← All issues
cybersecurityCyberBubbleransomware

Your Mac Is Under Attack: 4 Critical Flaws Being Exploited Right Now

🌐  World Intel
USA: Medusa Ransomware Has Hit 500+ Critical Infrastructure Targets

The FBI confirmed Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. That includes hospitals, utilities, and government agencies — the kinds of systems people depend on every day. The FBI's warning is a signal that Medusa is still very active and showing no signs of slowing down.

↗ BleepingComputer
USA: Hacker Claims 3.6 Million Azure Account Records Stolen from Fortune 500 Firms

A hacker is advertising databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies. The attacker reportedly got in using stolen employee credentials — not by breaking through technical defenses, but by using passwords that were already compromised. If verified, this would be one of the larger cloud credential theft incidents of the year.

↗ BleepingComputer
USA: RingCentral Data Breach Exposed Info of 1.6 Million Accounts

Business communications platform RingCentral suffered a data breach that exposed the personal information of 1.6 million accounts. RingCentral is widely used by companies for phone calls, video meetings, and messaging — meaning the exposed data could include contact details for millions of employees at businesses across the country. Notifications to affected users are now underway.

↗ BleepingComputer
⚔️  Active Attacks
Mac Users Targeted: Screen Sharing Flaw Used to Mine Cryptocurrency

Hackers are actively exploiting a critical flaw in macOS Screen Sharing (CVE-2026-65400) that lets an attacker log in without a valid password — just by being on the same network. Once inside, attackers have been seen installing a Monero miner, which quietly runs in the background and uses your Mac's computing power to make money for the attacker. CISA added this flaw to its list of known exploited vulnerabilities on Tuesday, meaning real attacks are confirmed.

🛡 What to do: Open System Settings → General → Sharing and turn off Screen Sharing if you don't use it. Then run Software Update to install the latest macOS security patches immediately.
Clop Ransomware Gang Deploys Custom-Built Weapon Against Engineering Software

The Clop ransomware gang is using a sophisticated custom tool to attack companies running PTC Windchill, software used by manufacturers to manage product designs and engineering data. The tool — a web shell — can decrypt every stored password in the system, map out sensitive file vaults, and open a permanent back door for the attackers to return later. This isn't an off-the-shelf tool; it was purpose-built for this software, which signals a serious, targeted campaign against industrial and engineering firms.

🛡 What to do: If your organization uses PTC Windchill or FlexPLM, contact your IT or security team today to confirm patches are applied and check for signs of unauthorized access in your system logs.
🔓  New Vulnerabilities
CVE-2026-65400 Apple macOS Screen Sharing CRITICAL 9.8

An attacker on your local network — say, on the same coffee shop Wi-Fi — can log into your Mac's Screen Sharing feature without needing a password at all. This gives them full visual access to your screen and the ability to control your computer. It's being actively exploited right now, with attackers using access to install cryptocurrency miners.

Status: Patch available — install the latest macOS update immediately.

CVE-2026-59310 Broadcom VMware vCenter CRITICAL 9.8

VMware vCenter is the control center that IT teams use to manage large numbers of virtual servers. This flaw allows an attacker with network access to trick the software into running their own code — essentially letting them take over the entire virtual infrastructure. It's confirmed as actively exploited and is a top priority for any organization running VMware.

Status: Patch available from Broadcom — apply immediately, prioritize internet-facing vCenter instances.

CVE-2026-33824 Microsoft Windows IKE Service Extensions CRITICAL 9.8

The Internet Key Exchange (IKE) Service in Windows has a flaw that attackers can exploit to run malicious code remotely on a target machine. CISA confirmed it's being actively exploited, and BleepingComputer notes it's already being used in the wild as a remote code execution attack. Windows systems that haven't been updated recently are at risk.

Status: Patch available via Windows Update — apply now, especially on servers and VPN gateways.

CVE-2026-24301 Microsoft Copilot Personal (CoSnitch) HIGH

Researchers at Varonis found three flaws in Microsoft Copilot Personal — the consumer AI assistant at copilot.microsoft.com — that they named CoSnitch. A single click on a crafted link could silently pull data from apps connected to your Copilot session, including emails and files, without you realizing it. Researchers found no evidence of real-world exploitation, and Microsoft shipped patches on August 18.

Status: Patched by Microsoft on August 18, 2026 — no action required if you use the web version of Copilot, as updates apply automatically.

🛠  New Tech
DecryptAds: A Free Tool That Exposes Who Is Really Tracking You Online

A new free service called DecryptAds (decryptads.com) lets anyone look up which advertising companies and data brokers are collecting information from any website or app. Created by security researcher Zach Edwards and his team at Infoblox, it works by scraping the public disclosure files that websites are required to publish — then cross-referencing them to reveal the full picture. A search for ESPN.com, for example, turned up 143 ad partners and 19 data brokers, including four firms based in Russia, China, or the UAE. The tool also flags high-risk adtech partners linked to adversarial nations and can help identify the source of malicious ads. It's built for privacy researchers and security teams, but anyone can use it to see exactly who profits from their web browsing.

↗ Krebs on Security
💡  Deep Dive
MacSync Stealer: The Mac Malware Campaign That's Been Hiding in Plain Sight Across 30+ Websites

For years, Mac users have operated under a comfortable assumption: Macs don't get viruses, or at least not serious ones. Today's story is a reminder of why that assumption is increasingly dangerous. Microsoft's security researchers just mapped out a sophisticated malware operation targeting Macs that has been quietly running across more than 30 rotating web domains — and it's been actively stealing real data, not just looking around.

The malware, called MacSync Stealer, is an information stealer — software designed to vacuum up passwords, files, and sensitive data from an infected Mac and ship it off to attackers. Microsoft's Defender Experts team connected the dots across more than 30 different web domains that the attackers kept rotating through, making it harder for security tools to block them all at once. What's notable here is the level of operational sophistication: the attackers weren't just checking in to see if the malware was running. They were actively pulling data out. The infection likely starts with a ClickFix attack — a trick where a website tells you to copy and paste a command into your Mac's Terminal to fix a fake problem. That one paste is all it takes to invite the malware in.

This matters for everyday Mac users because the entry point isn't a technical exploit you need a patch to fix — it's a social trick that works on anyone. You visit a website, it tells you something is broken and shows you a "fix," and if you follow the instructions, your Mac is compromised. No password prompt, no warning. The malware then works its way through your system, collecting credentials and files before sending them off to servers the attackers control. Microsoft confirmed this is active exfiltration — meaning stolen data is actually leaving victims' machines, not just being cataloged for later.

Microsoft has not named a specific criminal group behind MacSync Stealer or disclosed how many victims have been affected. Watch for more details as the investigation continues. In the meantime, the best defense is awareness: if any website ever asks you to open your Mac's Terminal and paste in a command, stop immediately. That is almost never a legitimate request, and it's the most common way this kind of attack begins.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →