CISO Talk by James Azar
CyberHub Podcast
SAP Commerce Cloud Under Attack, GeoServer Zero-Day Exploited Within Hours & Microsoft Power Pages Misconfiguration Exposes Millions of Records
0:00
-19:30

SAP Commerce Cloud Under Attack, GeoServer Zero-Day Exploited Within Hours & Microsoft Power Pages Misconfiguration Exposes Millions of Records

Attackers are reverse-engineering enterprise patches in days, probing zero-days within hours and finding millions of records sitting behind misconfigured cloud permissions

☕ Good Morning Security Gang

After a weekend to catch our breath, I’ve got ten stories proving the attackers didn’t take Saturday and Sunday off. We’re starting the week with two maximum-concern vulnerability situations: a perfect CVSS 10.0 vulnerability in SAP Commerce Cloud already being probed only three days after SAP released its patch, and an unpatched GeoServer vulnerability that attackers began probing within hours of public disclosure.

But vulnerabilities aren’t the only issue today. An attacker is auctioning employee-directory information allegedly stolen from nine major enterprises, with the data potentially providing an organizational roadmap for future social engineering. A Microsoft Power Pages configuration problem exposed millions of records across government and private-sector organizations—including Microsoft itself and the City of Atlanta. RingCentral’s breach has now resulted in data associated with roughly 1.6 million unique email addresses appearing publicly. We also have a correction to last week’s LiteLLM supply-chain story, a major DDoS campaign, a $7 million malicious advertising operation built around expired domains, and another major investment into AI-native cybersecurity startups.

Before we get into all of it, a quick thank you. Over the weekend, the CyberHub Podcast passed 90,000 YouTube subscribers 🎆. Every one of you who watches, listens, shares the show and sends feedback has helped us reach that milestone.

I also learned Friday that I’m a finalist for the GeorgiaCISO ORBIE Awards, selected from 175 submissions and 30 finalists. I’m competing in the Enterprise category alongside some exceptional security leaders, and I’m grateful to Sean Kramer for the nomination and to everyone who has supported me and the show.

Now, back to cybersecurity. Double espresso in hand. Coffee Cup Cheers, Security Gang.

🧭 Today’s Cybersecurity Picture

There is one word connecting nearly every story today: speed.

The vulnerability lifecycle we built our traditional security programs around is disappearing. SAP issued a patch, and attackers were probing for vulnerable systems three days later without public exploit code being available. A GeoServer vulnerability was publicly disclosed, and researchers began seeing attack traffic within hours. Stolen enterprise information is being packaged and auctioned while some potential victims may still be determining how credentials were compromised.

Meanwhile, several of today’s biggest incidents weren’t caused by sophisticated exploitation at all. Microsoft’s Power Pages story comes down to cloud permissions. The employee-directory theft appears connected to stolen identities and credentials. That’s important because while attackers are becoming faster, many of the controls capable of stopping them remain remarkably familiar: patching, identity security, least privilege, configuration management and visibility.

The fundamentals haven’t changed. The amount of time we have to execute them has.

📰 Today’s Top Stories

“A perfect 10 unauthenticated RCE is exactly the scenario your change-control process needs an emergency lane for.” James Azar

🚨 SAP Commerce Cloud CVSS 10.0 Vulnerability Already Under Attack

SAP Commerce Cloud, the enterprise e-commerce platform supporting large digital storefronts and supply-chain operations, has a maximum-severity vulnerability tracked as CVE-2026-58231 with a perfect CVSS score of 10.0. The vulnerability allows unauthenticated remote code execution, meaning an attacker doesn’t need credentials or user interaction to execute arbitrary code against a vulnerable server.

SAP released its fix on August 12. Only three days later, honeypot sensors operated by threat-intelligence researchers began detecting exploitation attempts against exposed application endpoints over HTTPS.

Here’s what makes the timeline particularly important: according to the episode source, there was no public proof-of-concept exploit available when that scanning began. Someone appears to have taken SAP’s patch, compared it with the vulnerable software, determined what SAP changed and developed enough understanding to begin probing the internet for vulnerable systems—all within approximately 72 hours.

