Hackers arrested over €30M bank fraud exploiting service provider flaw

2026-08-14T19:23:22Z8d93f37f505b8935f553563fc0c2239f34b3e7d0b30bca19bbc9e3a9ec7d5ade
CVE-2026-59310AkiraClopEDR evasionGoogle WorkspaceOAuth token theftSAP Commerce CloudShinyHuntersVMware vCenteractive exploitationauthentication bypasscryptominingdata breachextortionfinancial fraudmacOSmercenary spywareransomwareremote code executionreverse SSHthird-party compromisezero-day

What happened

BleepingComputer security feed reporting active exploitation of critical vulnerabilities, ransomware and data theft, cloud and identity attacks, spyware targeting, financial fraud, and major third-party data breaches. Notable items include exploitation of VMware vCenter Syslog Server CVE-2026-59310 for reverse SSH persistence, a maximum-severity SAP Commerce Cloud RCE under attack, exploitation of a macOS Screen Sharing authentication bypass to deploy Monero miners, Akira affiliates disabling EDR via Safe Mode, and Windows LegacyHive zero-day patching. The feed also documents Clop and ShinyHun

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8d93f37f505b8935f553563fc0c2239f34b3e7d0b30bca19bbc9e3a9ec7d5ade
Enrichment time
2026-08-14T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.