Fake Job Interviews, 1.6M Breached Accounts & Apple's Spyware Warning
Friday, August 14, 2026 · 5-minute read
Apple sent a new round of spyware threat notifications to an undisclosed number of people across 110 countries on Thursday. The company said it has now alerted users in more than 150 countries since it started sending these warnings in late 2021. The targets are typically journalists, activists, politicians, and diplomats — people singled out because of their job or public role, not caught up in a random mass attack.
↗ The Hacker NewsUkrainian authorities raided and shut down 94 fake call centers operating across the country this week. The centers ran investment scams and tricked victims into handing over banking credentials. Police seized millions in cash during the operation — a reminder that a lot of online financial fraud still runs through old-fashioned phone calls.
↗ BleepingComputerPresident Trump signed a memo this week directing the National Coordination Center to build a program that lets vetted private companies legally hack foreign criminal organizations. Approved firms could conduct offensive cyber operations against transnational crime groups — a significant and controversial expansion of who gets to go on offense online. The program requires government approval for each operation, but critics are already asking who watches the watchers.
↗ The Hacker NewsResearchers at CTM360 found over 3,000 malicious URLs linked to a global campaign called RecruitTrap. Attackers pose as real recruiters from well-known companies and send targets links to fake interview scheduling pages. When you click, a convincing fake login window — called a Browser-in-the-Browser popup — appears and asks for your Google or Facebook password. In more sophisticated versions, the attack can also capture your multi-factor authentication code in real time, bypassing that protection entirely. Marketing professionals are the most common target because their accounts unlock advertising platforms, customer data, and company social media profiles.
Researchers at Broadcom's Symantec uncovered a China-linked group called Jewelbug running two separate businesses from the same control panel. One operation spies on governments and militaries across the Middle East, Southeast Asia, and South Asia. The other defrauds people through cryptocurrency scams. Both missions run through a single browser-based remote-access tool called XG-Web, which turns a victim's browser into a remote-control channel and tunnels deeper into their network from there. It is rare — and alarming — to see a state-linked espionage group moonlighting in financial fraud at this scale.
A critical flaw in VMware's vCenter Syslog Server is being actively exploited right now. An attacker who finds a vulnerable server can execute their own code on it remotely — no password needed — then install a reverse SSH backdoor to keep access even after reboots. VMware vCenter is the software many companies use to manage large numbers of virtual machines, so a compromise here can give an attacker a foothold across an entire organization's infrastructure.
Status: Patch available — apply it immediately. Active exploitation is confirmed.
A newly disclosed zero-day vulnerability dubbed ShieldBreak affects Microsoft Defender, the built-in antivirus on Windows. Exploiting it lets an attacker gain SYSTEM-level privileges — effectively full control of the machine. The irony is sharp: the security tool itself becomes the way in. Microsoft has not yet released a public patch as of this issue going to press.
Status: No patch yet — watch for an out-of-band update from Microsoft. Keep Defender itself updated and limit who can run unknown software on Windows machines.
Microsoft patched a Windows zero-day called LegacyHive this week in an out-of-cycle update, after the flaw was disclosed following July's regular Patch Tuesday. The vulnerability sits in a legacy part of the Windows registry system and could be used to escalate privileges on a compromised machine. It is the kind of flaw attackers love: useful as a second step after they've already gotten a foothold somewhere.
Status: Patch now available — install via Windows Update.
Security researcher Zach Edwards and his co-founders launched DecryptAds (decryptads.com), a free service that maps the hidden web of companies tracking you on any website or app. You type in a domain — say, espn.com — and it pulls together all the publicly filed data about who is allowed to run ads or harvest your data there, then cross-references it to spot data brokers, geo-risk partners, and supply-chain red flags that would be invisible if you looked at any single file alone. A search for espn.com revealed 19 registered data brokers and four ad partners based in Russia, China, or the UAE — including one Russian firm processing payments through a sanctioned bank. The tool is built for privacy researchers and security teams but is simple enough for anyone to use, and arrives just as several US states have passed laws forcing data brokers to register publicly.
↗ Krebs on SecurityWhatsApp started rolling out an optional Scam Alert feature this week. It uses a small on-device machine learning model to analyze incoming messages and warn you when the patterns match known scam behavior — things like urgent requests for money or suspicious links from strangers. Crucially, the analysis happens locally on your phone, so WhatsApp itself never reads your messages to power it. Enable it in WhatsApp's Privacy settings once it rolls out to your account.
↗ BleepingComputerIf you use RingCentral for work calls or messaging, your personal information may now be in criminal hands. The ShinyHunters extortion group stole data from 1.6 million RingCentral accounts after hacking the company in July. The breach was confirmed this week through Have I Been Pwned, the well-known data breach notification service run by security researcher Troy Hunt.
RingCentral is one of the most widely used business phone and messaging platforms in the world — the kind of software that sits quietly in the background of millions of office workers' days. When a platform like this gets breached, the stolen data tends to be rich: names, email addresses, phone numbers, and account details that can be used to build convincing follow-up scams. ShinyHunters has a long track record of doing exactly that, using stolen data to craft targeted spear-phishing emails that look legitimate because they reference real information about the victim.
For regular people, the most immediate risk is not that someone logs into your RingCentral account — it's what happens next. Criminals package breached data and sell it, or use it themselves to send emails pretending to be your employer's IT department, your bank, or a service you use. The email will have your real name, maybe your real phone number, and will feel personal. That's the playbook. A breach like this becomes fuel for months of downstream scams.
Check whether your email was included at haveibeenpwned.com. If it was, be extra skeptical of any unexpected emails or calls over the coming weeks claiming to be from RingCentral, your IT team, or your phone provider. Change your RingCentral password and make sure two-factor authentication is turned on. And if you reused your RingCentral password anywhere else, change it there too — right now.