Patch Now or Pay Later: Hackers Strike SAP & Mac Users in 72 Hours
Saturday, August 15, 2026 · 5-minute read
Four suspects were arrested in Brazil and three others charged in Europe after they exploited a security flaw at a financial services provider to drain money from Commerzbank customers' accounts. The group used the vulnerability to bypass normal controls and make unauthorized withdrawals totalling around €30 million. This is a reminder that your bank's security is only as strong as every third-party company it works with.
↗ BleepingComputerUkrainian authorities raided and shut down 94 fake call centers operating across the country. The centers ran investment scams and tricked people into handing over access to their bank accounts. Police seized millions in cash — but operations like these are quick to rebuild elsewhere, so staying skeptical of unsolicited calls about investments remains essential.
↗ BleepingComputerThe hacking group Mustang Panda has upgraded its spying tools with a rootkit that can hide malicious files and network activity from security software. Victims confirmed so far include government agencies in Myanmar, Mongolia, Pakistan, and Russia. The group is using this as a follow-up tool after first infecting machines with a separate piece of malware called PlugX.
↗ The Hacker NewsAttackers are actively breaking into internet-exposed Macs by exploiting a flaw in macOS's built-in Screen Sharing feature. The bug lets an attacker on the same network log in without a valid password. Once inside, they install a Monero miner — software that quietly uses your computer's power to generate cryptocurrency for the attacker. The Netherlands' national cybersecurity agency issued a warning after public exploit code appeared online, meaning almost anyone can now attempt this attack.
When a website owner lets their domain name expire, criminals swoop in and re-register it — inheriting the site's old reputation and any links pointing to it. Security firm Infoblox found that around 65,000 of these expired domains are snapped up every single day. That's nearly one in five new domain registrations. The criminals then redirect visitors to scam pages or malware downloads, exploiting the trust people have for what they think is a familiar site.
This is about as bad as it gets — a perfect 10 out of 10 severity score. SAP Commerce Cloud is e-commerce software used by major retailers and businesses worldwide. The flaw lets an attacker who isn't logged in at all send specially crafted requests to the system and run any code they want on it. That means full control: stealing data, planting malware, or taking the whole service offline. Attacks started just three days after SAP released the fix.
Status: Patch available — SAP released a fix this week. If your organization runs SAP Commerce Cloud, escalate to your IT team today.
This flaw in Apple's Screen Sharing feature skips the password check entirely, letting anyone on the same Wi-Fi or network connect to your Mac as if they had your credentials. It's being actively exploited right now — attackers are using it to install cryptocurrency mining software. The fix was rushed out by Apple on August 6.
Status: Patch available — update to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 immediately.
A newly discovered zero-day vulnerability in Microsoft Defender — the built-in security tool on every Windows PC — can give an attacker full SYSTEM-level control of a machine. That's the highest level of access possible on Windows, meaning an attacker could do anything. Microsoft has not yet released a patch.
Status: No patch yet. Watch for an out-of-band Windows update and install it immediately when it arrives. Keep an eye on Windows Update settings.
A free new tool called DecryptAds (decryptads.com), built by security researchers at Infoblox, lets you type in any website and instantly see every advertising company and data broker that collects information from its visitors. It also flags which ad partners are based in countries considered security risks — like Russia or China. For example, a search for ESPN's website revealed 143 ad partners and 19 data brokers, including four partners linked to Russia, China, or the UAE. One of those partners, flagged as a Russian firm, was found processing payments through a sanctioned Russian bank — yet it was also serving ads on major U.S. military news websites. The tool is free and requires no signup, making it a genuinely useful privacy check for curious non-technical users.
↗ Krebs on SecurityThis week, a perfect-severity flaw in SAP's e-commerce software was already under active attack just three days after the patch was released. That's not unusual anymore — it's becoming the norm. And it reveals one of the most uncomfortable truths in cybersecurity today: the gap between "a fix exists" and "your systems are actually fixed" is exactly where criminals live.
Here's how it works. When a company like SAP releases a security patch, they also publish details about what was broken. Security researchers, journalists, and yes — criminals — all read those announcements. For a sophisticated attacker, that announcement is essentially a treasure map. They reverse-engineer the patch to figure out exactly what the vulnerability was, build a tool to exploit it, and start scanning the internet for unpatched targets. This entire process used to take weeks or months. Now it takes days, sometimes hours. In the SAP case, attack attempts began hitting security researchers' honeypot servers just 72 hours after the patch dropped.
For large organizations, patching isn't as simple as clicking "update." Enterprise software like SAP Commerce Cloud runs complex operations — online stores, inventory systems, payment processing. Applying a patch means testing it first to make sure it doesn't break something, scheduling downtime, getting approvals, and deploying across potentially hundreds of servers. That process routinely takes days or weeks. Attackers know this, and they're counting on it. The window between "patch released" and "patch applied everywhere" is their best opportunity of the year.
What can you do? If you're an everyday user, the lesson is simpler: when your phone, computer, or apps prompt you to update, do it that day — not next week. Consumer updates are far easier to apply than enterprise ones, and delay is the main thing attackers rely on. If you work in an organization, push for emergency patching procedures for critical-severity vulnerabilities. The old rhythm of monthly patch cycles was designed for a slower era. Attackers have moved on. Your update schedule should too.