“A perfect CVSS 10 patched and under attack in 72 hours with zero public exploit code, think about what that actually means.” James Azar

Current activity appears to be automated mass scanning rather than confirmed successful compromise, with attack traffic traced to hosting infrastructure in the United States. But waiting for confirmed victims before responding would completely misunderstand what the telemetry is telling us.

If your organization operates SAP Commerce Cloud, get the official update deployed across every affected instance. Review web server and WAF telemetry for suspicious POST requests against administrative services. And if immediate patching genuinely isn’t possible, restrict access aggressively while you move toward remediation.

SAP environments can be notoriously difficult to patch because years of customization create legitimate concerns about breaking business functionality. I understand that operational reality.

But a CVSS 10.0 unauthenticated RCE affecting infrastructure connected to commerce and payment workflows is exactly why emergency change procedures exist.

🧠 Why the SAP Timeline Matters

Think about what three days actually means.

Somebody appears to have taken SAP’s patch, reverse-engineered the changes, understood enough about the underlying vulnerability to begin developing attack traffic and started probing internet-facing systems before many enterprises could complete their normal change-control process.

That’s the vulnerability-management problem in 2026.

We can no longer build critical-vulnerability processes entirely around fixed seven-, 14- or 30-day SLAs. Severity matters, but exploitability, exposure and business consequence have to override the calendar.

If your organization doesn’t have an emergency path capable of getting a vulnerability like this from disclosure to production remediation in hours rather than weeks, build one.

The next vulnerability isn’t going to wait for your Tuesday change window.

🌎 GeoServer Zero-Day Probed Within Hours — And There Is No Patch

If the SAP situation is difficult, GeoServer may be worse because defenders currently don’t have a patch to deploy.

GeoServer is an open-source platform widely used to publish and process geospatial information across government, agriculture, telecommunications and transportation environments. Researchers publicly disclosed an SQL injection vulnerability affecting GeoServer’s JSON array filtering functionality when paired with certain PostGIS or Oracle JDBC data stores. Improper sanitization of user-controlled input can, under affected configurations, create a pathway toward remote code execution.

According to the episode, attack-surface researchers began detecting probing within hours of public disclosure, eventually observing hundreds of attempts originating from a relatively small number of source addresses.

At this stage, the reported activity represents probing rather than confirmed follow-on compromise. That’s an important distinction. But GeoServer has a history of vulnerabilities moving rapidly into real-world exploitation, with previous flaws already represented in CISA’s Known Exploited Vulnerabilities catalog.

And because there isn’t currently a vendor patch, defenders have to shift from remediation toward containment.

Inventory every GeoServer deployment. Determine which instances are internet accessible. Restrict external connectivity wherever the business permits it. Evaluate which data stores and functionality are exposed. Increase monitoring around affected services and prepare your team to deploy the vendor fix as soon as it becomes available.

When there’s no patch, architecture becomes your patch.

🪪 Employee Directories From Nine Major Enterprises Appear on the Dark Web

A dark-web seller operating under the name TheHatMan is auctioning internal employee-directory information allegedly extracted from Azure and Entra environments belonging to at least nine major companies.

According to researchers reviewing samples, McDonald’s represents the largest alleged dataset with more than 1.7 million records, followed by Tata Consultancy Services at roughly 800,000, Vodafone at approximately 425,000 and HCL Technologies at around 250,000. Other organizations named include InterContinental Hotels Group, Kyndryl, Gap, Hexaware and Wyndham.

Researchers described the samples as credible based on the structure of the data and alignment between corporate domains and typical Azure directory exports. The datasets allegedly contain more than employee names. They include corporate email addresses, employee IDs, job titles, departments, manager relationships, service accounts and—in some instances—information identifying global administrators.

That last part is where this becomes much more than a privacy issue.

Give an attacker employee names, organizational reporting relationships, departments, executive assistants, administrators and privileged accounts, and you’ve effectively given them a social-engineering targeting map.

The precise initial-access mechanism remains unconfirmed. However, researchers found evidence suggesting infostealer malware may have played a significant role, identifying compromised credentials associated with infections on systems belonging to employees at several of the organizations. One compromised system reportedly contained dozens of corporate credentials and hundreds of session cookies.

