Here are today’s top cybersecurity stories for Friday, August 14, 2026.
Shell Investigates Potential Data Theft After Clop Claims Tied to PTC Windchill Flaw
Shell confirmed it is investigating a potential security incident after the Clop ransomware group listed the company among roughly 50 organizations targeted through exploitation of a critical flaw in PTC Windchill and FlexPLM software, tracked as CVE-2026-12569. Clop’s leak site lists engineering drawings, facility testing reports, photos, and project plans as stolen from Shell. General Electric and Philips also confirmed investigations into the same campaign. BleepingComputer
RingCentral Data Breach Exposes 1.6 Million Accounts
The ShinyHunters extortion group published a 280GB archive of data stolen from business communications platform RingCentral, exposing names, email addresses, phone numbers, and physical addresses for 1.6 million accounts. RingCentral disclosed the breach on July 28 following a social engineering attack against its systems and says the core platform remained unaffected. The company reports no new unauthorized activity since containment. BleepingComputer | SecurityWeek
Apple Sends Mercenary Spyware Threat Notifications to Users in 110 Countries
Apple issued a new round of Threat Notification alerts on August 13, warning targeted iPhone users in 110 countries of a possible mercenary spyware attack against their devices. The alerts are reserved for cases where Apple’s threat intelligence identifies a well-funded surveillance operation targeting specific individuals, and have now reached users in more than 150 countries since the program began in 2021. Apple did not name the spyware vendors or victims involved. The Hacker News | BleepingComputer
Unpatched GeoServer Zero-Day Under Active Exploitation
Researchers at watchTowr report active exploitation attempts against an unpatched SQL injection flaw in the open-source geospatial platform GeoServer, first disclosed publicly on August 12. The vulnerability affects the jsonArrayContains filter function and, under certain configurations, leads to remote code execution. No CVE identifier or vendor patch is available, and observed attempts so far appear to be scans probing for vulnerable instances rather than confirmed payload delivery. The Hacker News | SecurityWeek
Zoom Patches Zero-Click Flaw Letting Meeting Participants Hijack Other Devices
Zoom patched three vulnerabilities in its meeting client’s annotation function, the most severe of which, CVE-2026-53413, allowed a meeting participant to execute code on another participant’s device without any interaction from the target. Researchers at A Security dubbed the flaw “Zoomsday” and said they found and weaponized it using publicly available AI models in under 24 hours. Zoom rated the bug high severity with a CVSS score of 8.3 and shipped fixes across its Workplace, Rooms, and Meeting SDK clients on August 11. SecurityWeek
Trezor Discloses Data Breach at Shipping Partner ShipMonk Affecting Nearly 14,000 Customers
Hardware wallet maker Trezor disclosed a data breach at third-party shipping provider ShipMonk affecting 13,689 customers who placed orders between May 10 and August 8. ShipMonk told Trezor the attacker exploited a flaw in the third-party analytics platform Metabase to gain unauthorized access on August 6. Exposed data includes names, email addresses, phone numbers, and shipping addresses, and Trezor is warning affected customers about follow-on phishing risk. BleepingComputer
New AmnesiaStealer macOS Malware Gives Attackers Live Control of Browser Sessions
Jamf Threat Labs identified a new Rust-based macOS infostealer named AmnesiaStealer, spread through a fake GitHub download page using the ClickFix technique to trick users into pasting a malicious Terminal command. Beyond harvesting Keychain data, browser credentials, and Telegram data, the malware includes a module giving an attacker live, interactive control of the victim’s browser session. Jamf notes the same fake GitHub lure infrastructure has appeared in Atomic Stealer and MacSync campaigns. SecurityWeek | The Hacker News
Former Contractor Sentenced to Two Years for Extorting Siemens Subsidiary Brightly Software
Cameron Curry, a 27-year-old former data analyst contractor for Brightly Software, was sentenced to two years in prison for stealing employee compensation data and threatening to release it unless the company paid $2.5 million. Curry sent more than 60 threatening emails over six weeks in late 2023 and early 2024 and ultimately extorted $7,540.92 before being caught. He was convicted on six counts of extortion in March. CyberScoop | BleepingComputer
Ukrainian Police Raid 94 Fraudulent Call Centers, Seize $2 Million
Ukrainian police disrupted 94 fraudulent call center operations in a nationwide sweep involving more than 400 searches, seizing computers, phones, SIM cards, and roughly $2 million in assets. Investigators say the operations impersonated bank employees and investment platforms and pushed victims toward fraudulent cryptocurrency schemes and remote-access scams. Help Net Security
Stay tuned for today’s in-depth analysis posts.






