and IntelFusions - earlier "china_airlines" npm lure reporting
  • · SOCRadar Threat Research Unit - AnonyMousKIT analysis
VT

Vaughn Thomas

Compliance Engineer & Threat Researcher, SOClogix

Technical review: William Johnson, VP of Security Operations

Full bio →
VT

Vaughn Thomas

Compliance Engineer

SOClogix Cyber Group

200+

Threat groups tracked

50+

Intel feeds monitored

52×

Reports per year

Global dark web & forum monitoring
Live CISA KEV & NVD tracking
Adversary TTP analysis
Compliance-threat intersection

Get Weekly Briefings Free

Confirmed via email. No spam. Unsubscribe anytime.

This Week at a Glance

CVEs covered3
Actively exploited2
Public exploit code2
Active campaigns2
Malicious npm packages24
AnonyMousKIT domains506

Get Vaughn's Briefing Every Week

Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.

Confirmed via email. No spam. Unsubscribe anytime.

Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.