Weekly Threat Awareness ReportExchange Auth Bypass Exploited · Defender "ShieldBreak" · PivotC2 FortiGate RAT
Three high-severity Microsoft flaws lead this week: an Exchange Server authentication bypass that UNC3886 is actively exploiting to gain administrative privileges, the "ShieldBreak" privilege escalation in Defender's Malware Protection Engine, and an Outlook integer overflow that enables remote code execution and is already noted as exploited. On the campaign side, a Russian-speaking cybercrime operator is exploiting a FortiOS heap overflow to plant PivotC2, a post-exploitation RAT built for FortiGate appliances, and SAP has patched a CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud. The through-line, echoed by this week's mindmap: edge exploitation and AI-assisted operations are converging - and the email platform and security tooling organizations trust most are squarely in scope.
Vaughn Thomas
Compliance Engineer & Threat Researcher · SOClogix Cyber Group
Technical review: William Johnson, VP of Security Operations
About the Analyst
Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.
Full bio and published research LinkedIn200+
Threat groups tracked
50+
Intel feeds monitored
3 yrs
Threat research tenure
This Week's Threat Landscape Mindmap
Threat landscape for August 31 - September 6, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Vulnerabilities at a Glance
Exploitation status and required action for each CVE covered this week, including the SAP Commerce Cloud flaw covered under campaigns below.
| CVE | Product | Severity | Exploitation Status | Fix | Priority |
|---|---|---|---|---|---|
CVE-2026-58231 | SAP Commerce Cloud (COM_CLOUD 2211) | Critical · CVSS 10.0 | Patched; exploitation not reported | SAP August Security Patch Day | URGENT |
CVE-2026-62911 | Microsoft Exchange Server | High | Active - UNC3886; public exploit | Microsoft patches + mitigations | URGENT |
CVE-2026-70329 | Microsoft Outlook | High | Noted as exploited; no public exploit | Apply update when released | URGENT |
CVE-2026-64914 | Microsoft Defender (Malware Protection Engine) | High | Publicly discussed; no active exploits | Standard Defender updates | This cycle |
CVEs Affecting Client Assets
Vulnerabilities identified this week with direct relevance to common enterprise environments. All three sit in the Microsoft stack, and two are noted as exploited.
CVE-2026-62911 New this week Actively exploited Public exploit APT-linkedMicrosoft Exchange Server - Authentication Bypass to Admin Privileges
Authentication Bypass by Capture-replay (CWE-294) · Remote · Actively exploited by UNC3886
A high-severity flaw in the core authentication process of Microsoft Exchange Server lets attackers bypass security checks and gain unauthorized administrative privileges. It is an authentication bypass by capture-replay: an attacker intercepts valid communication data and reuses it to trick the server into granting access as if they were a legitimate user. Successful exploitation hands the attacker the keys to the email environment, exposing organizations to data theft, unauthorized access to sensitive email, and lateral movement deeper into the corporate network. The flaw is being exploited in the wild, intelligence reporting links the activity to the advanced threat group UNC3886, and publicly available exploit code has been identified, significantly lowering the barrier to entry.
Recommended Actions
- Apply all available Microsoft security patches and mitigation guidance for Exchange Server immediately
- Monitor the Exchange environment for anomalous activity - unexpected administrative actions, new mailbox permissions, and new transport or inbox rules
- Prioritize internet-facing Exchange servers, and treat any server exposed before patching as potentially compromised until reviewed
CVE-2026-70329 New this week Actively exploitedMicrosoft Outlook - Remote Code Execution
Integer Overflow or Wraparound (CWE-190) · Unauthorized · Network · Noted as exploited
A high-severity flaw in the core processing logic of Microsoft Outlook could let an unauthorized attacker execute malicious code remotely. It is an integer overflow: a calculation produces a number too large for the software to handle, which an attacker can use to manipulate the program's behavior and potentially take control of the application. Exploited over a network, it enables arbitrary code execution on a victim's machine, leading to data theft, malware installation, or complete system compromise - a critical threat for anyone who interacts with untrusted email or network-based Outlook resources. The vulnerability is noted as being exploited, though no specific exploit code or APT groups have been identified and there are no known indicators of compromise yet, so vigilance is essential until further technical details emerge.
Recommended Actions
- Monitor official Microsoft channels and apply the Outlook security update as soon as it is available
- Apply any interim mitigation guidance Microsoft publishes before the update ships
- Remind users to treat unexpected email and attachments with extra caution while no indicators of compromise exist to detect attacks
CVE-2026-64914 New this weekMicrosoft Defender "ShieldBreak" - Elevation of Privilege
Improper Access Control (CWE-284) · Malware Protection Engine · No active exploits identified
A high-severity flaw nicknamed "ShieldBreak" in the Microsoft Malware Protection Engine - the core scanning engine inside Microsoft Defender - lets an attacker escalate their permissions to a level that would normally require administrative authorization, potentially taking full control of a system. It is an improper access control issue: the software fails to properly restrict who can perform certain high-level actions, effectively creating a bypass. The result is unauthorized access to sensitive files, data tampering, or malware installation, with the security tool meant to protect the system turned against it. The flaw is being discussed publicly, but there are currently no identified active exploits, APT activity, or known indicators of compromise - it is not yet being widely weaponized, though the public attention calls for proactive defense.
