CVE

Apple
2026-08-08 15:16:33

macOS screen sharing flaw let attackers log into Macs without a password on the same network

Apple patched a serious macOS screen sharing authentication flaw, tracked as CVE-2026-65400, on Aug. 6. According to Apple’s security advisory, if Screen Sharing was enabled on a Mac, an attacker on the same network could log in without valid credentials. The bug was tied to the screensharingd service, which reportedly mishandled Secure Remote Password, or SRP, authentication and returned an outdated success state, causing an unauthenticated connection to be treated as authenticated. The report said that meant an attacker needed neither a valid macOS account nor an old VNC password to log in as any user. A proof of concept published by security researchers went further, showing the issue could be used to read and write files, execute code remotely with root privileges, and establish persistence through LaunchDaemons or shell startup files. The vulnerability was reported by Alfredo Pesoli through Bynario Atlas. Apple said it has no evidence of active exploitation so far. For crypto users who store private keys, seed phrases, or software wallets on a Mac, the risk is acute because a compromised endpoint can expose wallet data regardless of local password protections. Apple has released fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

210
macOS screen sharing flaw let attackers log into Macs without a password on the same network
macOS
2026-08-08 14:34:27

Critical macOS screen sharing flaw allows passwordless remote login; Apple fixes it in version 26.6.1

A critical security flaw in macOS screen sharing could let a network attacker log into a Mac with any account without knowing the password, according to a disclosure by security researcher Calif tracked by Dongcha Beating. The bug, assigned CVE-2026-65400, affects systems with screen sharing enabled and was described as a form of unauthenticated remote code execution that can give an attacker full desktop control. Calif said the root cause and exploitation method were identified after reverse-engineering Apple’s macOS 26.6.1 patch, and proof-of-concept code has already been released. Apple has fixed the issue in macOS 26.6.1 and users are advised to update as soon as possible. While there is no evidence so far of broad exploitation in real-world environments, the public release of PoC code is raising the risk for unpatched machines. For users who cannot update right away, turning off screen sharing is cited as a temporary mitigation until the patch can be installed.

610
Critical macOS screen sharing flaw allows passwordless remote login; Apple fixes it in version 26.6.1
cryptocurrenc
2026-08-04 07:39:03

Crypto firms race for Anthropic Mythos access as Binance says it still hasn’t received the model

A new arms race is taking shape in crypto, but it is not about building frontier AI models in-house. It is about getting access to them first. According to a CoinTelegraph report published on Aug. 4, only a small number of crypto companies have secured access to Anthropic’s restricted Claude Mythos model, while major players including Binance, Fireblocks and the Ethereum Foundation are still waiting or have not disclosed equivalent access. Coinbase said in June that it had obtained Mythos, and Zcash founder Zooko Wilcox said Anthropic used the model to audit the Zcash protocol for Shielded Labs. At the same time, AI-assisted attacks are no longer theoretical. Data cited from Epoch AI showed a rise in severe CVE vulnerabilities after Mythos launched, while recent incidents involving Boltz and Coinkite added urgency to the debate. Security leaders across the industry are now arguing over whether the approval process for high-end defensive models should be streamlined so legitimate defenders can use them before attackers widen the gap.

600
Crypto firms race for Anthropic Mythos access as Binance says it still hasn’t received the model
CertiK
2026-07-30 08:40:00

CertiK flags Google EdgeTPU flaws as AI security shifts beyond the model layer

CertiK researchers said they found two security flaws in Google’s EdgeTPU, tracked as CVE-2026-0150 and CVE-2026-0153. Google acknowledged the findings and listed them in its June 2026 Security Bulletin, rating the bugs High and Critical. Beyond the disclosure itself, the research points to a broader shift in how companies need to think about AI security. The report argues that as AI systems move from generating content to carrying out tasks, the security focus can no longer stay limited to model behavior alone. Enterprises are now deploying AI across identity verification, facial recognition, edge inference and other business-critical functions, while AI agents are increasingly connecting to databases, APIs and third-party tools. In that setting, risk can emerge not only inside a model, but across the interfaces and trust relationships that link infrastructure, applications and external systems. CertiK also ties this change to a wider industry trend. It cites McKinsey’s “The state of AI in 2025,” which says 88% of companies have deployed AI in at least one business function and more than 60% have begun exploring AI agents. A separate Google Cloud survey found 83% of respondents believe major infrastructure upgrades are needed to support AI agents at scale. The company says the practical implication is clear: securing AI now means validating the full system, from development and deployment to runtime operations.

670
CertiK flags Google EdgeTPU flaws as AI security shifts beyond the model layer
Web3 Security
2026-07-27 10:02:00

Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people

Web3 recorded 182 publicly disclosed security incidents in the first half of 2026, with total losses reaching about $956 million, according to reports released by OKX Web3’s security team, SlowMist and OtterSec. The headline loss figure was down nearly 60% from a year earlier, but the decline mostly reflected the absence of a repeat of Bybit’s roughly $1.5 billion 2025 outlier. Incident count actually rose to 182 from 121, up about 50% year over year. The reports point to a structural shift in how attacks are carried out. The largest losses increasingly came from outside audited smart contracts and instead hit signing flows, cloud keys, validation paths, developer devices and users themselves. Examples cited in the reports include the roughly $285 million Drift Protocol attack, a months-long social engineering campaign centered on pre-signed transactions, and a Singapore case in which AI-generated officials appeared in a fake video conference, leading to losses of about S$4.9 million. Recovery remains rare. SlowMist said only 18 incidents in H1 resulted in stolen funds being recovered or frozen, totaling about $118 million, or 12.3% of overall losses. The rest, nearly 90%, was effectively gone. The reports also describe supply-chain poisoning, AI-assisted phishing, malicious browser extensions, recruiter scams and increasingly industrialized laundering routes involving privacy tools, cross-chain channels and OTC off-ramps.

750
Nearly 90% of stolen crypto funds were unrecoverable in H1 2026 as Web3 attacks shifted from code to people