A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The data extortion group known as ExfilSquad, which surfaced on July 26, has claimed responsibility for stealing data from 15 organizations. So far, they have publicly leaked information from 13 victims, indicating a significant impact on businesses in various sectors. ExfilSquad's tactics include threatening to release sensitive data unless a ransom is paid, which puts additional pressure on affected organizations to comply. This incident raises concerns about data security and the potential for reputational damage for the victims involved. Organizations must remain vigilant and consider strengthening their cybersecurity measures to prevent similar attacks in the future.
SCM feed for Latest
In July, the ShinyHunters group executed a data breach involving RingCentral, a communications platform. This breach was the result of a sophisticated social engineering campaign, indicating that attackers used manipulation techniques to gain unauthorized access to sensitive information. The extent of the data compromised has not been specified, but given RingCentral's role in facilitating business communications, this incident raises significant concerns about the security of user data and the potential for further exploitation. Companies using RingCentral should assess their security measures and ensure that employees are trained to recognize social engineering tactics. This breach serves as a stark reminder of the vulnerabilities that can arise from human error in cybersecurity.
As the energy sector increasingly adopts AI technologies, concerns are growing about the associated cybersecurity and supply chain risks. These advancements, while promising for efficiency and innovation, expose critical infrastructure to potential cyberattacks. For instance, AI systems can be vulnerable to manipulation, which could lead to disruptions in energy services or even safety hazards. Companies operating in this space need to be vigilant and bolster their cybersecurity measures to protect against these emerging threats. The implications are significant, as a successful attack could affect not just energy providers, but also the wider economy and public safety.
SCM feed for Latest
The White House is expanding the role of private companies in offensive cyber operations, a move that raises governance and oversight concerns. Under this new initiative, private sector entities may be involved in cyber attacks against foreign adversaries. While the intention is to bolster national security and counter cyber threats, critics worry about the lack of regulation and the potential for abuse. This shift could lead to a scenario where private firms, rather than government entities, decide how and when to engage in hacking operations. The implications of this policy could affect international relations and the overall cybersecurity landscape in the U.S.
The Hacker News
Hackers are increasingly buying expired domains to take advantage of their existing traffic and credibility to misdirect users toward scams and malware. According to Infoblox, a firm that specializes in DNS threat intelligence, these domains—known as dropcatch domains—can be quickly registered after they expire. In the first half of 2026 alone, cybercriminals purchased over 50,400 of these domains, allowing them to exploit unsuspecting users. This practice poses significant risks as it can lead to increased phishing attacks and the spread of malicious software. Users and businesses need to be aware of these tactics to protect themselves from falling victim to these scams.
Four hackers were arrested in Brazil, and three others face charges in Europe for orchestrating a bank fraud scheme that exploited a vulnerability in a service provider. The attackers managed to withdraw over €30 million from the accounts of customers at Commerzbank. This breach underscores the risks associated with third-party service providers and highlights the need for robust security measures. The incident not only affects the financial institution but also raises concerns for customers whose accounts were compromised. Authorities are taking steps to address the issue and prevent similar attacks in the future.
darkreading
The National Institute of Standards and Technology (NIST) is grappling with a significant increase in reported vulnerabilities, which are being driven by advancements in AI technology. Researchers are finding that AI can both identify and exploit these vulnerabilities at an alarming rate. As the volume of these vulnerabilities continues to rise, NIST is exploring whether AI could also serve as a solution to manage and mitigate these risks. This situation is concerning for organizations that rely on software and digital systems, as the growing number of vulnerabilities could lead to increased cybersecurity incidents. The ongoing research suggests that while AI presents challenges, it may also offer tools to enhance security measures.
A data breach has been reported by a Scottish government agency, specifically from the prosecutor's office. This incident was triggered by a third-party service provider, which raises concerns that other agencies using the same vendor may also be impacted. While details about the extent of the breach are still emerging, the situation indicates a potentially wider vulnerability across multiple government entities. Data breaches like this can undermine public trust and disrupt operations, making it crucial for agencies to assess their security measures and ensure the protection of sensitive information. The incident emphasizes the risks associated with outsourcing services to third parties.
Infosecurity Magazine
Researchers have confirmed that the cyber extortion group ExfilSquad has accessed and stolen sensitive data from at least 13 different organizations. This data has been published by the group through torrents, making it publicly available. The nature of the stolen information remains unspecified, but the breach underscores significant security vulnerabilities within these organizations. As the leaked data could potentially be used for further attacks or identity theft, companies need to assess their security measures and respond swiftly to mitigate any potential fallout. This incident serves as a reminder of the ongoing risks posed by cybercriminals who exploit weaknesses in security protocols.
A recently patched vulnerability in SAP Commerce Cloud, classified as a maximum-severity remote code execution flaw, is now being actively targeted by attackers. The flaw was fixed just three days ago, and threat intelligence firm Defused has reported that cybercriminals are already exploiting it. This vulnerability puts users of SAP Commerce Cloud at risk, as it allows unauthorized code execution, potentially leading to data breaches or service disruptions. Companies using this platform need to ensure they apply the latest security updates to protect their systems. The urgency of the situation is underscored by the rapid exploitation following the announcement of the patch, making swift action essential for affected organizations.
SCM feed for Latest
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.
A new botnet called Evooo1Bot has emerged, built on the Mirai framework and featuring enhanced capabilities. This botnet is designed to convert compromised edge devices into persistent proxies, which can be exploited for various malicious activities. Researchers have noted that this could significantly impact Internet of Things (IoT) devices, making them potential tools for cybercriminals. The ability to create proxies means that attackers can mask their identity and amplify their operations, raising concerns about privacy and security. Users of affected devices need to be vigilant and improve their security measures to prevent being turned into unwitting participants in these attacks.
CISA has issued a warning about a significant vulnerability in Johnson Controls’ Metasys building automation systems. This flaw could potentially allow unauthorized access to control critical building functions, posing a risk to facility operations. The alert, identified as ICSA-26-225-14, emphasizes the importance of addressing this issue promptly to prevent exploitation. Organizations using Metasys technology should take immediate action to protect their systems. This vulnerability not only affects the security of the buildings but could also have broader implications for safety and operational integrity in environments reliant on these automation systems.
Shell is currently investigating a potential security incident after the Clop ransomware group claimed to have stolen 89GB of sensitive data from the company. The group is known for targeting large organizations and demanding ransom payments to prevent the public release of stolen information. Although Shell has not confirmed the specifics of the data taken, the incident raises concerns about the security of sensitive corporate information and the potential impacts on operations and reputation. As the investigation unfolds, it remains to be seen how the company will respond and whether any sensitive information has already been compromised. This incident serves as a reminder for all organizations to bolster their cybersecurity measures against ransomware attacks.