Security news.
Today's cybersecurity landscape is marked by widespread data breaches affecting millions of users and organizations, alongside active exploitation of critical vulnerabilities. macOS users are also facing new threats from infostealers, emphasizing the need for robust endpoint protection and rapid patching.
Threema Secure Messaging Hit by Large-Scale DDoS Attacks
The secure messaging service Threema experienced severe communication disruptions earlier this week due to multiple distributed denial-of-service (DDoS) attacks.
New AmnesiaStealer macOS Malware Hijacks Browser Sessions
A new information-stealing malware, AmnesiaStealer, targets macOS users via "ClickFix" attacks, featuring a streaming module that allows attackers to remotely control the victim's web browser.
Evooo1Bot Linux Botnet Turns Routers into Traffic Relays
A new Mirai-based modular Linux botnet, Evooo1Bot, is targeting internet-facing gateway devices to convert them into SOCKS5 traffic relay nodes.
Hackers Arrested for €30M Bank Fraud Exploiting Service Provider Flaw
Four individuals were arrested in Brazil and three charged in Europe for allegedly exploiting a vulnerability at a service provider, enabling them to withdraw funds from Commerzbank customer accounts.
Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner
The NCSC warns that hackers are actively exploiting a macOS authentication bypass vulnerability following the public release of exploit code, using it to deploy Monero miners.
Max Severity SAP Commerce Cloud Flaw Actively Exploited
A critical SAP Commerce Cloud remote code execution vulnerability (CVE-2026-58231, CVSS 10.0), patched just three days ago, is already being targeted in attacks.
RingCentral Data Breach Exposes 1.6 Million Accounts
The ShinyHunters extortion group reportedly stole personal information from 1.6 million RingCentral accounts after hacking the company in July.
Over 1,000 Charities Hit by Beacon CRM Data Breach
A data breach impacting over 1,000 charities is believed to stem from a compromised AWS access key exposed in publicly available JavaScript build artifacts.