Threats & incidents
-
AmnesiaStealer takes control of browser sessions
A macOS infostealer distributed through fake GitHub pages can progress from password and browser theft to interactive control of authenticated Chromium sessions.
-
GE joins investigation into Cl0p campaign
GE has opened a cyber investigation as Philips confirms a contained server compromise, adding substance — but not full confirmation — to Cl0p’s claims of mass data theft through PTC enterprise software.
-
RingCentral breach data reaches 1.6m addresses
A dataset attributed to RingCentral’s July social-engineering incident contains almost 1.6 million unique email addresses, extending the known public footprint of the breach.
-
Apple spyware alerts reach 110 countries
Apple has sent a fresh wave of mercenary-spyware threat notifications across 110 countries and expanded how high-risk users are warned about targeted attacks.
-
SAP Commerce attacks follow patch by days
Attack traffic is already targeting a maximum-severity SAP Commerce Cloud vulnerability only days after SAP released fixes for the unauthenticated code-execution flaw.
-
€30m banking fraud traced to payment provider flaw
Arrests in Europe and Brazil have followed an investigation into a €30 million German banking fraud that authorities traced to exploitation of a payment provider vulnerability.
-
678,000 caught in French tax breach
France’s tax authority has confirmed the extraction of fiscal data concerning 678,000 people and businesses after attackers used impersonated credentials to access internal systems.
-
Ransomware fragments as data theft gains ground
Check Point recorded 2,139 ransomware leak-site victims in Q2 2026 as active groups reached a record 93 and smaller affiliate-driven operations gained ground.
-
Trezor customers exposed through ShipMonk breach
A breach at logistics provider ShipMonk exposed contact and shipping information belonging to 13,689 Trezor customers across the UK, Europe and other markets.
-
Dutch NCSC confirms macOS Screen Sharing attacks
The Dutch NCSC has observed attackers exploiting CVE-2026-65400 against internet-reachable Macs, gaining root access and installing cryptomining software.









