# Archive

Browse past daily curated stories

Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14

Saturday, August 15, 2026

  1. 1
    0
    BleepingComputer general
    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    Attackers are actively exploiting a macOS Screen Sharing authentication bypass vulnerability to deploy Monero cryptocurrency miners, with the Netherlands' NCSC issuing an active exploitation warning after public exploit code emerged. The flaw allows remote unauthenticated login via the Screen Sharing service, giving attackers full control of affected Macs. Security teams running macOS systems with Screen Sharing enabled should patch immediately and audit for unauthorized remote access or cryptomining processes.

  2. 2
    0
    Dark Reading general
    Global Threat Campaign Hits Critical VMware vCenter Flaw

    CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, is under active global exploitation with attackers achieving remote code execution against unpatched servers. Exploitation began earlier in August 2026, and researchers warn that patching alone may not fully mitigate the threat if attackers have already established persistence. vCenter administrators should treat this as an emergency patching priority and audit for indicators of compromise beyond applying the available fix.

  3. 3
    0
    BleepingComputer general
    Max severity SAP Commerce Cloud flaw now targeted in attacks

    A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...]

  4. 4
    0
    Ars Technica Security general
    Private security firms will soon be allowed to hack overseas cybercriminals

    A Trump administration memo has, for the first time in U.S. history, authorized private cybersecurity firms to conduct offensive cyber operations against foreign criminal organizations. Contracts may require a $1 million performance bond forfeited for non-compliance, and experts describe this as a significant philosophical and legal shift in U.S. cyber policy. The move raises unresolved questions about liability, attribution errors, and the risk of escalation when private actors conduct state-sanctioned attacks.

  5. 5
    0
    SecurityWeek general
    Hackers Exploiting Unpatched GeoServer Zero-Day

    An unpatched zero-day SQL injection vulnerability in GeoServer is being actively exploited in the wild, with attackers leveraging it to achieve remote code execution against affected deployments. GeoServer is widely used in government and enterprise geospatial infrastructure, making this a high-impact target. No patch is available, so defenders should implement network-level controls and WAF rules to limit exposure while awaiting an upstream fix.

  6. 6
    0
    BleepingComputer general
    Hackers arrested over €30M bank fraud exploiting service provider flaw

    Seven cybercriminals — four arrested in Brazil and three charged in Europe — are accused of exploiting a vulnerability at an unnamed financial service provider to siphon funds from Commerzbank customer accounts, totaling over €30 million in fraud. Germany's BKA and Brazil's federal police coordinated the investigation and arrests. The attack vector via a third-party service provider highlights ongoing supply chain risk in the banking sector.

  7. 7
    0
    BleepingComputer general
    RingCentral data breach exposed info of 1.6 million accounts

    ShinyHunters breached RingCentral in July 2026, stealing personal information — including names, addresses, email addresses, and phone numbers — from approximately 1.6 million accounts, with exposure confirmed via Have I Been Pwned. The stolen dataset has been published by the threat actors. RingCentral users should be alerted to elevated phishing and social engineering risk given the breadth of contact data now in attacker hands.

  8. 8
    0
    SecurityWeek general
    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    A re-investigation of the widely reported compromise affecting 2,500 organizations initially blamed on malicious LiteLLM packages has revealed that Trivy, the open-source container scanning tool, was the actual root cause, with over 95% of affected companies exposed before the malicious LiteLLM packages were even published. The finding is significant for security teams who may have scoped their incident response around the wrong tool. Organizations using Trivy in their CI/CD pipelines should review their exposure and audit for compromise artifacts.

  9. 9
    0
    SecurityWeek general
    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Fortinet patched authentication bypass vulnerabilities in both FortiWeb and FortiManager that could allow attackers to log in with arbitrary credentials or impersonate any FortiGate appliance on the network. These flaws represent a critical risk given the privileged position FortiManager and FortiWeb hold in enterprise network architectures. Fortinet customers should apply the latest patches immediately and review access logs for anomalous authentication attempts.

  10. 10
    0
    SecurityWeek general
    Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    CVE-2026-59310, a directory traversal flaw in VMware vCenter enabling unauthenticated remote code execution, has drawn global attacker attention with confirmed exploitation campaigns beginning in early August 2026. The vulnerability's position in virtualization management infrastructure makes it a high-value target for ransomware operators and nation-state actors alike. VMware administrators should prioritize patching and check for signs of lateral movement originating from vCenter hosts.