Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 14:49 14/08/2026 UTC
Last updated: 13:34 14/08/2026 UTC

Latest updates

Browse →

Apple macOS security update for CVE-2026-65400

Security Patch Release

Updated: 14.08.2026 17:59 · First: 14.08.2026 17:59 · 📰 1 src / 1 articles · H score: 46

Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases, closing a Screen Sharing authentication bypass that could let network attackers connect without valid credentials. The update reduces exposure on systems that expose TCP port 5900 and is especially urgent because the flaw is being actively abused in the wild. Administrators should install the patched macOS versions and disable Screen Sharing if it is not needed.

MacOS Screen Sharing authentication bypass actively exploited (CVE-2026-65400)

Vulnerability

Updated: 14.08.2026 17:59 · First: 14.08.2026 17:59 · 📰 1 src / 1 articles · H score: 41

CVE-2026-65400 in macOS Screen Sharing is being actively exploited on systems with TCP port 5900 exposed to the internet, allowing network attackers to bypass authentication and reach the desktop without credentials. Reported intrusions escalated to root access and Monero mining on exposed systems. Apple fixed the flaw on August 6 and released patched macOS versions, while defenders are being urged to update or disable Screen Sharing if it is not needed.

ExfilSquad leak of 13 victim archives

Data Leak

Updated: 14.08.2026 17:49 · First: 14.08.2026 17:49 · 📰 1 src / 1 articles · H score: 62

ExfilSquad published victim data from 13 organizations on August 7, turning claimed exfiltration into a public leak and increasing privacy and extortion risk. The released archive was reported at 382.64 GB and 27 million records, with one DCPS set including 60,000 records. Leaked material included student names, dates of birth, and unique student identifiers, creating direct exposure for affected individuals. Review of public samples tied the leak to Microsoft D365 CRM and ERP access through misconfigured Power Page portals with public read access.

SAP Commerce Cloud improper authorization RCE (CVE-2026-58231)

Vulnerability

Updated: 14.08.2026 16:45 · First: 14.08.2026 16:45 · 📰 1 src / 1 articles · H score: 49

SAP Commerce Cloud CVE-2026-58231 is being targeted three days after patching, exposing affected deployments to unauthenticated arbitrary code execution. The flaw sits in the core Data Hub Adapter extension and can be abused through low-complexity attacks. SAP has not yet flagged it as actively exploited, but defenders lack a public PoC and are already seeing attack attempts in the wild.

Evooo1Bot modular Linux botnet activity

Malware Activity

Updated: 14.08.2026 16:00 · First: 14.08.2026 16:00 · 📰 1 src / 1 articles · H score: 31

Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is Mirai-derived and adds encrypted C2, a 28-command remote administration interface, an SSH brute-force scanner, and a reverse SOCKS relay. Analysis linked the activity to multiple exploited CVEs and a shared loader URL at 91.92.40[.]118/wget.sh. The combination of exploitation and proxying raises the risk of stealthier follow-on access through compromised infrastructure.

Evooo1Bot multi-CVE exploitation wave

Exploitation Wave

Updated: 14.08.2026 16:00 · First: 14.08.2026 16:00 · 📰 1 src / 1 articles · H score: 1

Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions. The activity broadens the risk to exposed edge devices by tying one loader infrastructure to many CVE hits.

DecryptAds launches adtech disclosure-file correlation service for tracking visibility

Security Tool/Service

Updated: 14.08.2026 14:24 · First: 14.08.2026 14:24 · 📰 1 src / 1 articles · H score: 15

The launch of DecryptAds adds a free way to correlate ads.txt, app-ads.txt, buyers.json and sellers.json, improving visibility into who can track users across websites and apps. The service turns fragmented adtech disclosures into a searchable map of ad partners, data brokers and reseller relationships. That strengthens investigations into malvertising, geo-risk ad networks and other supply-chain risks in the ad ecosystem.

