TL;DR
Microsoft SharePoint authentication bypass (CVE-2026-55040) now actively exploited following PoC release. SAP Commerce Cloud max-severity RCE already targeted in attacks three days post-patch. macOS Screen Sharing flaw under active exploitation for Monero mining deployment.
Executive Summary
- Microsoft SharePoint CVE-2026-55040 (CVSS 9.1 authentication bypass) is under active exploitation after public PoC release.
- SAP Commerce Cloud remote code execution vulnerability is being targeted in attacks within days of patching.
- macOS Screen Sharing authentication bypass is actively exploited to deploy Monero cryptocurrency miners.
- Massive malicious Chrome VPN extension campaign targeting Russian-speaking users identified; 737 extensions route traffic through attacker-controlled proxies.
- Lazarus Group attributed to Windows zero-day exploitation targeting defense and aerospace sectors in France, Germany, Brazil, and India; previously reported but escalation noted.
Top Threats Today
1. SharePoint Authentication Bypass Under Active Exploitation
Severity: HIGH Affected: Technology
Threat actors have begun exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the release of proof-of-concept code [1]. The vulnerability carries a CVSS score of 9.1 [1]. Active exploitation is now underway as attackers leverage the publicly available PoC [1].
Sources:[1] The Hacker News
Recommended Action
- Immediately apply Microsoft security updates addressing CVE-2026-55040 to all SharePoint installations
- Audit SharePoint access logs for suspicious authentication patterns or unexpected privilege escalation
- Implement network segmentation to limit lateral movement from compromised SharePoint instances
- Enable multi-factor authentication on SharePoint administrative accounts
2. SAP Commerce Cloud RCE Targeted Post-Patch
Severity: HIGH Affected: Technology
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched three days prior, is already being targeted in active attacks, according to threat intelligence company Defused [1]. The rapid shift from patch to exploitation indicates attackers are monitoring vendor advisories and developing attack tooling with minimal lag time [1].
Sources:[1] BleepingComputer
Recommended Action
- Verify SAP Commerce Cloud instances are running the latest patched version
- Monitor SAP logs for signs of RCE exploitation attempts (unusual process execution, file modifications)
- Restrict network access to SAP Commerce Cloud administrative interfaces
- Conduct post-exploitation forensics on any instances that received the patch late
3. macOS Screen Sharing Flaw Exploited for Cryptomining
Severity: HIGH Affected: Technology
The Netherlands' National Cyber Security Centre (NCSC) reports that a macOS authentication bypass vulnerability in Screen Sharing is under active exploitation after public exploit code became available [1]. Attackers are leveraging the flaw to deploy Monero cryptocurrency miners on compromised systems ⚠[1].
Sources:[1] BleepingComputer
Recommended Action
- Disable macOS Screen Sharing if not required; disable remote login services on all systems
- Patch macOS to the latest available version addressing the authentication bypass
- Monitor process execution for Monero miner signatures (xmrig, xmr-stak, other mining processes)
- Check for unusual network connections to known mining pools
4. 737 Malicious Chrome VPN Extensions Route User Traffic
Severity: HIGH Affected: Technology
A massive set of 737 free VPN and proxy extensions have been discovered on the Chrome Web Store, primarily targeting Russian-speaking users seeking access to blocked services [1]. These extensions intercept browser traffic and route it through attacker-controlled proxy infrastructure, exposing users to man-in-the-middle attacks, credential harvesting, and malware injection [1]. The extensions were published across at least 40 different Chrome Web Store developer accounts [1].
Sources:[1] The Hacker News
Recommended Action
- Audit all installed Chrome/Chromium extensions, particularly VPN and proxy tools
- Remove any VPN extensions not from official, trusted vendors (Cloudflare Warp, Mullvad, ProtonVPN)
- Educate users on risks of free VPN services and recommend reputable paid alternatives
- Deploy browser policies blocking installation of unapproved extensions in enterprise environments
- Monitor network traffic for unexpected proxy connections or TLS decryption indicators
5. OpenAI, Anthropic, Google API Flaw Exposes AI Reasoning and Secrets
Severity: HIGH Affected: Technology
A flaw in the way OpenAI, Anthropic, and Google handle encrypted reasoning between API calls allows researchers to recover internal reasoning, API keys, and passwords from session logs [1]. The weakness affects encrypted reasoning objects used by the providers' reasoning engines ⚠[1], potentially exposing sensitive data to attackers who gain access to API logs or session records [1].
Sources:[1] The Hacker News
Recommended Action
- Review API access logs for any unauthorized or suspicious queries
- Rotate all API keys and credentials that may have been exposed through affected services
- Implement API request signing and additional authentication layers beyond bearer tokens
- Limit API session retention and implement strict log encryption standards
Ongoing Threats
Lazarus Windows Zero-Day & Microsoft Patch Tuesday: The Lazarus Group exploitation of a Windows zero-day targeting defense and aerospace sectors, and Microsoft's patching of 398 security vulnerabilities, were featured in earlier coverage.
Today’s Action Checklist
- ☐ URGENT: Apply patches for CVE-2026-55040 (SharePoint) and verify deployment across all instances
- ☐ URGENT: Confirm SAP Commerce Cloud systems are running patched version; review recent logs for exploitation attempts
- ☐ HIGH: Audit Chrome extensions in use; remove any free VPN or proxy tools not from trusted vendors
- ☐ HIGH: Patch macOS systems to latest version and disable Screen Sharing where not operationally required
- ☐ HIGH: Rotate API keys and credentials for OpenAI, Anthropic, and Google Cloud integrations; audit session logs