SAP's CVSS 10.0 flaw drew attacks three days after the fix
Attackers hit SAP Commerce Cloud three days after its patch with no public exploit code, and Clop was inside PTC Windchill weeks before that fix shipped.
SAP shipped a patch for CVE-2026-58231, a CVSS 10.0 flaw in Commerce Cloud that lets an unauthenticated attacker abuse a default authentication client to reach code execution. Defused Cyber recorded the first attempts against its honeypots three days later, and no public proof of concept was in circulation (Security Affairs). Nobody had published exploit code. The patch was the exploit code.
A fix for a remote flaw is also a map to it
A patch for a remotely reachable bug carries its own instructions. The diff shows which call path was wrong and roughly how to walk it, which is the trade every vendor makes when it ships a fix, and it is normally worth making: the defender starts with a head start measured in the time it takes an attacker to read a changelog. Three days is what that head start was worth here, in an enterprise commerce product where the same window has to cover a change request, a maintenance slot and a regression test.
The other timeline runs the other way
Clop's 43-victim data theft campaign traces to CVE-2026-12569 in PTC Windchill and FlexPLM, a CVSS 9.8 deserialisation flaw the gang used as a zero-day from early June, weeks before PTC patched it on 17 June. Shell said on 14 August that it is investigating a potential incident, and Philips confirmed a compromise of one enterprise server (Tech Times). For every one of those victims the fix arrived after the theft, and nearly two months after the patch the names are still coming out.
Put the two incidents together and the patch stops being the pivot in either story. Before it, there was nothing to apply. Three days after it, there was traffic. Neither case has a phase in which patching promptly was the whole defence, which is an uncomfortable thing to say about the one control that actually gets measured.
The largest number today involved no software flaw
RingCentral had 1.6 million accounts verified as exposed by Have I Been Pwned, each record carrying a full name, phone number, email address and physical address. ShinyHunters voice-phished a single employee in July, then published a 280GB archive on 3 August when the company declined to pay (Tech Times). No CVE, no severity score, no patch to apply late. A phone call.
What the three have in common is not the way in. Two of them turned on a vendor's code running inside the victim and one turned on a vendor's employee. What they share is the state of the data waiting on the other side: records in readable form, in bulk, sitting in systems built to serve them up quickly.
One release today works on that half
Google open-sourced HEIR, a compiler toolchain that converts pre-trained models to run on homomorphically encrypted inputs without decrypting them, shipping four worked demonstrations including a deep learning recommendation model and a credit card fraud detector, built with the accelerator firms Belfort, Niobium, Cornami and Optalysys (Google).
Be precise about what that is. It lets a model compute on data it never sees in the clear, which is a much narrower claim than a customer database nobody can read. It would not have stopped the phone call. The fraud detector is a demonstration, one of four, and the release publishes no deployment behind any of them. But it is the only item in today's record that changes what an intruder walks out with rather than how fast a hole closes. Every other defence above is a race against a clock the attacker starts.
The patch cycle is not going to stop being the job. It is worth being honest that in both of today's exploited flaws, the timing beat it: once by weeks, on the vendor's side, and once by three days, on the customer's.
What the ledger holds
The day-by-day feed behind this note is in the ledger. Every figure above links to the source it came from. Nothing here is estimated.
Built from the digest of 2026-08-16.