
Weekly Axis Of Easy #464
Last Week’s Quote was: “It is change, continuing change, inevitable change, that is the dominant factor in society today. No sensible decision can be made any longer without taking into account not only the world as it is, but the world as it will be.” — was by Isaac Asimov. Jane got it right first. Congratulations.
This Week’s Quote: “Education is not merely neglected in many of our schools today, but is replaced to a great extent by ideological indoctrination.” By ???
THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.
This is your easyDNS #AxisOfEasy Briefing for the week of August 17th, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.
To Listen/watch this podcast edition with commentary and insight from Joey and Len the Lengend click here.
In this issue:
- Apple’s Spyware Pager Goes Off in 110 Countries
- A Nation-State Crew Rooted 361 vCenter Servers in 47 Countries — Patch Was Out Five Days
- Nine Fortune 500 Names, Millions of Records: The Azure Credential Dump Nobody’s Calling a Breach
- GeoServer’s Unpatched Zero-Day Is Getting Probed Right Now, and There’s No Fix Yet
- The March Supply-Chain Attack That Keeps Getting Bigger: LiteLLM’s 2,500-Company Hangover
Elsewhere Online:

easyHermes Is Here
We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform. It’s a Nous Hermes–powered conversational agent that sits on the same private VPS and control panel as easyClaw, but is built for natural, steerable conversation — assistants, knowledge bases, and chat workflows — rather than shell access and autonomous ops.
Now you can finally settle the “openClaw vs. Hermes” argument for yourself, or just run both and let them fight it out.
Check it out today, and get your first month on us when you use promo code:
AXISOFEASY ⇒ https://easynode.ai(opens in new tab)
Apple’s Spyware Pager Goes Off in 110 Countries
Apple confirmed to TechCrunch it sent a fresh round of mercenary-spyware threat notifications on August 13, reaching users in 110 countries — part of a running total the company now puts at over 150 countries notified since the program started in 2021. The alerts, now surfaced directly on the iPhone lock screen in addition to email, read plainly: a mercenary spyware attack was detected targeting the device. Apple won’t attribute the campaign to any vendor or government, though it has previously named NSO Group’s Pegasus as the archetype of the category, and it maintains it can never achieve absolute certainty — only high confidence.
This is the surveillance-industry equivalent of a smoke detector going off in 110 buildings at once, and Apple still won’t say who’s holding the lighter. Journalists, diplomats, activists and politicians remain the target profile, but the scale of this round is a reminder that mercenary spyware isn’t a niche threat model anymore — it’s a recurring, global, multi-vendor business. If you receive one of these notifications, take it at face value and get expert help; if you don’t, the operative word in “vast majority of users” is still majority, not all.
More via The Hacker News
GeoServer’s Unpatched Zero-Day Is Getting Probed Right Now, and There’s No Fix Yet
A researcher going by @q1uf3ng dropped an unauthenticated SQL-injection zero-day in GeoServer’s jsonArrayContains function on X on August 12, complete with a working path to remote code execution against admin-configured databases. WatchTowr says exploitation attempts started within hours — hundreds of probes from a small pool of IPs, currently reconnaissance rather than payload delivery, with the RondoDox botnet already in the mix. Shadowserver counts over 1,500 exposed instances worldwide. As of this writing there’s no CVE, no CVSS score, and no vendor patch.
GeoServer sits quietly underneath a lot of government, agriculture, telecom and transit infrastructure that nobody thinks about until it’s the reason a map doesn’t load — or the reason an attacker has a shell. No patch means your only lever right now is exposure reduction: get it off the public internet, restrict jsonArrayContains where you can, and watch your logs for the probing pattern, because “reconnaissance now” reliably turns into “exploitation later” once someone weaponizes the PoC properly.
More via The Hacker News
The March Supply-Chain Attack That Keeps Getting Bigger: LiteLLM’s 2,500-Company Hangover
Back in March, threat actor TeamPCP compromised Aqua Security’s Trivy scanner, which LiteLLM’s own CI pipeline auto-installed, which let attackers slip credential-stealing code into two LiteLLM package releases that sat live on PyPI for about 40 minutes before being pulled. New victim-mapping published this month by CloudSEK puts the real damage at over 2,500 organizations and roughly 430,000 exposed CI/CD pipelines — cloud keys, Git tokens, Kubernetes secrets and AI-provider API keys, scooped up across a supply chain most of those victims didn’t know they were part of.