RingCentral ShinyHunters data leak

Data Leak

Updated: 14.08.2026 13:52 · First: 14.08.2026 13:52 · 📰 1 src / 1 articles · H score: 57

The ShinyHunters group published a 280GB archive of stolen RingCentral data on a dark web leak site after a ransom demand was refused, turning a July 2026 breach into a public exposure event. The leaked material tied to 1.6 million accounts included names, email addresses, phone numbers, and physical addresses. RingCentral said its core platform was not disrupted, but the leak increased the risk of follow-on misuse of customer data.

RingCentral hit by network compromise

Incident

Updated: 14.08.2026 13:52 · First: 14.08.2026 13:52 · 📰 1 src / 1 articles · H score: 57

RingCentral disclosed a breach that exposed personal information for 1.6 million accounts after a sophisticated social engineering campaign compromised its systems. ShinyHunters later claimed the intrusion, said it stole 623GB of data, and leaked 280GB after a ransom demand went unpaid. RingCentral said its core platform was not disrupted and that only a limited portion of customers was affected.

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity

Updated: 14.08.2026 13:45 · First: 14.08.2026 13:45 · 📰 1 src / 1 articles · H score: 29

The AmnesiaStealer macOS infostealer is being spread through ClickFix social engineering, putting infected Macs at risk of credential theft, browser data theft, and live-session hijacking. The malware uses a counterfeit GitHub download lure and a self-deleting script to install itself while hiding activity from users. It then launches a remote-controlled second stage that can drive Chromium-family browsers and steal cookies in plaintext through the DevTools protocol.

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign

Updated: 14.08.2026 13:45 · First: 14.08.2026 13:45 · 📰 1 src / 1 articles · H score: 34

A ClickFix distribution campaign is pushing AmnesiaStealer onto mac users, increasing the risk of credential theft and browser-session hijacking. The lure uses a counterfeit GitHub download page and copy-paste social engineering to get victims to run a malicious command. Once installed, the payload stages data theft and can give operators hidden control over browser sessions.

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta

Updated: 14.08.2026 10:30 · First: 14.08.2026 10:30 · 📰 1 src / 1 articles · H score: 60

Researchers linked Jewelbug to a single hack-for-hire model, showing that espionage and crypto fraud now share one control panel and shared infrastructure. The cluster's dual-use setup broadens the threat from state-aligned spying to a monetized ecosystem that can harvest access while pursuing profit. The operation is also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049. Its reach spans governments and militaries in the Middle East, Southeast Asia and South Asia.

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign

Updated: 14.08.2026 10:30 · First: 14.08.2026 10:30 · 📰 1 src / 1 articles · H score: 45

The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, broadening the group's activity beyond espionage. The same operators also used decoy documents themed around Taiwanese government organizations, suggesting an additional interest in Taiwan. Shared infrastructure tied the fraud activity to the group's espionage operations, indicating one team was managing both tracks.

NCA charges five London suspects in Russian Coms case

Law Enforcement

Updated: 14.07.2026 11:21 · First: 14.07.2026 11:21 · 📰 1 src / 1 articles · H score: 22

The NCA charged five London suspects in the Russian Coms fraud case, advancing a cybercrime prosecution tied to millions of scam calls. The suspects face allegations including supplying articles for fraud and handling criminal property. They are scheduled to appear at Westminster Magistrates’ Court on August 14 2026.

Ukraine takedown of 94 fraudulent call centers

Law Enforcement

Updated: 14.08.2026 00:12 · First: 14.08.2026 00:12 · 📰 1 src / 1 articles · H score: 23

Authorities in Ukraine carried out a takedown of 94 fraudulent call centers this week, disrupting a fraud network that used investment scams and bank impersonation to steal money and account access. Police also conducted 411 searches with help from the National Police, the Security Service of Ukraine, the Prosecutor General’s Office, and German police. The operation exposed a broader fraud infrastructure that used remote-access tools and targeted victims in the EU.

