Info
2026-08-14 18:09Z · last 4h · 19 findings
· glm-5.2:cloud
Threat Brief — 2026-08-14 — Active macOS Exploitation, Widening Scottish Breach
Executive summary. A macOS Screen Sharing authentication bypass is now actively exploited in the wild to deploy Monero miners, with public exploit code circulating — Dutch NCSC has issued an alert. Scotland's prosecutor's office disclosed a third-party data breach that may extend to other government agencies serviced by the same vendor. Mozilla's Firefox/Thunderbird GPG signing key exposure (first reported Aug 12) continues to see coverage but no new technical developments. A batch of MSRC CVE acknowledgement updates includes one notable reclassification: CVE-2026-48566 (Windows DWM Core) was upgraded from Information Disclosure to Elevation of Privilege.
Top items
- macOS Screen Sharing auth bypass actively exploited for Monero mining. The Netherlands' NCSC warns that attackers are exploiting a macOS authentication bypass vulnerability after public exploit code surfaced. Active in-the-wild exploitation with miner deployment makes this the most urgent item today. If you manage macOS fleets, audit Screen Sharing exposure immediately. (src: BleepingComputer)
- Scottish prosecutor's office data breach may widen to other agencies. A third-party vendor servicing Scotland's prosecutor's office suffered a breach, and the same vendor may have serviced other Caledonian government agencies — raising the possibility of broader exposure across Scottish government. (src: Dark Reading)
- MSRC reclassifies CVE-2026-48566 from Information Disclosure to Elevation of Privilege. Microsoft updated the impact of this Windows DWM Core Library vulnerability — a step up in severity class. A dozen other August Patch Tuesday CVEs received acknowledgement updates only (Speech Runtime, DHCP Client, Win32k, Event Logging, Remote Access API, Package Manager, NTFS, License Manager). These are administrative updates to the already-reported August Patch Tuesday batch. (src: MSRC)
- ZachXBT exposes $5M wallet scammer who recorded victim calls and posted them online. A cryptocurrency scammer who stole $5M from dozens of wallets was identified after publishing recorded conversations with victims — a self-incriminating blunder. Low direct infrastructure risk but relevant to social-engineering awareness. (src: SecurityLab)
- Brave enables GPU-level anti-fingerprinting by default on desktop and Android. Brave closed a long-standing tracking loophole in graphics card fingerprinting, enabled by default. Relevant if your organization uses Brave as a managed browser or tracks fingerprinting defenses. (src: SecurityLab)
- Google Workspace attack chains increasingly bypass phishing via stolen OAuth tokens. Material Security analysis highlights that Workspace compromises don't always start with phishing — stolen OAuth tokens provide direct access to Gmail, Drive, and connected systems. Worth reviewing OAuth token hygiene and third-party app consent policies. (src: BleepingComputer)
- Google reports Chrome spam-fighting results: notifications cut by a quarter, 7B fewer alerts. Google shared metrics on its battle against notification spam in Chrome on Android. Defensive-tooling news, no direct threat action required. (src: SecurityLab)
Themes
- Third-party supply-chain risk persists in government. The Scottish prosecutor breach traces to a shared third-party vendor — echoing the same pattern seen in enterprise breaches (Trezor/ShipMonk, RingCentral). Vendor concentration risk remains a top-tier exposure.
- Public exploit code accelerates active exploitation. The macOS Screen Sharing flaw moved from disclosure to active Monero-miner deployment after PoC code went public — reinforcing the shrinking window between disclosure and mass exploitation.