LiteLLM is the plumbing that routes requests to over a hundred LLM providers, which means this wasn’t an attack on LiteLLM’s users so much as an attack on everyone downstream of everyone who ever ran it. Five months on, boards that closed the ticket after “we unpinned the bad version” are now finding out that credential rotation, not version pinning, was always the actual fix. If your CI/CD ever touched LiteLLM 1.82.7 or 1.82.8, or anything built on top of Trivy in that window, that’s your homework this week.
More via SecurityWeek
A Nation-State Crew Rooted 361 vCenter Servers in 47 Countries — Patch Was Out Five Days
Broadcom patched two critical VMware vCenter flaws on July 29 — a directory-traversal bug and an auth-bypass, both rated a maximum 9.8. Five days later, a suspected China-nexus actor was already inside. Researchers at German incident-response firm QUIRSO tracked the campaign from first contact on August 3 through August 9, by which point they’d counted 361 distinct victim IPs spread across 47 countries, with Germany, the US, Turkey, Iran and France taking the brunt of it. The attacker used a reverse SSH shell for persistence and, on at least one appliance, chained both flaws together to spin up a rogue admin account with no corresponding login from the legitimate one. Some infections have since been tied to Babuk-derived ransomware.
vCenter isn’t just another box on the network — it’s the console that owns every VM, every host, every snapshot in an organization’s virtual estate. Compromise it and you don’t have a foothold, you have the building. The five-day gap between “patch available” and “hundreds of servers owned” is the real story here, and it’s not an outlier anymore, it’s the baseline. If you’re running vCenter and it’s reachable from anywhere near the internet, assume compromise-until-proven-clean, not patch-and-move-on.
More via The Hacker News
Nine Fortune 500 Names, Millions of Records: The Azure Credential Dump Nobody’s Calling a Breach
A threat actor calling itself “TheHatman” has spent the past week flooding cybercrime forums with internal employee directories allegedly pulled straight from the Azure and Entra tenants of nine major companies: McDonald’s (1.7 million records, the largest haul), Tata Consultancy Services, Vodafone, HCL Technologies, IHG, Kyndryl, Gap, Hexaware and Wyndham. Hudson Rock says the data — names, roles, emails, phone numbers, workplace addresses — matches standard Azure directory export formats closely enough to look legitimate. TCS has told its stock exchange it’s found no credible evidence of a breach on its own systems.
Researchers are converging on compromised credentials and infostealer malware rather than an Azure platform vulnerability, which is almost worse news: it means this isn’t a patchable bug, it’s the modern reality that your perimeter is whatever your weakest employee’s browser has saved a password to. Nine unrelated global enterprises hit by the same actor via the same access pattern is a services-and-identity story, not a Microsoft story — audit your conditional access policies and rotate anything infostealer logs might have touched, because “no evidence of a breach” and “not compromised” are not the same sentence.
More via SecurityWeek
Also on AxisOfEasy this week:
Nothing new in Curated Posts since our last check — still nothing since May. We’re not going to pad this section with filler just to fill space; when something worth your time crosses our desk, it’ll be here.
Elsewhere Online:
Read: https://www.scworld.com/news/black-hat-2026-openai-reveals-agents-planned-collective-attacks-via-secret-message-board(opens in new tab)
Read: https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html(opens in new tab)
Read: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html(opens in new tab)
Read: https://www.theregister.com/security/2026/08/14/scottish-prosecutors-cast-eye-over-leaky-supplier-after-staff-data-exposed/5287479(opens in new tab)
Read: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/(opens in new tab)
Previously on #AxisOfEasy
If you missed the previous issues, they can be read online here:
- August 14, 2026: #AxisOfEasy 463: Facial Recognition Comes To The London Underground, Whether You Signed Up Or Not(opens in new tab)
- August 7, 2026: #AxisOfEasy 462: The npm Worm That Ate The JavaScript Supply Chain(opens in new tab)
- July 31, 2026: #AxisOfEasy 461: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode(opens in new tab)
- July 24, 2026: #AxisOfEasy 460: AI Agent Breaches Hugging Face Infrastructure In Unprecedented Security Incident(opens in new tab)
- July 17, 2026: #AxisOfEasy 459: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent To Being Protected(opens in new tab)

Thomas Sowell.