Daily Podcast full article
SAP Commerce Cloud CVSS 10 and Lazarus IT-worker tactics put enterprises on alert
SAP’s August security release exposed a maximum-severity Commerce Cloud flaw that can lead to unauthenticated code execution, while fresh Lazarus-linked research shows North Korean operators trying to become trusted insiders rather than merely break in.

A patch cycle with board-level implications
Enterprise security teams have two very different alarms to handle this week. One is a classic emergency: SAP has shipped fixes for a CVSS 10.0 vulnerability in SAP Commerce Cloud’s Data Hub Adapter. The other is more human and slower moving: new research into the Lazarus-linked Famous Chollima ecosystem shows suspected DPRK IT workers pursuing trusted developer access inside a fake DeFi company. Together, they capture the widening shape of enterprise risk: exposed business software on one side, identity and hiring compromise on the other.
SAP’s August 2026 Patch Day bulletin says the company released 28 new security notes and one GitHub security advisory on August 11, with two updates to earlier notes. The top item is SAP Security Note 3771065 for CVE-2026-58231, described by SAP as “Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)” affecting COM_CLOUD 2211 and 2211-JDK21, with a critical rating and CVSS 10.0 score.
Why the SAP flaw is so urgent
The severity is not just a number. The Hacker News reported on August 12 that CVE-2026-58231 can allow an unauthenticated attacker to abuse a default authentication client and submit crafted input to functions that lack sufficient validation, potentially resulting in arbitrary code execution and compromise of internal components.
That combination is dangerous in a commerce environment. SAP Commerce Cloud systems often sit close to payment flows, customer profiles, pricing logic, stock data, order management, loyalty systems and third-party marketing tools. A pre-authentication path to code execution can put defenders at a disadvantage because the attacker may act before normal login controls, fraud checks or user-behavior analytics have a chance to work.
Onapsis’ August 11 analysis, updated August 12, said SAP Security Note 3771065 addresses insufficient authorization checks and input validation, and that successful exploitation could compromise internal components with high impact on confidentiality, integrity and availability. Onapsis also said customers should patch to fixed Commerce Cloud release levels and rebuild or redeploy the updated Commerce Cloud version; as a temporary reduction of exposure, it pointed to configuring an IP Filter Set to restrict access to the vulnerable endpoint.
For security leaders, that “rebuild/redeploy” detail matters. In many organizations, the bottleneck will not be downloading a fix; it will be identifying affected Commerce Cloud deployments, confirming which environments are public-facing, coordinating change windows with e-commerce teams, testing extensions and custom integrations, and verifying that the corrected application is actually running in production.
SAP’s wider August risk picture
CVE-2026-58231 was not alone. SAP’s bulletin listed other critical August items, including CVE-2026-44772, a code injection vulnerability in SAP Manufacturing Integration and Intelligence with a CVSS 9.9 score; CVE-2026-34265, a memory corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform with CVSS 9.8; and CVE-2026-44758, another SAP Manufacturing Integration and Intelligence code injection flaw rated CVSS 9.1.
Onapsis described the August patch set as “very busy,” counting 33 new and updated SAP Security Notes, including five HotNews Notes and nine High Priority Notes. Its analysis singled out SAP Commerce customers and SAP MII customers for special attention, and said Onapsis Research Labs supported SAP in patching multiple SAP MII vulnerabilities.
The practical takeaway is that SAP remediation should not be treated as a one-ticket exercise. Organizations should triage CVE-2026-58231 first, but they should also review whether SAP MII, NetWeaver ABAP, BusinessObjects, SAP Business AI Platform Approuter, Search and Navigation, and related Commerce Cloud components appear in their estate. A critical commerce bug may draw the headlines, but attackers often chain lower-profile issues with exposed services, weak segmentation or stale credentials.
Lazarus shows a different route inside
While SAP administrators rush patches, a separate August 10 ANY.RUN report documented a very different intrusion model. Researchers said they created a fake DeFi startup and hired suspected Famous Chollima operatives, giving them a controlled view of a DPRK IT-worker operation after “hiring.” The report says the operators’ value is not only malware delivery, but legitimate access to code, systems, intellectual property and trusted business processes.
ANY.RUN’s article describes Famous Chollima as a Lazarus-umbrella division seeking remote roles in industries rich in money and intelligence, including cryptocurrency, finance and healthcare, with more recent expansion into pharmaceuticals, civil engineering and architecture. The described tradecraft includes forged identities, fake résumés, proxy interviews, remote facilitators and “ghost developers.”
This is what makes the Lazarus alarm strategically important. The threat is not a single malicious attachment or a one-time wallet-draining lure. It is the possibility that a sanctioned state-linked operator becomes an employee, contractor or developer with routine access. Once trusted, such a person may not need to exploit a software vulnerability to review source code, influence pull requests, observe incident-response discussions, access cloud dashboards or understand how money moves.
Tools, weak signals and hiring controls
ANY.RUN said its controlled environments recorded activity such as system reconnaissance with dxdiag, systeminfo and wmic; use of Google Remote Desktop and AnyDesk; VPN infrastructure; cryptocurrency wallets; AI tools; and developer environments including Visual Studio Code and Remix. The report also listed observed tools and services including AstrillVPN, ChatGPT, Google Gemini, 2fa.cn, MetaMask, Bitget Wallet, ip8.com, Vultr and Gorilla Servers.
None of those signals is conclusive by itself. Developers use remote access tools, AI assistants and wallets for legitimate reasons. The defensive value lies in correlation: inconsistent identity documents, interview behavior that suggests proxying or live translation, unexplained remote-control setup on corporate machines, repeated VPN use from suspicious infrastructure, mismatched geography, and unusual access patterns during onboarding.
The common lesson: trust must be continuously verified
The SAP and Lazarus stories converge on one message: trust boundaries are shifting. SAP Commerce Cloud may carry the word “cloud,” but customers still need asset visibility, patch discipline and deployment verification. A developer may pass interviews and produce code, but employers still need identity assurance, periodic verification and behavioral monitoring that respects privacy while protecting sensitive systems.
For SAP teams, the priority is immediate: identify affected COM_CLOUD 2211 and 2211-JDK21 deployments, apply SAP’s fixed release, rebuild and redeploy, restrict vulnerable endpoint exposure where patching cannot be completed immediately, and review logs for suspicious pre-authentication activity. For security operations, create detections around unusual Commerce Cloud endpoint access, unexpected child processes, outbound connections from commerce nodes and changes to integrations.
For hiring and engineering leaders, the Lazarus lesson is to harden onboarding. Verify identity before granting production access, separate interview performance from access approval, require managed devices, limit personal remote-access tools, monitor impossible travel and VPN anomalies, and review code privileges during the first weeks of employment. In high-risk sectors such as crypto, fintech, defense suppliers and healthcare, insider-risk controls now belong in the same conversation as endpoint detection and vulnerability management.
This week’s cyber alarms are not identical. One is a maximum-severity software flaw with a clear patch path. The other is an intelligence-led warning about adversaries blending into normal remote work. But both punish delay. In 2026, the attacker may arrive through an unauthenticated endpoint — or through HR.
Sources from the last 72 hours
- [1]SAP Security Patch Day - August 2026Aug 11, 2026, 12:00 AM UTC
- [2]SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary CodeAug 12, 2026, 12:00 AM UTC
- [3]SAP Security Notes: August 2026 Patch DayAug 11, 2026, 12:00 AM UTC
- [4]Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi StartupAug 10, 2026, 12:00 PM UTC
AI-generated article based on recent web research, then preserved as a dated editorial snapshot.

Comments
Be the first to comment.