|
🔓 McDonald's staff records sold by hacker
LINK
|
- A seller on a data-trading forum is offering what they claim are 1.7 million McDonald's employee records, allegedly pulled from the company's Azure tenant using stolen login credentials.
- The seller, TheHatman, posted an 8,000-row sample whose column names like FacsimileTelephoneNumber match Microsoft's Entra ID export output, with genuine McDonald's email domains, the internal mcdonaldscorp.onmicrosoft.com address, and encoding damage consistent with a real Export-Csv run without UTF-8.
- The sample contains no passwords or hashes, so the risk is social engineering from full names, job titles, phone numbers, and internal email formats; the report advises treating unsolicited contact that knows your role with suspicion and confirming instructions out-of-band.
|
🍎 macOS flaw lets hackers hijack Macs
LINK
|
- Hackers are breaking into internet-exposed Macs through an authentication bypass in macOS Screen Sharing, tracked as CVE-2026-65400, that CISA rescored on August 14 from 7.1 to critical (CVSS 9.8) and now calls automatable.
- The flaw lets an attacker on the network authenticate to Screen Sharing on TCP port 5900 without valid credentials thanks to faulty state management, and in every case reported to NCSC-NL attackers gained root and installed a Monero cryptocurrency miner.
- Apple patched the bug on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, but with public proof-of-concept code available, users who can't update can disable Screen Sharing under System Settings > General > Sharing.
|
🇫🇷 France tax hack exposes 678,000 taxpayers
LINK
|
- France's tax agency confirmed that hackers stole data on 678,000 taxpayers, including private individuals and businesses, in a cyberattack that officials described as more complex than anything they had faced before.
- The Directorate-General for Public Finances (DGFiP) said stolen data includes income figures, tax rates, and family circumstances, but does not grant access to secure accounts on impots.gouv.fr; for businesses, exposed data covered SIREN registration numbers and business addresses.
- Authorities disclosed no technical details on how attackers broke in or their motivation; the Paris Public Prosecutor's cybercrime unit and OFAC are investigating, and affected taxpayers will be notified from Monday about identity theft and fraud risks.
|
🤖 New botnet hijacks routers as proxies
LINK
|
- A new Mirai-based Linux botnet called Evooo1Bot is hijacking internet-facing gateway devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, turning them into SOCKS5 relay nodes to hide the attackers' traffic.
- Active since at least July, the malware breaks in by exploiting known vulnerabilities in these devices, though Fortinet found some embedded exploits are wrongly implemented and fail, then downloads one of 12 builds matching the CPU architecture and clears Bash history.
- Beyond proxying, Evooo1Bot steals logins via a sniffer capturing HTTP Basic Authentication and Cookie headers, brute-forces SSH using 150 enterprise username-password combinations, and launches DDoS attacks with 16 flood methods including UDP, DNS, SYN, and HTTP floods.
|
🛒 SAP Commerce Cloud flaw actively exploited
LINK
|
- Attackers are actively exploiting a maximum severity (CVSS 10.0) flaw in SAP Commerce Cloud that lets them break in and run code remotely without any login, just days after SAP shipped a fix in its August 2026 Patch Day.
- The bug, tracked as CVE-2026-58231, stems from an improper authorization weakness in the platform's core Data Hub Adapter extension, where an attacker abuses a default authentication client and sends crafted input to functions that lack sufficient validation.
- Threat intelligence firm Defused detected exploitation attempts against its honeypots three days after the patch despite no known public proof-of-concept, and SAP, now investigating, urges affected organizations to apply the latest security updates.
|
|