← Latest brief

Security news.

·Morning Brief

Today's cybersecurity landscape highlights a surge in active exploitation, with multiple critical vulnerabilities in SAP Commerce Cloud, macOS Screen Sharing, and GeoServer now under attack. We're also seeing significant data breaches impacting millions of users and numerous organizations, alongside ongoing concerns about AI's role in both offense and defense.

BLEEPINGVULN
2d agoREAD

Max severity SAP Commerce Cloud flaw now targeted in attacks

A critical SAP Commerce Cloud (Data Hub Adapter) remote code execution vulnerability (CVE-2026-58231), patched just three days ago, is already being actively exploited.

BLEEPINGEXPLOIT
2d agoREAD

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The NCSC warns that threat actors are actively exploiting a macOS authentication bypass vulnerability after public exploit code became available, deploying a Monero cryptocurrency miner.

SECURITYWEEKZERO-DAY
2d agoREAD

Hackers Exploiting Unpatched GeoServer Zero-Day

An unpatched SQL injection vulnerability in GeoServer is actively being exploited by attackers, potentially leading to remote code execution.

BLEEPINGBREACH
2d agoREAD

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after a July hack, with data including names, addresses, emails, and phone numbers.

SECURITYWEEKBREACH
2d agoREAD

Over 1,000 Charities Hit by Beacon CRM Data Breach

A data breach at Beacon CRM, affecting over 1,000 charities, is attributed to a compromised AWS access key exposed in publicly available JavaScript build artifacts.

BLEEPINGPOLICY
2d agoREAD

Hackers arrested over €30M bank fraud exploiting service provider flaw

Four cybercriminals were arrested and three others charged for exploiting a vulnerability at a service provider, leading to the fraudulent withdrawal of €30 million from Commerzbank customer accounts.

DARK READINGAI
2d agoREAD

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

As AI-augmented research and scanning contribute to a surge in vulnerability volumes, NIST is exploring whether AI can also provide solutions for managing this influx.

BLEEPINGMALWARE
2d agoREAD

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

Apple is issuing new "Threat Notification" alerts to users whose iPhones may have been targeted by mercenary spyware attacks.

Generated twice daily from public security RSS feeds. Informational only.