Max severity SAP Commerce Cloud flaw now targeted in attacks

A Critical SAP Commerce Cloud Flaw is Being Exploited Just Three Days After Patch Release A maximum-severity vulnerability in SAP’s Commerce Cloud e-commerce platform, patched just three days ago, has already been targeted by attackers. The critical flaw, tracked as CVE-2026-58231, allows unauthenticated attackers to execute arbitrary code with ease, compromising the confidentiality, integrity, and … Read more

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Cybersecurity Threats Evolve: How Attackers Are Exploiting Google Workspace Vulnerabilities A recent spate of high-profile breaches has exposed a concerning trend in cybersecurity threats. Over the past two months, several prominent companies, including Vercel and Composio, have fallen victim to sophisticated attacks that have left security experts scratching their heads. What’s striking about these incidents … Read more

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

A Severe macOS Vulnerability is Being Exploited by Hackers to Deploy Cryptocurrency Miners A critical vulnerability in Apple’s macOS operating system has been discovered and is being actively exploited by hackers. The flaw, which affects Screen Sharing, a built-in remote desktop feature, allows attackers to gain unauthorized access to user systems without valid credentials. What’s … Read more

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

A trio of disturbing developments in the world of cybersecurity has left experts and security-conscious individuals alike on high alert. The convergence of vulnerabilities in commercial refrigeration systems, unauthorized access to a major logistics company’s systems, and a demonstration of how easily a Boeing 737 can be hacked is a stark reminder that no industry … Read more

Cyera’s Oasis Security Buy is All About AI Agent Control

Cyera’s $1 Billion Acquisition of Oasis Security Aims to Revolutionize AI Agent Management In a major move to tackle the growing problem of non-human identities (NHI) in cybersecurity, Cyera has announced plans to acquire Oasis Security for approximately $1 billion. This deal marks another significant consolidation in the industry, as companies seek to bolster their … Read more

RingCentral data breach exposed info of 1.6 million accounts

A massive data breach at RingCentral, a popular cloud-based collaboration and communication platform used by over 600,000 businesses, has exposed the personal information of an astonishing 1.6 million accounts. The ShinyHunters extortion group is behind the hack, which was made possible through a “sophisticated social engineering campaign” that compromised RingCentral’s systems in July. The breach … Read more

Shell investigates ‘potential incident’ after Clop data theft claims

Oil Giant Shell Investigates Potential Data Breach Amid Ransomware Claims Shell, one of the world’s largest oil and gas companies, is currently investigating a potential security incident after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive data. The alleged heist includes engineering drawings, facility testing reports, project plans, and other confidential … Read more

Who’s Tracking You? Use This New Service to Find Out

The Dark World of Adtech: New Service Sheds Light on Who’s Tracking You A new free service called DecryptAds has launched, making it easier for anyone to uncover who’s tracking them online. By scraping and correlating publicly available data from websites and apps, DecryptAds reveals the complex web of companies involved in adtech, including those … Read more

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Government AI platform deal sparks outrage over prioritizing traditional consulting model The Defense Department’s recent award of an $821 million contract to Accenture Federal Services for its War Data Platform (WDP) has drawn criticism for allegedly undermining goals to rapidly adopt commercial AI. The WDP, a restructuring of the former Advana program, aims to provide … Read more

Data analyst sent to prison for stealing data, extorting employer

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for orchestrating a $2.5 million extortion scheme targeting his employer. Cameron Curry, also known as “Loot,” was found guilty in March of stealing sensitive documents and using them to blackmail Brightly after learning that his six-month contract wouldn’t be … Read more