If you’re operating Microsoft Entra, this should reinforce the importance of phishing-resistant MFA, session controls, endpoint detection for infostealers and continuous monitoring for corporate credentials appearing in criminal ecosystems.

The perimeter isn’t where identity gets compromised anymore.

Sometimes it happens inside an employee’s browser session.

☁️ Power Pages Misconfiguration Exposes Millions of Records Including Microsoft’s Own Data

Our fourth major story involves an attacker known as Exfil Squad, whose claims regarding data obtained from approximately 15 organizations have now reportedly been corroborated by independent researchers.

And the root cause wasn’t a zero-day.

It wasn’t ransomware.

It wasn’t malware.

It was configuration.

The issue involves Microsoft Power Pages, the SaaS platform organizations use to create public-facing business websites connected to Microsoft Dynamics 365. Improperly configured portal permissions allowed unauthorized access to information contained in connected Dynamics environments, effectively leaving CRM data publicly accessible to anyone who knew where to look.

The scale is significant. According to the episode, the City of Atlanta had approximately 36GB representing roughly three million records exposed. Allstate allegedly had around 15GB involving approximately 657,000 records. The UK’s Department for Education had approximately 600,000 records exposed, while Frontier Airlines reportedly had 43GB covering around 2.4 million records.

And then there’s Microsoft. Microsoft’s own exposure reportedly totaled approximately 130GB and eight million records.

This is bigger than any individual victim because Power Pages sits on top of Dynamics 365 across countless enterprise and government environments. A seemingly small error involving guest access, table permissions or web roles can unintentionally turn backend CRM information into publicly readable internet content.

If your organization operates Power Pages connected to Dynamics 365, audit it now. Don’t wait for an extortion group to perform your cloud configuration review for you.

Leave a comment

⚡ Quick Hits

🇫🇷 French Tax Authority Investigates Data Breach

France’s tax authority confirmed that an attacker used a stolen or misused identity to access its systems in late June. A group calling itself Zero Bytes claims information involving more than 600,000 individuals was obtained, potentially including names, tax identifiers, email addresses and family and tax-status information.

The agency is notifying affected individuals, has filed a criminal complaint and has involved France’s data protection authority. The attackers’ complete claims had not been independently verified at the time of the episode.

The key detail here is the access method: once again, we’re talking about identity compromise, not some exotic malware chain.

☎️ RingCentral Data Dump Includes Roughly 1.6 Million Unique Email Addresses

The ShinyHunters extortion group published approximately 280GB of information following the July breach involving business communications provider RingCentral after the company reportedly declined to pay.

Have I Been Pwned has since confirmed approximately 1.6 million unique email addresses within the leaked dataset, along with information including names, addresses and phone numbers. RingCentral says the incident affected only a limited portion of its overall customer base and that affected customers have been notified.

This matters because communications platforms sit at the center of enormous amounts of corporate metadata. Even where credentials aren’t exposed, names, contact information and organizational relationships can become valuable inputs for targeted phishing and impersonation.

🔄 Important Correction: The LiteLLM Supply-Chain Incident

I also want to correct part of last week’s coverage of the LiteLLM supply-chain incident.

Updated research indicates that more than 95% of approximately 2,200 identifiable affected organizations were exposed through the upstream Trivy compromise, rather than solely through the roughly 40-minute period when malicious LiteLLM packages were publicly available.

That changes the timeline materially.

If your team scoped its investigation only around the LiteLLM package-publication window, widen that review back to March 19, when the underlying data collection associated with the Trivy compromise reportedly began.

We ran the earlier information based on research available at the time, but when the facts change, we correct the record.

That’s how this should work.

📵 Encrypted Messaging Platform Threema Hit by Major DDoS Campaign

Swiss encrypted-messaging provider Threema experienced large-scale, shifting-pattern distributed denial-of-service attacks that intermittently disrupted the service for much of two days.

The attack also affected its colocation provider, while organizations operating Threema’s on-premises infrastructure remained unaffected. The company has since implemented specialized upstream DDoS filtering designed to mitigate similar attacks in the future.

There’s an architectural lesson here as well: decentralization and customer-hosted infrastructure can sometimes create resilience benefits that go beyond privacy.