15 Government tenants hit by network compromise

Incident

Updated: 13.08.2026 21:15 · First: 13.08.2026 21:15 · 📰 1 src / 1 articles · H score: 45

The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity across login pages and mailbox views. The intrusion exposed browser cookies and enabled selective targeting of government accounts. The compromise was tied to Jewelbug operations running against a country in the Middle East. The event increased the risk of account abuse, follow-on email collection, and broader ministry compromise.

Jewelbug multi-region government webmail espionage campaign

Campaign

Updated: 13.08.2026 21:15 · First: 13.08.2026 21:15 · 📰 1 src / 1 articles · H score: 55

The Jewelbug campaign compromised 15 government webmail tenants and expanded a multi-region espionage effort against state targets in the Middle East, Southeast Asia, and South Asia. The operation used a shared webmail compromise and malicious script injection to reach login pages and mailbox views, then exfiltrated cookies to an operator C2 server. The same infrastructure also supported parallel cryptocurrency fraud, increasing the scale and operational continuity of the actor’s activity.

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta

Updated: 13.08.2026 21:15 · First: 13.08.2026 21:15 · 📰 1 src / 1 articles · H score: 60

Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-targeting intrusions with monetized fraud infrastructure.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave

Updated: 12.08.2026 12:01 · First: 12.08.2026 12:01 · 📰 3 src / 3 articles · H score: 46

Broadcom VMware vCenter is facing an active exploitation wave tied to CVE-2026-59310, putting exposed servers at risk of arbitrary code execution and persistence. The wave has reached 361 unique victim IP addresses across 47 countries, with attackers using path traversal followed by a malicious cron job and reverse_ssh to hold access. Activity began on August 3, shortly after disclosure, indicating rapid post-patch abuse of vulnerable appliances.

ShipMonk hit by network compromise

Incident

Updated: 13.08.2026 18:13 · First: 13.08.2026 18:13 · 📰 1 src / 1 articles · H score: 43

ShipMonk suffered unauthorized access to systems containing customer data, creating a compromise event that exposed information tied to Trezor orders. The provider breach affected order data for nearly 14,000 customers and raised the risk of follow-on phishing and impersonation attempts. Trezor said its own systems were not compromised, but the third-party incident exposed sensitive customer contact and shipping details.

Trezor customers customer data exposed after ShipMonk breach

Data Leak

Updated: 13.08.2026 18:13 · First: 13.08.2026 18:13 · 📰 1 src / 1 articles · H score: 44

A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impersonation. The exposed information included names, shipping addresses, email addresses, phone numbers, and some city data. Trezor systems were not compromised, but affected customers now face heightened fraud exposure.

Google Cloud ships quantum-safe key exchange and publishes post-quantum migration roadmap

Security Tool/Service

Updated: 13.08.2026 18:00 · First: 13.08.2026 18:00 · 📰 1 src / 1 articles · H score: 11

Google Cloud has begun rolling out quantum-safe key exchange and a staged post-quantum migration roadmap, expanding cryptographic protections for cloud services ahead of the 2027-2028 transition window. The update covers Google Cloud API endpoints, application and proxy load balancers, and Cloud KMS, making the platform’s security capabilities ready for post-quantum handshakes and key management. The rollout matters because it reduces exposure to store-now-decrypt-later risk while giving customers a path to validate hybrid deployments without breaking existing applications. Additional services, including Cloud VPN, Interconnect, Private CA, Cloud IAM, and a quantum-safe Cloud HSM, are scheduled to follow.

Adobe Commerce and Magento incorrect authorization flaw (CVE-2026-71362, exploitation attempts detected)

Vulnerability

Updated: 12.08.2026 23:54 · First: 12.08.2026 23:54 · 📰 2 src / 2 articles · H score: 40

CVE-2026-71362 exploitation attempts against Adobe Commerce and Magento are now being blocked, creating customer-account hijack and private-data exposure risk for affected storefronts. The flaw is an incorrect authorization issue that can let an attacker switch one customer session to another account without authentication. Sansec Shield WAF is already stopping observed abuse attempts while administrators are being urged to patch.

