# Today's Top Stories
August 15, 2026
-
1BleepingComputer general Aug 14Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability to deploy Monero cryptocurrency miners, with the Netherlands' NCSC issuing an active exploitation warning after public exploit code emerged. The flaw allows remote unauthenticated login via the Screen Sharing service, giving attackers full control of affected Macs. Security teams running macOS systems with Screen Sharing enabled should patch immediately and audit for unauthorized remote access or cryptomining processes.
-
2Dark Reading general Aug 13Global Threat Campaign Hits Critical VMware vCenter Flaw
CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, is under active global exploitation with attackers achieving remote code execution against unpatched servers. Exploitation began earlier in August 2026, and researchers warn that patching alone may not fully mitigate the threat if attackers have already established persistence. vCenter administrators should treat this as an emergency patching priority and audit for indicators of compromise beyond applying the available fix.
-
3BleepingComputer general Aug 14Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]
-
4Ars Technica Security general Aug 13Private security firms will soon be allowed to hack overseas cybercriminals
A Trump administration memo has, for the first time in U.S. history, authorized private cybersecurity firms to conduct offensive cyber operations against foreign criminal organizations. Contracts may require a $1 million performance bond forfeited for non-compliance, and experts describe this as a significant philosophical and legal shift in U.S. cyber policy. The move raises unresolved questions about liability, attribution errors, and the risk of escalation when private actors conduct state-sanctioned attacks.
-
5SecurityWeek general Aug 14Hackers Exploiting Unpatched GeoServer Zero-Day
An unpatched zero-day SQL injection vulnerability in GeoServer is being actively exploited in the wild, with attackers leveraging it to achieve remote code execution against affected deployments. GeoServer is widely used in government and enterprise geospatial infrastructure, making this a high-impact target. No patch is available, so defenders should implement network-level controls and WAF rules to limit exposure while awaiting an upstream fix.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6BleepingComputer general Aug 14Hackers arrested over €30M bank fraud exploiting service provider flaw
Seven cybercriminals — four arrested in Brazil and three charged in Europe — are accused of exploiting a vulnerability at an unnamed financial service provider to siphon funds from Commerzbank customer accounts, totaling over €30 million in fraud. Germany's BKA and Brazil's federal police coordinated the investigation and arrests. The attack vector via a third-party service provider highlights ongoing supply chain risk in the banking sector.
-
7BleepingComputer general Aug 14RingCentral data breach exposed info of 1.6 million accounts
ShinyHunters breached RingCentral in July 2026, stealing personal information — including names, addresses, email addresses, and phone numbers — from approximately 1.6 million accounts, with exposure confirmed via Have I Been Pwned. The stolen dataset has been published by the threat actors. RingCentral users should be alerted to elevated phishing and social engineering risk given the breadth of contact data now in attacker hands.
-
8SecurityWeek general Aug 14Trivy, Not LiteLLM Behind the 2,500 Org Compromise
A re-investigation of the widely reported compromise affecting 2,500 organizations initially blamed on malicious LiteLLM packages has revealed that Trivy, the open-source container scanning tool, was the actual root cause, with over 95% of affected companies exposed before the malicious LiteLLM packages were even published. The finding is significant for security teams who may have scoped their incident response around the wrong tool. Organizations using Trivy in their CI/CD pipelines should review their exposure and audit for compromise artifacts.
-
9SecurityWeek general Aug 13Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet patched authentication bypass vulnerabilities in both FortiWeb and FortiManager that could allow attackers to log in with arbitrary credentials or impersonate any FortiGate appliance on the network. These flaws represent a critical risk given the privileged position FortiManager and FortiWeb hold in enterprise network architectures. Fortinet customers should apply the latest patches immediately and review access logs for anomalous authentication attempts.
-
10SecurityWeek general Aug 13Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
CVE-2026-59310, a directory traversal flaw in VMware vCenter enabling unauthenticated remote code execution, has drawn global attacker attention with confirmed exploitation campaigns beginning in early August 2026. The vulnerability's position in virtualization management infrastructure makes it a high-value target for ransomware operators and nation-state actors alike. VMware administrators should prioritize patching and check for signs of lateral movement originating from vCenter hosts.