Hackers arrested over €30M bank fraud exploiting service provider flaw
2026-08-14T19:23:22Z•8d93f37f505b8935f553563fc0c2239f34b3e7d0b30bca19bbc9e3a9ec7d5ade
CVE-2026-59310AkiraClopEDR evasionGoogle WorkspaceOAuth token theftSAP Commerce CloudShinyHuntersVMware vCenteractive exploitationauthentication bypasscryptominingdata breachextortionfinancial fraudmacOSmercenary spywareransomwareremote code executionreverse SSHthird-party compromisezero-day
What happened
BleepingComputer security feed reporting active exploitation of critical vulnerabilities, ransomware and data theft, cloud and identity attacks, spyware targeting, financial fraud, and major third-party data breaches. Notable items include exploitation of VMware vCenter Syslog Server CVE-2026-59310 for reverse SSH persistence, a maximum-severity SAP Commerce Cloud RCE under attack, exploitation of a macOS Screen Sharing authentication bypass to deploy Monero miners, Akira affiliates disabling EDR via Safe Mode, and Windows LegacyHive zero-day patching. The feed also documents Clop and ShinyHun
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8d93f37f505b8935f553563fc0c2239f34b3e7d0b30bca19bbc9e3a9ec7d5ade
- Enrichment time
- 2026-08-14T19:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.