White House NSPM creates NCC cyber-operations program

Public Sector Action

Updated: 13.08.2026 16:30 · First: 13.08.2026 16:30 · 📰 1 src / 1 articles · H score: 31

The White House memo now directs the National Coordination Center (NCC) to create a vetting program for private security companies to conduct limited cyber operations against foreign cybercrime organizations. The framework puts the activity under U.S. government control with compliance review for constitutional, legal, and international-agreement requirements. It is intended to disrupt ransomware, phishing, financial fraud, sextortion, and impersonation scams.

National Security Presidential Memorandum (NSPM) authorized federal law enforcement agencies to collaborate with private firms on offensive cyber strikes for signed August 12

Public Sector Action

Updated: 13.08.2026 15:35 · First: 13.08.2026 15:35 · 📰 1 src / 1 articles · H score: 31

The White House authorized federal law enforcement agencies to work with private firms on offensive cyber strikes against foreign threat actors targeting the US, creating a new government-overseen framework for limited cyber operations. The National Security Presidential Memorandum (NSPM), signed on August 12, formalizes the program and places oversight with the Homeland Security Task Force’s National Coordination Center (NCC). The move expands public-private coordination against transnational cybercrime groups and aims to disrupt attacks affecting US businesses and individuals.

WhatsApp rolls out optional Scam Alert on-device scam warning feature

Security Tool/Service

Updated: 13.08.2026 14:50 · First: 13.08.2026 14:50 · 📰 1 src / 1 articles · H score: 11

WhatsApp has begun rolling out Scam Alert, a new optional security feature that warns users about potential scam messages, raising protection for over 3 billion users. The control runs on-device machine learning and keeps message content on the phone, which reduces privacy exposure while adding scam detection.

ICO reprimand of ACRO for GDPR breach

Regulatory/Legal Action

Updated: 13.08.2026 11:30 · First: 13.08.2026 11:30 · 📰 1 src / 1 articles · H score: 31

The ICO issued a reprimand to ACRO over GDPR infringement tied to a 2023 data breach that affected over 10,000 people. The breach involved unauthorized access to ACRO’s website and content management system (CMS) between August 2022 and March 2023. The exposure included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence information. The reprimand centers on poor patch management and insufficient security monitoring.

Criminal Records Office (ACRO) hit by data theft breach

Incident

Updated: 13.08.2026 11:30 · First: 13.08.2026 11:30 · 📰 1 src / 1 articles · H score: 37

The Criminal Records Office (ACRO) suffered an unauthorized-access breach that exposed sensitive records for 10,920 victims and put criminal-record data at risk. The intrusion ran from August 2022 to March 2023 and affected ACRO’s website and content management system (CMS). Exposed information included National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence data. The breach created lasting privacy and identity-theft risk even though full exfiltration could not be confirmed.

WindRelay and SpyNote RAT Android NFC relay fraud activity

Malware Activity

Updated: 13.08.2026 01:22 · First: 13.08.2026 01:22 · 📰 1 src / 1 articles · H score: 33

The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses a bank-impersonation call, a sideloaded fake app, and Accessibility Service abuse to gain device control before the attacker installs WindRelay and relays NFC card data. Samples seen between November 2025 and July 2026 indicate a sustained malware set, and targeting appears focused on Czechia, Slovakia, and Slovenia.

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign

Updated: 12.08.2026 16:35 · First: 12.08.2026 16:35 · 📰 3 src / 3 articles · H score: 22

Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and LinkedIn recruiter impersonation, then delivered Troy and a FudModule variant that incorporated CVE-2026-68820 and abuse of compromised Roundcube infrastructure. Microsoft patched CVE-2026-68820 in the August 2026 Patch Tuesday and marked it actively exploited. Check Point also reported RelayShell use on at least 17 servers and described additional delivery paths through MISTPEN, DLL sideloading, and a trojanized PDF viewer.