Apple warned hundreds of users of mercenary spyware attacks
2026-08-14T20:51:36Z•cab089526116a96e71ad0722dce55849d6d197fc72361a59e78918f5b372d80d
CVE-2026-20349CVE-2026-55040CVE-2026-71362Adobe CommerceAmnesiaStealerAppleCISA KEVCisco Secure FirewallClickFixLazarus GroupMetabaseNorth KoreaOperation Dream JobSharePointStorm-1175StormEncryptorWindowsactive exploitationbrowser credential theftdata breachdata scrapinginfostealerlogistics disruptionmacOSmercenary spywareransomwaresupply chainzero-day
What happened
Security Affairs reports multiple active and emerging threats, including targeted mercenary spyware notifications affecting users in 110 countries, the AmnesiaStealer macOS infostealer distributed through fake GitHub pages, large-scale Chess.com data scraping, active exploitation of critical Adobe Commerce CVE-2026-71362 and SharePoint CVE-2026-55040, CISA KEV additions affecting Cisco, Windows, and Metabase, Storm-1175’s StormEncryptor ransomware, a North Korean Lazarus campaign using a Windows zero-day, and a cyberattack disrupting CEVA Logistics operations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cab089526116a96e71ad0722dce55849d6d197fc72361a59e78918f5b372d80d
- Enrichment time
- 2026-08-14T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.