Mac Miners, a $7M Domain Trap, and Two Perfect-10 Flaws: This Week in Cyber
Sunday, August 16, 2026 · 5-minute read
Four cybercriminals were arrested in Brazil, and three more were charged across Europe, over a scheme that drained funds from Commerzbank customers. The attackers found a flaw in a third-party service provider used by the bank and exploited it to pull money directly from customer accounts. This is a reminder that your bank's security is only as strong as every vendor it relies on.
↗ BleepingComputerUkrainian authorities raided and shut down 94 fake call centers operating across the country. The centers ran investment scams and tried to trick people into handing over their banking credentials. Millions in cash were seized in the operation — a sign that old-school phone fraud is still big business for organized crime.
↗ BleepingComputerOil giant Shell says it's looking into a possible security breach after the Clop ransomware gang claimed it stole 89 gigabytes of company data. Shell hasn't confirmed what was taken or how the attackers got in. Clop has a history of stealing data from large organizations and publishing it publicly when ransoms aren't paid.
↗ BleepingComputerA critical flaw in macOS's Screen Sharing feature is being actively exploited. Attackers who are on the same network as a vulnerable Mac can log into it remotely — no password needed. Once in, they install a Monero miner, quietly running your hardware at full speed to make money for someone else. Apple already released an emergency fix on August 6. The Netherlands' national cybersecurity center issued a public warning after exploit code appeared online, which dramatically lowered the bar for attackers. If your Mac hasn't updated in the past two weeks, it may be vulnerable right now.
The Lazarus Group, North Korea's most notorious hacking team, exploited a previously unknown flaw in Windows to target defense industry firms. A zero-day flaw means there was no patch available when the attack happened. Defense contractors and their suppliers are the primary targets here, but the techniques often spread to other industries over time.
This is as bad as it gets — a perfect 10 out of 10 severity score. SAP Commerce Cloud powers the online stores of many large retailers and enterprises. An attacker with no login credentials whatsoever can send specially crafted requests to the system and take full control of it. That means they can read private data, change records, or bring the whole platform down. Attackers started probing for this flaw just three days after SAP released the patch.
Status: Patch available — SAP released a fix. If your organization runs SAP Commerce Cloud, treat this as urgent. Contact your SAP administrator immediately.
This flaw lets anyone on your local network — think coffee shop Wi-Fi, office network, or home network with a compromised device — connect to your Mac's remote desktop feature without a password. Apple normally requires valid credentials to allow remote access; this bug breaks that requirement completely. It's already being actively exploited to install crypto-mining malware on exposed Macs.
Status: Patch available — emergency updates released August 6, 2026 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
A new zero-day vulnerability dubbed "ShieldBreak" was found in Microsoft Defender, the built-in antivirus and security tool on Windows. An attacker who exploits it can gain SYSTEM-level access — that's the highest privilege level on a Windows machine, effectively giving them complete control. This is particularly alarming because Defender is supposed to be the thing protecting you.
Status: Patch status not yet confirmed. Watch for an emergency update from Microsoft and apply it immediately when available.
A new free service called DecryptAds (decryptads.com) lets anyone look up which advertising companies and data brokers are collecting information from any website or app. It was built by Zach Edwards and his team at security firm Infoblox. The tool cross-references public files that websites are required to publish, revealing things that are technically public but nearly impossible to find on your own. For example, a search for ESPN.com shows 143 ad partners and 19 data brokers — including several based in Russia, China, and the UAE. It can also flag when ad networks from adversarial countries are embedded in sensitive sites, like U.S. military news publications. It's a rare case of a genuinely useful privacy tool that doesn't cost anything.
↗ Krebs on SecurityImagine buying a house and discovering the previous owner had a great reputation in town — so everyone who shows up at your door already trusts you. That's exactly what's happening with expired internet domains, and it's now a massive, organized criminal industry.
When a website shuts down and its owner stops paying for the domain name, that address goes back on the market. Security researchers at Infoblox found that in just the first half of 2026, criminal groups spent nearly $7 million snapping up these dropcatch domains at a rate of 65,000 per day. The reason? Those old domains carry baggage that's actually valuable to criminals. Search engines still rank them highly. Old links from legitimate websites still point to them. Email security systems still trust them. The criminals inherit all of that goodwill instantly.
Once they own the domain, attackers redirect anyone who visits to scam pages, fake login forms, or sites that try to install malware. If you bookmarked a website years ago and visit it today, you might land somewhere completely different — and completely dangerous — without any obvious warning signs. The site might look normal. The URL is familiar. Your browser shows no warnings. That's what makes this so effective. One in five newly registered domains right now is a dropcatch domain — meaning the problem is enormous and growing.
There's no single easy fix for consumers, but a few habits help. Avoid clicking old bookmarks for sites you haven't visited in years without verifying they still look right. Be skeptical of any site that suddenly asks you to log in or download something when it didn't before. And consider using a DNS filtering service — many are free — that can block known malicious domains before your browser ever loads them. Researchers expect this type of attack to keep growing as more domains expire and criminal groups get better at automating the acquisition process.