Recommended Actions
- Ensure all Microsoft Defender software is fully up to date - Microsoft delivers the fix through its standard update channels
- Confirm the Malware Protection Engine version on endpoints rather than assuming automatic updates applied
- Alert on attempts to tamper with or disable Defender, a common precursor to privilege abuse
Active Threats & Campaigns
Threat actor activity and disclosed tradecraft with immediate defensive relevance.
PivotC2 - FortiGate Post-Exploitation RAT Delivered via CVE-2025-25249
SOCRadar's Threat Research Unit identified ongoing exploitation, since July 2026, of CVE-2025-25249, a heap-based buffer overflow in the wireless controller daemon of FortiOS and FortiSwitchManager. The exploit binary fortirun.bin opens a Node.js reverse shell that stages PivotC2, a post-exploitation RAT for FortiGate appliances. Over a single TLS socket it tunnels shells, proxies, port forwarding, scanning, and configuration harvesting with credential decryption. Of 30,000 targeted addresses, 178 devices were infected, mostly in the United States, with data exfiltration confirmed at two US organizations. The attack lifecycle runs from exploitation and PivotC2 deployment through internal tunneling, host discovery, browser credential theft, lateral movement, and exfiltration. Recovered tool outputs show heavy reliance on AI tools across multiple stages, including automatically generated command-output reports. Russian-language comments, exfiltration tactics, and active discovery of storage and backup infrastructure support a high-confidence assessment of a Russian-speaking, financially motivated cybercrime operator, which also appears to target CVE-2024-47575 (FortiManager), CVE-2026-35273 (PeopleSoft Enterprise PeopleTools), and CVE-2024-26304 (ArubaOS).
Recommended Actions
- Patch FortiOS and FortiSwitchManager for CVE-2025-25249 and review exposure of the wireless controller service
- Hunt FortiGate appliances for a fortirun.bin binary, unexpected Node.js processes, and long-lived outbound TLS sessions
- On any suspect appliance, rotate credentials stored in the device configuration - PivotC2 harvests and decrypts them
- Close the actor's other doors: CVE-2024-47575 (FortiManager), CVE-2026-35273 (PeopleTools), CVE-2024-26304 (ArubaOS)
Campaign Profile
Source: SOCRadar Threat Research Unit
CVE: CVE-2025-25249 (heap overflow)
Loader: fortirun.bin → Node.js reverse shell
Implant: PivotC2 over a single TLS socket
Scope: 30,000 targeted, 178 infected, mostly US
Actor: Russian-speaking, financially motivated
CVE-2026-58231SAP August Security Patch Day New this weekSAP Commerce Cloud - Unauthenticated Remote Code Execution
SAP patched a maximum-severity remote code execution flaw in SAP Commerce Cloud as part of its August Security Patch Day. It carries a CVSS score of 10.0 and stems from an improper authorization weakness in the core Data Hub Adapter extension, combined with insufficient input validation. An unauthenticated attacker with network access can abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation - a low-complexity attack that could achieve arbitrary code execution and compromise internal components, with high impact on the confidentiality, integrity, and availability of the application. Affected releases are COM_CLOUD 2211 and COM_CLOUD 2211-JDK21. Actual impact depends on deployment architecture, service permissions, network segmentation, and downstream connections.
Recommended Actions
- Apply the SAP August Security Patch Day fix to COM_CLOUD 2211 and 2211-JDK21 deployments
- Restrict network access to the Data Hub Adapter and review use of the default authentication client
- Map what the Commerce Cloud service account can reach downstream - segmentation and service permissions set the blast radius
Vulnerability Profile
Vendor: SAP
CVSS: 10.0
Component: Data Hub Adapter extension
Affected: COM_CLOUD 2211, 2211-JDK21
Access: Unauthenticated, low complexity
Fix: August Security Patch Day
Sources
Primary reporting behind this week's briefing.
- · Microsoft Security Update Guide - CVE-2026-62911, CVE-2026-64914, CVE-2026-70329
- · SOCRadar Threat Research Unit - PivotC2 and CVE-2025-25249 exploitation research
- · Fortinet PSIRT - CVE-2025-25249
- · SAP August Security Patch Day - CVE-2026-58231
Protect your environment
Vaughn Thomas
Compliance Engineer & Threat Researcher, SOClogix
Technical review: William Johnson, VP of Security Operations
Vaughn Thomas
Compliance Engineer
SOClogix Cyber Group
200+
Threat groups tracked
50+
Intel feeds monitored
52×
Reports per year
Get Weekly Briefings Free
This Week at a Glance
Get Vaughn's Briefing Every Week
Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.
Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.