Week 33 belonged to anything left facing the internet. VMware vCenter servers and GeoServer installs were picked off within days of their flaws becoming public - in GeoServer's case, within hours - and Macs with Screen Sharing switched on were quietly turned into crypto miners. The gap between disclosure and exploitation is no longer measured in weeks.
For anyone not running a server, the more relevant news was in the Chrome Web Store, where researchers found 737 VPN extensions routing entire browser sessions through proxies controlled by a single operator. More than half were still installable when the research went out.
This is our first weekly roundup, covering Monday 10 to Sunday 16 August. The format: what genuinely needs your attention, then the week's biggest stories whether or not you're personally exposed - each with an honest line on who actually is - then things worth knowing without doing anything about.
What to act on#
737 Chrome VPN extensions were routing your traffic through someone else's proxy#
Researchers found 737 VPN extensions across 40+ Chrome Web Store developer accounts sending the user's entire browser session through SOCKS5 proxies run by a single provider. That put the operator in the middle of everything: destinations visited, source IP, TLS SNI values, and the full body of anything sent over plain HTTP.
274 of them impersonated 66 real VPN brands - Proton VPN, NordVPN, Surfshark, ExpressVPN, CyberGhost, TunnelBear, Cloudflare's 1.1.1.1, Google's Outline. Total installs were around 75,000, which is modest, but the deception was deliberate: fake premium tiers, policy-evasion tricks, and internal Russian-language instructions left in the code.
221 have been pulled. 516 were still live on the Chrome Web Store.
What to do: open chrome://extensions and remove any VPN extension you did not deliberately install from the vendor's own website. A browser extension that proxies your traffic has a better view of your browsing than your ISP does. If you want a VPN, install the vendor's actual application - and if privacy is the goal rather than geo-shifting, our ranked guide to private browsers is a better starting point than any extension.
Windows: 398 fixes, and one kernel flaw already being used#
Microsoft's August update covers 398 CVEs, 62 of them critical. The one that matters is CVE-2026-68820, a privilege-escalation flaw in afd.sys, the kernel-side Windows networking driver. Microsoft confirms active exploitation, and Check Point attributes it to Lazarus as part of Operation Dream Job - the same activity reported separately two days later as a standalone Lazarus zero-day. It is one story, not two.
Being honest about the risk: this is an escalation bug, so an attacker needs code execution on the machine first. It turns a foothold into SYSTEM rather than creating the foothold. The bigger deal for most people is elsewhere in the same batch - four unauthenticated remote code execution flaws rated 9.8, in Windows DNS Server, Windows Deployment Services, Microsoft QUIC and HPC Pack.
What to do: install the August updates. On a home machine that is Settings, Windows Update, and a reboot you have probably been postponing.
Macs with Screen Sharing exposed are being mined#
CVE-2026-65400 (CVSS 9.8) is an authentication bypass in the built-in macOS remote desktop service. The Dutch NCSC found active abuse across multiple systems with port 5900 reachable from the internet - in every case the attacker got root and installed a Monero miner.
Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
What to do: update. If you cannot right now, turn the service off at General, Sharing, Screen Sharing. This is also a decent argument for watching what leaves your machine, not just what arrives - see our guide to outbound firewalling on macOS, since a crypto miner announces itself in outbound traffic long before you notice the fans.
Nobody legitimate will ask you to tap your bank card against your phone#
WindRelay is Android malware currently aimed at Czechia, Slovakia and Slovenia, and it is worth knowing because the mechanics are so plausible. Victims are called or messaged, walked into sideloading an app personalised with their own name, and then told to hold their payment card to the back of the phone to "verify identity" or "change the PIN". The phone becomes a live NFC relay: the card data is streamed in real time to a fraudster elsewhere, who spends it.
It arrives by sideload after a phishing, smishing or vishing call - never through the Play Store - and it leans on Accessibility Service permissions to do its work quietly.
What to do: treat any instruction to tap your card against your phone as fraud, without exception. The same rule that defeats most smishing applies here: the request itself is the tell. Keep sideloading off unless you have a specific reason, as covered in our Android hardening guide.
