
Active Exploitation of Patched Vulnerabilities and Supply Chain Attack Highlighted in SANS StormCast
The August 17, 2026, SANS Internet Storm Center StormCast highlighted active exploitation of two recently patched vulnerabilities: an Apple screen-sharing flaw (exploited per the Dutch information security agency) and an unauthenticated SQL injection in GeoServer, which requires a non-default configuration. A remote code execution vulnerability in SAP Commerce Cloud, patched on Patch Tuesday, was also targeted within days, though exploitation details remain undisclosed. Additionally, a supply chain attack worm named Chaindrop compromised 444 packages by embedding malicious code in Visual Studio Code and Cursor IDE configuration files, bypassing traditional NPM post-install scripts to steal NPM and GitHub credentials. The worm’s activation method relied on IDE trust prompts triggered when opening project directories. Patches for the Apple and SAP vulnerabilities were released prior to exploitation, while GeoServer’s fix lacked a CVE number at the time. The video noted that screen-sharing services should not be exposed to public networks.