← All issues
cybersecurityCyberBubbleAndroid

Answer a Video Call, Lose Your Phone — Plus Four Critical Flaws to Patch Now

🌐  World Intel
France: Tax Authority Breach Hits 678,000 Citizens

An attacker broke into systems belonging to France's General Directorate of Public Finances — the agency that handles tax collection — and stole personal data on 678,000 people. The French Ministry of the Economy confirmed the breach this morning. If you have any connection to the French tax system, expect phishing emails that pretend to be official government notices.

↗ BleepingComputer
China-Linked Hackers Hit VMware Servers With Ransomware

Researchers at German incident response firm QUIRSO say a suspected Chinese APT group is actively exploiting a critical flaw in VMware vCenter — software that large organisations use to manage their entire IT infrastructure. The attackers are deploying ransomware based on leaked Babuk code. A patch landed July 29, but many servers remain unupdated.

↗ The Hacker News
Brazil & Europe: Seven Arrested Over €30M Bank Fraud

Four people were arrested in Brazil and three more charged in Europe after investigators say the group exploited a vulnerability at a financial service provider to drain funds from Commerzbank customers' accounts. The total haul is estimated at over €30 million. The case shows how a single flaw at a behind-the-scenes provider can put thousands of ordinary bank customers at risk.

↗ BleepingComputer
⚔️  Active Attacks
Mac Screen Sharing Bug Is Being Used to Mine Crypto on Your Machine

Hackers are actively exploiting a freshly patched flaw in macOS's Screen Sharing feature. The bug lets an attacker on the same network log into your Mac's built-in remote desktop without knowing your password — no guessing required. Once in, they install software that secretly mines Monero cryptocurrency using your computer's processor, slowing your machine down and running up your electricity bill. The Netherlands' national cybersecurity agency confirmed the attacks are happening right now. Public exploit code is already circulating online, meaning almost anyone can run this attack.

🛡 What to do: Open System Settings on your Mac, go to General → Software Update, and install macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 right now. If you don't use Screen Sharing, turn it off under System Settings → General → Sharing.
New AmnesiaStealer Malware Hijacks Your Browser — While You Watch

A new piece of info-stealing malware called AmnesiaStealer is targeting Mac users. It spreads through ClickFix attacks — fake pop-ups that trick you into running a malicious command. What makes it unusual is a live streaming feature: once installed, the attacker can watch and control your web browser in real time, letting them log into your accounts even if you use two-factor authentication.

🛡 What to do: Never copy-paste commands from browser pop-ups or website prompts, no matter how urgent they look. If a website tells you to open Terminal and run something, close the tab immediately.
🔓  New Vulnerabilities
CVE-2026-58231 SAP Commerce Cloud CRITICAL 10.0

This is as bad as it gets — a perfect 10 out of 10 severity score. SAP Commerce Cloud is e-commerce software used by large retailers and enterprises worldwide. The flaw lets a complete stranger on the internet run any code they want on the server, no login needed, because the software fails to properly check who is sending requests. Attackers started probing for vulnerable servers just three days after the patch dropped.

Status: Patch available — apply immediately if your organisation runs SAP Commerce Cloud.

CVE-2026-65400 Apple macOS Screen Sharing CRITICAL 9.8

This flaw lets anyone on your Wi-Fi network log into your Mac remotely without a password. The Screen Sharing feature — normally protected by your credentials — fails to properly verify who is connecting. Apple pushed an emergency patch on August 6, but attackers are already using it in the wild to install crypto-mining software.

Status: Patch available — update macOS immediately (see Active Attacks section above).

CVE-2026-59310 VMware vCenter Server CRITICAL 9.8

VMware vCenter is the control panel IT teams use to manage hundreds or thousands of virtual machines at once. This directory-traversal vulnerability lets an outside attacker run their own code on the server — meaning they can take over an organisation's entire virtual infrastructure. A suspected Chinese hacking group is actively exploiting this and following up with ransomware.

Status: Patch available since July 29, 2026 — if your IT team hasn't applied it, escalate this today.

CVE-2026-69414 "ShieldBreak" Microsoft Defender HIGH — Score TBD

A researcher going by "Nightmare Eclipse" publicly disclosed a zero-day flaw in Microsoft Defender ��� the built-in antivirus on Windows — last week. The bug can be used to disable or bypass Windows' main security shield, potentially letting other malware run undetected. Microsoft confirmed it's working on a fix but one isn't out yet.

Status: No patch yet — Microsoft is working on a fix. Keep Windows Update set to automatic so the patch installs the moment it's released.

🛠  New Tech
DecryptAds: A Free Tool That Shows Who's Really Tracking You on Every Website

Security researcher Zach Edwards and his team just launched DecryptAds, a free service that maps out every advertising company and data broker collecting information from any website or app you name. Type in a web address and it instantly shows you which ad networks can track you, which ones are based in countries like Russia, China, or the UAE, and whether any have been flagged as security risks. A search for ESPN.com, for example, revealed 143 ad partners and 19 registered data brokers — including four entities linked to Russia, China, or the UAE, and one that routes payments through a sanctioned Russian bank. The tool works by cross-referencing the public disclosure files that websites are required to publish, files that exist but are almost impossible to read without software help. For anyone concerned about third-party tracking, this is the most transparent look yet at who's watching.

↗ Krebs on Security
💡  Deep Dive
Your Android Phone Could Be Hijacked by a Video Call — and There's No Fix Coming

Imagine getting a video call from an unknown number, answering it, and handing the caller full control of your phone's operating system — without clicking a single link or downloading anything. That's exactly what a newly published exploit chain can do to Android phones running Unisoc modem firmware. And there is currently no fix.

Here's how it works. Security researchers at SSD Secure Disclosure have spent months building a two-stage attack. Stage one, published back in March, showed that sending a specially crafted SIP video call to a vulnerable phone could let an attacker run their own code on it remotely. Stage two, published today, completes the chain: it escalates that foothold all the way to full kernel-level control. That's the highest level of access possible. From there, an attacker can read everything on the device, install spyware, or silently monitor calls and messages.

The catch — and it's an important one — is that the attacker needs to control a private 4G cellular network to pull this off. That's not something your average criminal can set up in their bedroom. But it's well within reach of a government intelligence agency or a well-funded criminal group. Victims just have to answer the call. The researchers say they tried to contact Unisoc through email and LinkedIn multiple times over months and received zero response — the same silence they got after the first disclosure in March. That's a big problem, because without a vendor fix, the only protection is awareness.

Unisoc chips are found in hundreds of millions of budget and mid-range Android phones, particularly across Africa, Asia, and Eastern Europe. If you're unsure whether your phone uses a Unisoc chip, check your phone's settings under "About Phone" — look for the processor name. If it says Unisoc (or Spreadtrum), be cautious about answering video calls from numbers you don't recognise, and watch for any patch announcements from your phone's manufacturer.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →