The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]

The Netherlands National Cyber Security Centre (NCSC) has issued a warning regarding active exploitation of a macOS authentication bypass vulnerability, identified as CVE-2026-65400. This vulnerability affects macOS Screen Sharing, a built-in feature that enables remote desktop control via the VNC protocol on TCP port 5900.
Apple addressed CVE-2026-65400 on August 6, 2026, with fixes included in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The flaw allowed network-based attackers to gain unauthorized access without valid credentials, potentially enabling them to remotely open applications, access files, modify security settings, and perform other actions. The update specifically improved state management to ensure proper credential validation and prevent unauthorized authentication attempts.
The NCSC's advisory was updated after the agency received reports of the vulnerability being exploited in the wild. These attacks specifically target systems where port 5900 is exposed to the internet. In the observed incidents, attackers successfully obtained root access to the compromised systems and subsequently deployed a Monero cryptocurrency miner. The NCSC did not provide details on the start date of these attacks, their full scope beyond cryptocurrency mining, or the total number of affected systems.
Users are strongly advised to update their macOS systems to one of the patched versions. For those unable to update immediately, the NCSC recommends disabling Screen Sharing through System Settings (General > Sharing > Screen Sharing) if the feature is not essential.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs