Security Affairs

Security Affairs Read, think, share … Security is everyone’s responsibility

  • Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
    by Pierluigi Paganini on August 15, 2026 at 5:48 pm

    Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they

  • SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
    by Pierluigi Paganini on August 15, 2026 at 5:14 pm

    Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.

  • macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
    by Pierluigi Paganini on August 15, 2026 at 8:34 am

    Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less than two weeks after Apple shipped the fix. The

  • GeoServer Zero-Day Is Already Being Probed. That’s the Problem
    by Pierluigi Paganini on August 15, 2026 at 7:18 am

    GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability

  • Apple warned hundreds of users of mercenary spyware attacks
    by Pierluigi Paganini on August 14, 2026 at 5:09 pm

    Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already

  • AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
    by Pierluigi Paganini on August 14, 2026 at 8:43 am

    AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser. Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-stage Rust-based macOS infostealer that spread through a counterfeit GitHub download page using the ClickFix technique. The lure looks convincing: correct GitHub dark theme, Octocat logo,

  • Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
    by Pierluigi Paganini on August 14, 2026 at 8:24 am

    7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak

  • US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
    by Pierluigi Paganini on August 14, 2026 at 7:14 am

    Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the

  • Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
    by Pierluigi Paganini on August 13, 2026 at 5:48 pm

    Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data. Cybersecurity firm

  • U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
    by Pierluigi Paganini on August 13, 2026 at 5:12 pm

    U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software that could allow unauthenticated,

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.