← Latest brief

Security news.

·Afternoon Brief

Today's security landscape is dominated by multiple active exploitation campaigns and significant data breaches. Several critical vulnerabilities, including those in SAP Commerce Cloud, macOS Screen Sharing, and GeoServer, are being actively targeted, highlighting the urgency for immediate patching. Meanwhile, a series of high-impact data breaches at RingCentral, Scottish Government, and charities underscore the persistent threat of third-party compromises and credential theft.

BLEEPINGEXPLOIT
2d agoREAD

SAP Commerce Cloud flaw actively exploited

A maximum-severity remote code execution vulnerability (CVE-2026-58231) in SAP Commerce Cloud, patched just three days ago, is already under active attack.

BLEEPINGEXPLOIT
2d agoREAD

macOS Screen Sharing flaw exploited for Monero miner

Hackers are actively exploiting a macOS authentication bypass vulnerability in Screen Sharing to deploy a Monero cryptocurrency miner, following the public release of exploit code.

SECURITYWEEKZERO-DAY
2d agoREAD

Unpatched GeoServer zero-day under active exploitation

An unpatched SQL injection vulnerability in GeoServer, which could lead to remote code execution, is currently being actively exploited by attackers.

BLEEPINGBREACH
2d agoREAD

RingCentral data breach impacts 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after a July hack, with data including names, addresses, emails, and phone numbers.

DARK READINGBREACH
2d agoREAD

Scottish Government suffers data breach via third party

A breach at a third-party service provider to a Scottish government agency, specifically the prosecutor's office, may have exposed data from other agencies as well.

SECURITYWEEKBREACH
2d agoREAD

Over 1,000 charities hit by Beacon CRM data breach

A data breach impacting over 1,000 charities using Beacon CRM is believed to stem from a compromised AWS access key exposed in publicly available JavaScript build artifacts.

BLEEPINGMALWARE
2d agoREAD

Apple warns users of mercenary spyware attacks

Apple has issued new "Threat Notification" alerts to users whose iPhones have been targeted by sophisticated mercenary spyware attacks.

BLEEPINGPOLICY
2d agoREAD

Hackers arrested for €30M bank fraud

Four individuals were arrested in Brazil and three charged in Europe for allegedly exploiting a service provider vulnerability to withdraw €30 million from Commerzbank customer accounts.

Generated twice daily from public security RSS feeds. Informational only.