💰 $7 Million Expired-Domain Operation Becomes Malware Infrastructure

Researchers tracking a threat actor known as Sable Squirrel uncovered an operation that has spent nearly $7 million acquiring expired domains, inheriting their traffic, reputation and historical trust.

The actor uses those domains to operate a Vietnam-based sports-piracy and gambling ecosystem while simultaneously supporting malware command-and-control infrastructure associated with tools including Quasar RAT and AsyncRAT.

The security implication is important. A domain’s historical reputation doesn’t tell you who owns it today.

Security controls that rely heavily on domain age or reputation need context around ownership changes, DNS behavior and newly observed infrastructure. A ten-year-old domain can become malicious overnight if the registration changes hands.

💵 Team8 Raises Another $365 Million for Technology and AI Security

Finally, venture firm Team8 raised another $365 million, pushing total assets under management to approximately $2 billion since its founding.

A significant portion of the new capital is expected to support AI-native security companies. Team8’s previous cybersecurity portfolio includes companies such as Talon, Dig Security and Cider Security, while recent investments highlighted in the episode include several emerging AI and security startups.

Why does this matter to practitioners?

Because capital allocation tells us where technology markets believe tomorrow’s problems will emerge.

AI security is moving from an experimental product category toward a significant part of the cybersecurity ecosystem. Some companies will succeed. Plenty won’t.

Our job as practitioners is to separate actual capability from the inevitable mountain of AI marketing we’re about to receive.

🧠 James Azar’s CISOs Take

Today’s stories reinforce something I’ve been talking about repeatedly: our security processes have to operate closer to business speed because attackers already do. Three days from an SAP patch to active probing isn’t enough time for a traditional enterprise vulnerability workflow that spends days assessing ownership before somebody even submits the change request. Hours between a GeoServer disclosure and scanning isn’t enough time for a weekly vulnerability meeting. That doesn’t mean we abandon governance or recklessly push updates into production. It means our governance needs an emergency lane. Security, infrastructure, application owners and business leaders should already know what happens when a critical internet-facing platform suddenly becomes exploitable. If you’re figuring that process out during the vulnerability, you’re already behind.

The second lesson today is that some of our largest exposures still don’t require sophisticated exploitation at all. Power Pages exposed millions of records because permissions were wrong. Employee directories appear to have been harvested through compromised identities and infostealers. A French government system was reportedly accessed through a stolen or misused identity. We can talk about AI-powered attacks and zero-days all day long, but identity, configuration, least privilege and asset visibility continue determining whether attackers succeed. The technology is moving faster, but the fundamentals haven’t become obsolete. They’ve become more urgent.

🛠️ Action Items

  • Emergency-patch SAP Commerce Cloud across internet-facing and affected internal instances rather than waiting for the next normal maintenance window.

  • Review SAP web-server and WAF telemetry for suspicious POST requests and anomalous access against administrative services.

  • Inventory every GeoServer deployment immediately and determine which instances use potentially affected PostGIS or Oracle configurations.

  • Restrict internet access to GeoServer wherever operationally possible until a vendor fix becomes available.

  • Prepare an expedited GeoServer deployment plan now so the eventual patch can move immediately when released.

  • Audit Entra ID for infostealer-related credential exposure, suspicious sessions and abnormal directory enumeration.

  • Strengthen phishing-resistant MFA and session controls for privileged and directory-access accounts.

  • Review service accounts and global administrators for unnecessary privileges and excessive directory visibility.

  • Audit Microsoft Power Pages table permissions, web roles and guest access across every Dynamics 365-connected portal.

  • Test public-facing Power Pages anonymously to verify backend CRM information cannot be retrieved without authorization.

  • Review exposure associated with RingCentral and prepare employees for targeted phishing using leaked contact information.

  • Expand LiteLLM/Trivy investigations back to March 19 rather than limiting reviews to the malicious-package publication window.

  • Review domain-reputation controls to identify trusted domains that have recently changed ownership.

  • Validate DDoS protections and upstream-provider escalation procedures for externally critical communications platforms.

  • Build or test an emergency vulnerability-management lane capable of moving a critical exposed system from disclosure to production remediation within hours when threat intelligence justifies it.

🔥 Stay Cyber Safe.

Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar

Ready for more?