The week's biggest#
Three new passkey attacks, and none of them broke the cryptography#
The most-discussed research of the week was three separate attacks on passkey implementations. SpecterOps reused YubiKey signatures left in Windows event logs to impersonate privileged Entra ID users. Unit 42 pulled a 32-byte secret out of Chrome's memory and recovered synced private keys from Google Password Manager. Dirk-jan Mollema generated fresh WebAuthn assertions from Windows Hello for Business without triggering a new PIN or biometric check.
The framing matters more than the findings. None cracked the math. Every one of them starts from a machine or session the attacker already controls - malware running on the endpoint, or an authenticated Windows session. That is a meaningfully different threat model from phishing, which is the thing passkeys exist to defeat and still do.
What it does puncture is the shorthand that "phishing-resistant" means "safe". It doesn't; it means the login is hard to steal remotely. Once malware is resident on the device, the surrounding plumbing - logs, browser memory, session state - becomes the target instead. Our guidance on passkeys and MFA stands unchanged: they remain the best available option, and this research is an argument for keeping the endpoint clean, not for going back to passwords.
Who's exposed: primarily Windows and Entra ID environments, and only after an attacker is already on the machine. Nothing observed outside test environments. Patch CVE-2026-34348 with the August Windows updates and you have handled the part that is yours.
VMware vCenter: 361 victims across 47 countries#
CVE-2026-59310, a directory-traversal flaw in vCenter Server rated 9.8, allows remote code execution. Broadcom patched it in late July. Compromised systems first called home on 3 August, five days after public disclosure, and researchers logged 361 unique victim IPs across 47 countries, concentrated in Germany, the US, Turkey, Iran and France. Persistence came via a cron job running reverse_ssh.
The correlation between disclosure and exploitation is the lesson: publication of the advisory was, in effect, the campaign's start signal.
Who's exposed: organisations running self-managed VMware virtualisation. Not you personally, and not your data unless a company holding it runs vCenter and skipped a three-week-old patch.
GeoServer was attacked within hours of disclosure#
A critical SQL injection in GeoServer's PostGIS handling (GHSA-mqjf-5f49-2fjh, CVSS 9.8) leads to remote code execution. Patches landed on 14 August, and exploitation attempts began within hours - hundreds of them, from a small pool of addresses. Fixed in 35.1, 34.5 and 33.6.
The point isn't GeoServer specifically. It's that "we'll patch it next maintenance window" is now a strategy with a measurable failure rate.
Who's exposed: anyone self-hosting GeoServer, which mostly means government mapping agencies, universities and GIS shops. If you have never heard of it, you don't run it.
A poisoned AI package went unnoticed for five months#
LiteLLM, an open-source gateway connecting applications to multiple AI model providers, had two malicious versions - 1.82.7 and 1.82.8 - live on PyPI on 24 March 2026 for roughly 40 minutes. The attackers got in using an API token exposed through the compromised Trivy dependency, part of the wider TeamPCP campaign.
Those packages harvested environment variables, SSH keys, cloud credentials, Kubernetes tokens, database passwords and model API keys, encrypted them, and shipped them to an attacker-controlled domain. CloudSEK maps potential exposure to more than 2,500 organisations - captured loot, not confirmed victims.
It surfaced publicly on 12 August. A 40-minute window in March, disclosed in August: that gap is the story. Anyone who installed during it has had stolen credentials in circulation for five months.
Who's exposed: teams building on LiteLLM. If that's you, check for installs in the 10:39-16:00 UTC window on 24 March and rotate every secret those systems could reach. This is the shape of risk covered in our post on what actually breaks company security - the breach rarely arrives through your own code.
Adobe shipped three 10.0s, and one is now being exploited#
Adobe's August release covered seven critical flaws across ColdFusion, Commerce and Campaign Classic, three of them scored 10.0. None showed exploitation at release. That has since changed for CVE-2026-71362 in Adobe Commerce - the platform behind a great many online shops.
Who's exposed: businesses running Magento/Adobe Commerce storefronts. As a shopper you can't act on it, but it's a reasonable thing to ask a vendor holding your card details.
