Daily Recap, Attackers are actively exploiting an unpatched GeoServer zero-day, and they rapidly expanded pressure to SAP Commerce Cloud, VMware vCenter, Adobe Commerce, and WordPress 7.0.4 soon after disclosure. Microsoft also patched the LegacyHive Windows zero-day, while RingCentral reported a likely 1.6M-account impact and Apple issued new Threat Notification alerts tied to mercenary spyware operations. #GeoServer #LegacyHive #RingCentral #SAPCommerceCloud #VMwarevCenter #AdobeCommerce #WordPress704 #AmnesiaStealer #Mirai #Akira #DGFIP #BeaconCRM #Clop #Shell #BrightlySoftware #Apple #MercenarySpyware #Ukraine #SafeMode #EDR #MiraiVariant
Exploited Flaws
- Attackers are actively exploiting an unpatched GeoServer zero-day, while fast-moving campaigns also targeted SAP Commerce Cloud, VMware vCenter RCE, Adobe Commerce, and WordPress 7.0.4 shortly after disclosure. – GeoServer Zero-Day, SAP Commerce, VMware vCenter, Adobe Commerce, WordPress RCE
- Microsoft patched a LegacyHive Windows zero-day, as defenders warned of continued rapid exploitation of newly disclosed flaws across enterprise software. – LegacyHive Patch
Data Breaches
- RingCentral said a breach likely affected 1.6 million accounts, with a separate report confirming exposure of account data tied to the same incident. – RingCentral Breach, RingCentral Exposed
- France‘s tax authority DGFIP is investigating a breach after claims of 600,000 victims, while Beacon CRM was linked to a compromise affecting more than 1,000 charities. – France Tax Breach, Beacon CRM Breach
- Shell is investigating a potential incident following Clop data-theft claims, highlighting the ongoing wave of extortion-driven breach reporting. – Shell Probe
- A former Brightly Software contractor was sentenced to 2 years in prison for stealing payroll and corporate data in a $2.5 million extortion scheme. – Insider Sentence, Brightly Case
Malware & Botnets
- AmnesiaStealer malware is targeting macOS users to steal data and take over browser sessions, adding another cross-platform credential theft threat. – AmnesiaStealer
- A new Mirai variant adds stealth features to the notorious botnet code, signaling continued evolution of IoT malware. – Mirai Variant
- Akira operators used Safe Mode to disable EDR, steal data, and then fail to encrypt systems in a disrupted attack. – Akira Attack
Threats & Policy
- Apple issued new Threat Notification alerts for users believed to be targeted by mercenary spyware, underscoring ongoing high-end surveillance operations. – Apple Alerts
- Ukraine shut down 94 fraudulent call centers and seized millions in cash, while hackers also breached government webmail amid parallel crypto fraud activity. – Ukraine Raids, Govt Webmail
- Experts remain split on a Trump memo that could reshape private-sector hacking policy and government offensive-cyber coordination. – Trump Memo
Industry & Research
- Google Cloud outlined a post-quantum roadmap with a 2029 readiness goal, as the industry continues preparing for cryptographic transitions. – PQ Roadmap
- Researchers said mid-tier AI models have become much better at hacking, while dubious AI watermark removers are proliferating with little proof they work. – AI Hacking, Watermark Tools
- Rapid7 layoffs and other sector updates were highlighted alongside reports on hacking a Boeing 737 and refrigeration system vulnerabilities. – Industry Notes
- Cybersecurity M&A remained active, with 21 deals announced in July 2026. – M&A Roundup
- Flock tightened privacy controls amid backlash over officer-abuse scandals and audit-assistance concerns. – Flock Controls
- Trivy, not LiteLLM, was identified as the source of the compromise affecting 2,500 organizations. – Trivy Cause