August 14, 2026 by sig9
Hacker Wars - August 14, 2026
Your daily dose of infosec chaos
Zero-day season rolls on, with GeoServer and VMware vCenter both getting chewed on in the wild. macOS picks up a shiny Rust infostealer, a stray AWS key in a JavaScript bundle burns over a thousand charities, and Akira figured out that a reboot into Safe Mode makes EDR quietly disappear. Busy day. Let’s dig in.
Hackers Hammer Unpatched GeoServer Zero-Day
Attackers are actively exploiting an unpatched SQL injection flaw in GeoServer that can be escalated to full remote code execution. Geospatial servers are the overlooked corner of many networks, and right now that corner is on fire.
What to do: Patch GeoServer now or yank it off the internet until you can, and comb logs for SQL injection patterns.
Global Campaign Targets Critical VMware vCenter Flaw
A widespread campaign is exploiting CVE-2026-59310 in vCenter, and researchers warn patching alone may not evict intruders who already slipped in. Your hypervisor is the crown jewel, and attackers know it.
What to do: Patch vCenter and hunt for post-compromise persistence, not just the vulnerable version.
AmnesiaStealer Brings Rust-Powered Theft To macOS
A new Rust-based infostealer is hoovering passwords, Keychain data, Chromium profiles, and Safari cookies, and can even hijack active browser sessions. The “Macs don’t get malware” crowd continues to have a rough decade.
What to do: Treat macOS as a real attack surface with EDR, hardened browser configs, and zero tolerance for sketchy downloads.
Leaked AWS Key In JavaScript Bundle Breaches 1,000-Plus Charities
Beacon CRM shipped an AWS access key inside publicly available JavaScript build artifacts, exposing data belonging to more than a thousand charities. Anything compiled into your frontend is public by definition, including your secrets.
What to do: Scan build artifacts and bundles for credentials, and swap long-lived cloud keys for short-lived ones.
Akira Silences EDR With A Safe Mode Reboot
An Akira affiliate disabled endpoint defenses by rebooting a compromised host into Safe Mode with Networking, then exfiltrated data before fumbling the encryption. EDR that vanishes on a reboot is just expensive decoration.
What to do: Enable tamper protection that survives Safe Mode boots and alert on unexpected reboot patterns.
That’s the chaos for today. Stay sharp out there.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.