# Today's Top Stories
August 16, 2026
-
1Ars Technica Security general Aug 14Vulnerability giving attackers full control of Macs is under active exploitation
A critical macOS vulnerability in the screen-sharing subsystem is under active exploitation, allowing remote attackers to log in without a password and gain full control of affected Macs. Security practitioners should prioritize patching immediately, as unauthenticated remote access represents a severe risk to enterprise macOS deployments. No CVE details were provided in the summary, but the active exploitation status makes this an urgent priority.
-
2BleepingComputer general Aug 14Shell investigates 'potential incident' after Clop data theft claims
The Clop ransomware gang has claimed responsibility for stealing 89GB of data from oil giant Shell, which has confirmed it is investigating a 'potential security incident.' Clop has a well-documented history of large-scale data theft campaigns exploiting file transfer software vulnerabilities, making this consistent with the group's established TTPs. Security teams at energy sector organizations should review exposure to Clop's known initial access vectors.
-
3SecurityWeek general Aug 141.6 Million Likely Impacted by RingCentral Data Breach
A data breach at RingCentral has likely impacted approximately 1.6 million individuals, with stolen data including names, addresses, email addresses, and phone numbers published by the threat actors. The scale of this breach makes it significant for enterprise security teams whose organizations use RingCentral's UCaaS platform. Affected users face elevated phishing and social engineering risk given the breadth of PII exposed.
-
4SecurityWeek general Aug 14Over 1,000 Charities Hit by Beacon CRM Data Breach
A compromised AWS access key — exposed in publicly available JavaScript build artifacts — led to a data breach at Beacon CRM that impacted over 1,000 charities. This incident illustrates a common secrets-management failure where credentials are inadvertently embedded in client-side build outputs and indexed by public repositories or CDNs. Security teams should audit JavaScript bundles and CI/CD artifacts for exposed cloud credentials.
-
5The Record threat-intel Aug 14France investigates tax authority breach after hacker claims 600,000 victims
French authorities confirmed unauthorized access to systems at the Directorate General of Public Finances (DGFiP) in late June 2026, after a hacker claimed to have stolen data on 600,000 victims using stolen or misused identity credentials. The breach of a national tax authority represents a high-impact government sector incident with significant implications for citizen data privacy across France. The investigation is ongoing.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6WeLiveSecurity (ESET) threat-intel Aug 13Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Presented at Black Hat USA 2026, research examining the Hugging Face hack — involving OpenAI models performing autonomous offensive actions — argues that AI-driven attacks increase rather than decrease the need for human oversight in security operations. The incident demonstrates that AI agents can execute multi-step intrusions with reduced human involvement, creating new accountability gaps. This is directly relevant to security architects designing AI-integrated pipelines and access controls.
-
7SecurityWeek general Aug 14AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
AmnesiaStealer is a newly documented Rust-based macOS infostealer capable of harvesting passwords, macOS Keychain data, Chromium-based browser credentials, and Safari cookies, while also controlling browser sessions. Its use of Rust suggests deliberate evasion of traditional signature-based detection tuned for Objective-C or Swift macOS malware. macOS endpoint defenders should update detection rules to cover Rust-compiled binaries targeting browser and Keychain data stores.
-
8SecurityWeek general Aug 14Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud has published a post-quantum cryptography (PQC) migration roadmap targeting full readiness by 2029, with key milestones in 2027 and 2028. This roadmap is relevant to enterprise architects planning long-term cryptographic agility, particularly those with data subject to 'harvest now, decrypt later' threat models. Organizations using Google Cloud services should align their own PQC transition timelines with these milestones.
-
9BleepingComputer general Aug 15New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet dubbed Evooo1Bot is actively targeting internet-facing gateway devices and converting compromised routers into SOCKS5 traffic relay nodes. The use of SOCKS5 proxying is a classic technique for obfuscating C2 traffic and enabling follow-on attacker operations through victim infrastructure. Network defenders should audit exposed gateway devices for signs of compromise and restrict unnecessary outbound SOCKS traffic.
-
10SecurityWeek general Aug 1414,000 Trezor Customers Impacted by Data Breach at ShipMonk
Shipping data for approximately 14,000 Trezor hardware wallet customers was stolen in a breach at third-party logistics provider ShipMonk, exposing names, addresses, email addresses, and phone numbers. While no cryptographic keys or wallet credentials were compromised, Trezor customers are now at elevated risk of targeted phishing and physical theft attempts given the combination of their identity as cryptocurrency hardware wallet owners and their physical addresses being exposed.