vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
other Friday Squid Blogging: Searching for the Colossal Squid This article isn't about cybersecurity at all. It's a fascinating video about marine biology, specifically the use of red light to observe and attract giant squid and colossal squid in the deep ocean. There's no security… Schneier on Security · Aug 14, 2026 Info marine biologydeep seared light
threat-intel Investigation of banking hack leads to arrests in Germany, Brazil A coordinated investigation in Germany and Brazil has resulted in arrests and asset seizures linked to a €30 million banking hack. The hackers exploited a vulnerability in a payment provider to drain funds from German ac… The Record · Aug 14, 2026 High DEBRESbankingcybercrimemoney laundering
threat-intel Mission-Driven Security: Inside a Global Bank's Defense This article explores the evolving role of the Chief Information Security Officer (CISO) at Standard Chartered, a global bank. The piece highlights Cezary Piekarski's journey from a technical background to a strategic le… Dark Reading · Aug 14, 2026 High cisocybersecuritybanking
threat-intel Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ dom… The Hacker News · Aug 14, 2026 High VIRUAUdropcatchexpired domainsmalware
data-breach 1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack Approximately 1.6 million RingCentral accounts have been exposed after a ShinyHunters extortion attack. Attackers gained access to sensitive data, including customer information, and are now demanding ransom for its retu… The Register · Aug 14, 2026 High credential stuffingdata breachransomware
threat-intel Amid AI-Driven Bug Tsunami, NIST Looks to…AI The National Institute of Standards and Technology (NIST) is seeking public input on how to modernize the National Vulnerability Database (NVD) in light of a massive surge in software vulnerabilities, driven in part by A… Dark Reading · Aug 14, 2026 Medium vulnerabilityaicybersecurity
threat-intel IAM Compliance Requirements and Best Practices This article focuses on Identity and Access Management (IAM) compliance, highlighting the gap between documented policies and actual enforcement of access controls. It argues that simply having a documented IAM policy is… The Hacker News · Aug 14, 2026 High iamcomplianceaccess control
threat-intel Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office A data breach at Scotland's Crown Office and Procurator Fiscal Service (COPFS) has exposed the personal information of approximately 300 employees, potentially impacting a wider number of Scottish government agencies inv… Dark Reading · Aug 14, 2026 High UKvendor-riskdata-breachphishing
data-breach French tax authority admits data heist after crook touts 2M records The French tax authority, l'administration fiscale, has admitted to a data breach resulting in the potential theft of up to two million records. The breach was facilitated by a criminal attempting to sell the stolen data… The Register · Aug 14, 2026 Medium FRdata breachgovernmentcybersecurity
threat-intel What Boards Need to Know About Tech Risk This article argues that boards of directors often fail to adequately address technology risks due to a focus on revenue-generating investments and a lack of understanding of the technical realities of digital infrastruc… Dark Reading · Aug 14, 2026 High technical debtrisk managementcybersecurity
threat-intel France investigates tax authority breach after hacker claims 600,000 victims France’s tax authority, DGFiP, is investigating a breach that a hacker claims impacted over 600,000 individuals and businesses. The attacker gained unauthorized access to systems in late June, allowing them to steal data… The Record · Aug 14, 2026 High FRdata breachfrancegovernment
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth
threat-intel Autonomous AI attacks pose 'clear and present danger' to critical infrastructure A growing trend indicates that attackers are increasingly leveraging open-source AI agents to autonomously launch sophisticated cyberattacks against critical infrastructure, including government systems, energy companies… The Register · Aug 14, 2026 High CHIRNOaicyberattackcritical infrastructure
threat-intel Cyera's Oasis Security Buy is All About AI Agent Control Cyera is acquiring Oasis Security in a $1 billion deal to bolster its data security platform with AI agent management capabilities. This acquisition addresses the growing need to manage the increasing number of non-human… Dark Reading · Aug 14, 2026 High ISaiagenticidentity management
threat-intel In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities This week’s cybersecurity news highlights a range of concerning developments, including a government contract sparking AI concerns, a North Korean IT worker infiltrating a US federal agency, vulnerabilities discovered in… SecurityWeek · Aug 14, 2026 High NOransomwarecyberattackvulnerability
threat-intel Cyberharcèlement : la Belgique prépare un bannissement numérique Belgium is considering a system to temporarily ban individuals from social media platforms who are convicted of online offenses, drawing inspiration from a similar law in France. The initiative, spearheaded by Minister o… ZATAZ · Aug 14, 2026 Medium BEcyberbullyingonline crimesocial media
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
threat-intel Who’s Tracking You? Use This New Service to Find Out DecryptAds is a new service designed to expose the complex ecosystem of adtech companies tracking users online. By scraping data from files like ads.txt, app-ads.txt, and sellers.json, it reveals a network of data broker… Krebs on Security · Aug 14, 2026 High CHRUUAadtechdata-brokermalvertising
threat-intel Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers Researchers have discovered a post-exploitation technique leveraging Chrome DevTools Protocol (CDP) to steal cookies and sensitive data from running instances of Chrome and Edge on Windows. This method bypasses standard… The Hacker News · Aug 14, 2026 High cdpdevtoolscookie theft