Security news.
Today's security landscape is dominated by multiple active exploitation campaigns and significant data breaches. Several critical vulnerabilities, including those in SAP Commerce Cloud, macOS Screen Sharing, and GeoServer, are being actively targeted, highlighting the urgency for immediate patching. Meanwhile, a series of high-impact data breaches at RingCentral, Scottish Government, and charities underscore the persistent threat of third-party compromises and credential theft.
SAP Commerce Cloud flaw actively exploited
A maximum-severity remote code execution vulnerability (CVE-2026-58231) in SAP Commerce Cloud, patched just three days ago, is already under active attack.
macOS Screen Sharing flaw exploited for Monero miner
Hackers are actively exploiting a macOS authentication bypass vulnerability in Screen Sharing to deploy a Monero cryptocurrency miner, following the public release of exploit code.
Unpatched GeoServer zero-day under active exploitation
An unpatched SQL injection vulnerability in GeoServer, which could lead to remote code execution, is currently being actively exploited by attackers.
RingCentral data breach impacts 1.6 million accounts
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after a July hack, with data including names, addresses, emails, and phone numbers.
Scottish Government suffers data breach via third party
A breach at a third-party service provider to a Scottish government agency, specifically the prosecutor's office, may have exposed data from other agencies as well.
Over 1,000 charities hit by Beacon CRM data breach
A data breach impacting over 1,000 charities using Beacon CRM is believed to stem from a compromised AWS access key exposed in publicly available JavaScript build artifacts.
Apple warns users of mercenary spyware attacks
Apple has issued new "Threat Notification" alerts to users whose iPhones have been targeted by sophisticated mercenary spyware attacks.
Hackers arrested for €30M bank fraud
Four individuals were arrested in Brazil and three charged in Europe for allegedly exploiting a service provider vulnerability to withdraw €30 million from Commerzbank customer accounts.