Week 33's critical CVEs#
| Identifier | Product | Exploited? | Patch |
|---|---|---|---|
| CVE-2026-68820 | Windows afd.sys |
Yes, by Lazarus | Yes, 11 Aug |
| CVE-2026-65400 | macOS Screen Sharing | Yes, miners deployed | Yes |
| CVE-2026-59310 | VMware vCenter | Yes, 361 victims | Yes, late Jul |
| GHSA-mqjf-5f49-2fjh | GeoServer | Yes, within hours | Yes, 14 Aug |
| CVE-2026-71362 | Adobe Commerce | Yes, after release | Yes |
| CVE-2026-34348 | Windows Hello / WebAuthn | Research only | Yes, 11 Aug |
| CVE-2026-58231 | SAP Commerce Cloud | Probing only | Yes |
One note on that table, because the distinction matters and headlines tend to flatten it. The SAP Commerce Cloud flaw is scored 10.0 and was widely reported as being attacked, but what actually happened is that scanning hit a honeypot three days after the patch shipped. There is no public proof-of-concept and no confirmed compromise. Someone rattling the handle is not the same as someone getting in.
Worth knowing about#
The US authorised private companies to hack back. A signed presidential memo directs the National Coordination Center to stand up a programme within 60 days letting vetted US firms run surveillance and disruption operations against foreign criminal organisations - accessing systems without the owner's authorisation, and degrading or destroying them. US law currently prohibits exactly this without court authorisation. State-sponsored actors are excluded unless proven otherwise, and firms must stop and notify if an operation strays onto US persons or systems. Attribution in this field is frequently wrong, so "we thought it was a criminal group" is a failure mode with real consequences.
Someone spent $7 million buying expired domains. Infoblox tracked an operator it calls Sable Squirrel acquiring over 10,000 domains since June 2023, recycling them into illegal sports streaming, gambling promotion, malware command-and-control and scam infrastructure. The value is inherited reputation: old bookmarks, stale links and cached search results keep sending real people to an address that changed hands. Roughly 65,000 dropcatch domains are re-registered globally every day.
Stolen sessions keep beating stolen passwords. SpecterOps published a technique that switches on the Chrome DevTools Protocol inside an already-running browser to reach cookies and live authenticated sessions. It needs code execution on the machine first and exploits no Chrome vulnerability - Google doesn't classify it as one - but it sidesteps Device Bound Session Credentials by working through the authenticated browser rather than replaying cookies elsewhere. The same week brought AmnesiaStealer doing something similar on macOS. Nothing to patch; it's a reminder that phishing-resistant authentication protects the login, not the session that follows it - the same theme as the passkey research above.
Apple notified users in 110 countries of mercenary spyware targeting. This is a periodic round of Apple's threat notifications, running since late 2021 and now covering more than 150 countries cumulatively. Apple named no vendor and attributed nothing. Targets are the usual profile - journalists, activists, politicians, diplomats. If you received one, Apple's guidance is Lockdown Mode, current software, and Stolen Device Protection. If you didn't, this isn't about you.
Summary#
- Remove any VPN extension you didn't install from the vendor's own site. 516 of the 737 were still available at the time of writing.
- Install the August Windows updates. One kernel flaw is being actively used, four unauthenticated 9.8 RCEs shipped alongside it, and the passkey fix is in the same batch.
- Update macOS, or switch off Screen Sharing. Exposed machines are being mined right now.
- Never tap a payment card against a phone because someone asked you to. That request is fraud, every time.
- Three things worth remembering: the gap between disclosure and exploitation is now measured in hours, a supply-chain compromise can sit undiscovered for five months while stolen credentials stay valid, and "phishing-resistant" describes the login, not everything that happens after it.
Most of Week 33's headline severity - vCenter, GeoServer, ColdFusion - lands on infrastructure most readers do not run. That is normal, and worth saying plainly rather than dressing up as everyone's emergency. The parts that reach you are duller and more effective: a fake extension, a delayed reboot, a phone call asking you to tap your card.
Not sure whether any of this week's flaws touch your stack? Get in touch - the bluwarden team can map what you actually run against what's actually being exploited.
This roundup is general information, not a substitute for a vulnerability assessment of your own environment. Severity and exploitation status change quickly; check vendor advisories for the current position before acting on anything here.
