Script
Here is today's Cybersecurity Brief for Friday August 14th. A newly disclosed, unpatched GeoServer zero-day is already drawing active exploitation attempts. The SQL-injection flaw can potentially lead to remote code execution on the open-source geospatial platform. Researchers say attackers began probing internet-exposed systems within hours of public disclosure on Wednesday. Organizations using GeoServer should immediately identify exposed instances, restrict public access where possible, monitor logs for suspicious requests and database errors, and prepare to apply a vendor fix as soon as one becomes available. [1]
Apple has issued a new round of mercenary-spyware threat notifications to users in 110 countries. The company did not name a specific spyware vendor or attacker, but said these exceptionally sophisticated operations typically target people because of their work or identity, including journalists, activists, diplomats, and political figures. Recipients should treat an Apple notification as urgent: update devices, preserve evidence, seek specialized support, and avoid assuming a factory reset alone fully resolves the risk. [2]
Researchers have also identified more than 3,000 recruitment-themed phishing URLs in a campaign dubbed RecruitTrap. The operation impersonates recruiters and interview scheduling processes at more than 50 organizations. Its fake login windows use Browser-in-the-Browser techniques to make credential prompts appear legitimate, and some attacks relay multi-factor-authentication prompts in real time. Marketing professionals appear to be a major target, likely because their accounts can reach advertising platforms, social channels, customer data, and corporate email. Verify interview links independently, and use phishing-resistant authentication where available. [3]
Finally, a new White House memo directs the National Coordination Center to develop a program under which vetted U.S. companies could conduct federally authorized surveillance or disruptive cyber operations against foreign criminal groups. The proposal raises substantial oversight and attribution questions, but it signals a policy shift toward using private-sector offensive capability against transnational cybercrime. [4]
The common thread is that identity remains the primary battlefield: stolen credentials, high-value professional accounts, targeted spyware, and even government-backed disruption all center on who can access systems and who can be trusted. Thank you for listening to Cybersecurity Brief from The Daily FM. See you tomorrow! [5]
- The Hacker News | #1 Trusted Source for Cybersecurity News
...d @q1uf3ng on X. "GeoServer jsonArrayContains unauthorized SQL injection, and in the case of the sa [system administrator] database, it's naturally possible to achieve RCE," the researcher said. The threat intelligence and exposure management platform said it began to observe exploitation attempts within hours of public disclosure, and that it has seen hundreds of attempts originating from a small pool of IP addresses. "Currently, we're seeing attackers probe to identify vulnerable systems across the internet, triggering errors and not proceeding further," Jake Knot... ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories Aug 13, 2026 Hacking News / Cybersecurity News Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud se...
- The Hacker News | #1 Trusted Source for Cybersecurity News
...ted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021. "The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today," the tech giant said . "As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions." Typically, such notifications are sent to people who may have been individually targeted because of "who they are or what they do," including journalists, activists, politicians, and diplomats. They tend to focus on a very small number of speci... AI Is Flooding Security with Bugs Nobody ProvedSANSVulnerability / Artificial intelligenceStephen Sims on why unproven AI f...
- The Hacker News | #1 Trusted Source for Cybersecurity News
...ages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap , said it identified more than 3,000+ phishing URLs over two months. The campaign impersonated real recruiters and recruitment processes associated with more than 50 organizations across 14 sectors . Marketing professionals accounted for the majority of observed targets. The focus on marketing roles appears deliberate. Compromised marketing accounts can provide access to advertising platforms, corporate social media profiles, customer data, email, and other business-critical services. Read the full report here: https://www.ctm360.com/reports/recruittrap-browser-in-the-browser-bitb-recruitment-scam... Apple Warns Users in...
- The Hacker News | #1 Trusted Source for Cybersecurity News
...ion Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens," the memo reads . To that end, the NCC has been tasked with setting up a program that allows authorized companies to conduct two types of operations against TCOs upon obtaining approval: cyber surveillance operations, which can access sensitive data without authorization from the owner or operator, and cyber effects operations, which can result in disruption, denial, degradation, or destr......
- The Hacker News | #1 Trusted Source for Cybersecurity News
...to Expose Them Before Hiring Aug 13, 2026 Cyber Espionage / Threat Intelligence Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. For CISOs, the priority is clear: spot the warning signs before a fraudulent hire becomes trusted access. When the Threat Gets Hired A recent joint investigation by Mauro Eldritch ( BCA LTD ), Heiner García ( NorthScan ), and ANY.RUN showed what this looks like from inside the operation. Researchers deliberately hired suspected DPRK developers linked to Lazarus Group and gave...