Daily brief at 7am Melbourne. Unsubscribe any time.

Saturday 15 August 2026

The Mac Bug That Lets Strangers Log In Without a Password — And It's Being Exploited Right Now

A critical macOS screen-sharing bug is under active exploitation, a GeoServer zero-day is being weaponised in the wild, and OpenAI is now keylogging your desktop — welcome to Saturday.

Lead story

The Mac Bug That Lets Strangers Log In Without a Password — And It's Being Exploited Right Now

Apple has a serious problem. A vulnerability in macOS's screen-sharing subsystem is under active exploitation, allowing remote attackers to log in to a target machine without providing a password. No phishing required. No credential theft. Just a network path and a bug.

The flaw sits in the Remote Desktop / screen-sharing stack — a component that many Mac users leave enabled for IT support, remote work, or network administration. When it's on and the bug is present, an unauthenticated attacker who can reach the machine over the network can gain full control. Ars Technica, which broke the story, describes it as giving attackers "full control of Macs."

What makes this particularly nasty is the combination of factors: macOS has a reputation — sometimes deserved, sometimes not — for being "more secure" than Windows, which means a meaningful proportion of users have a false sense of comfort. Remote Desktop is on by default in some enterprise and education configurations. And active exploitation means this isn't a theoretical risk — someone is already using it.

The timing matters too. It's a Saturday in August, the tail end of northern hemisphere summer. Security teams are thin. Patch deployment is slower on weekends. Threat actors know this.

What you should do right now: If you're a Mac user with Screen Sharing or Remote Desktop enabled — check System Settings → General → Sharing. Turn off anything you don't actively need. Apply Apple's patch the moment it appears in Software Update if you haven't already. If you're running a fleet of Macs in an organisation, treat this as P1 until patched.

For Australian organisations, this is especially relevant in education and creative industries, where Mac deployments are dense. University IT teams in particular should be checking their remote-access configurations this weekend rather than waiting until Monday. Under the Privacy Act and relevant state government ICT security frameworks, any incident involving unauthorised access to systems carrying personal data triggers mandatory assessment obligations.

The broader pattern is worth noting. Three of the last four weeks have featured a critical, actively-exploited vulnerability in a major consumer platform — Linux containers, Zoom, and now macOS. The pace of exploitation following disclosure (or, worse, before it) is accelerating. Defenders are being asked to move faster than ever on patch cycles, and the window between "bug discovered" and "bug weaponised" continues to shrink.

Watch for Apple's security advisory, which should detail the CVE and affected macOS versions. If your organisation uses any MDM solution — Jamf, Mosyle, Microsoft Intune for Mac — get that patch into your deployment pipeline the moment Apple releases it. Don't wait for the weekly maintenance window.

Also today

GeoServer Zero-Day Under Active Attack — Patch Doesn't Exist Yet

Attackers are actively exploiting an unpatched SQL injection vulnerability in GeoServer, the widely-used open-source geospatial server. The flaw can be leveraged to achieve remote code execution, meaning a successful attacker can run arbitrary commands on affected systems. GeoServer is deployed across government, utilities, logistics, and environmental monitoring — sectors that handle sensitive spatial data. There's no patch available yet, so defenders are in the uncomfortable position of either isolating instances, restricting network access, or accepting risk. GeoServer has a substantial footprint in Australian state and federal government mapping and land-information systems, making this particularly relevant locally. ACSC advisories are worth watching for guidance.

SecurityWeek

ShinyHunters Dumps 1.6 Million RingCentral Records After Extortion Fails

The prolific ShinyHunters group has published data allegedly stolen from RingCentral after an extortion attempt went nowhere. The dumped records cover roughly 1.6 million accounts and include names, addresses, email addresses, and phone numbers — the standard kit for follow-on phishing and identity fraud. RingCentral is a major cloud communications platform used by businesses globally, including a significant number of Australian enterprises. If your organisation uses RingCentral, it's worth treating any inbound communications referencing account issues with heightened suspicion in the coming weeks, and checking whether corporate email addresses appear in the dump via breach-notification services.

The Register

France's Tax Authority Confirms Breach — 2 Million Records in Play

France's Directorate General of Public Finances (DGFiP) has confirmed it was breached in late June after a threat actor claimed to be selling data on roughly 2 million taxpayers. The attacker appears to have gained access by misusing or stealing a legitimate identity — a credential-based intrusion rather than a technical exploit. French authorities are disputing claims that the attacker still has live access. The incident is a reminder that tax authorities, which hold extraordinarily sensitive financial and identity data, remain high-value targets. Australia's ATO operates at similar scale and sensitivity; the ACSC has previously flagged ATO-impersonation as a major phishing vector.

The Record

Trivy Misconfiguration — Not LiteLLM — Behind the 2,500-Org Supply Chain Compromise

New analysis of the supply chain compromise that hit over 2,500 organisations has overturned the initial attribution. The culprit wasn't the malicious LiteLLM packages that made headlines — more than 95% of affected organisations were already exposed before those packages were ever published. The real vector was misconfigured Trivy container-scanning instances leaking secrets. It's a sobering finding: defenders were watching the wrong threat. Trivy is widely deployed in CI/CD pipelines as a security tool, which makes this a particularly painful irony. Any organisation running Trivy should audit whether scan results or credentials are being inadvertently exposed through misconfigured outputs or dashboards.

SecurityWeek

OpenAI Swaps Screenshots for Keylogging in Its 'Computer History' Feature

OpenAI has quietly pivoted its desktop memory feature away from Recall-style continuous screenshots and towards recording keystrokes and mouse clicks to build persistent ChatGPT memories. The company is calling it 'Computer History.' The rebranding from screenshots to keylogging may feel like a lateral move to privacy advocates — both approaches hoover up highly sensitive behavioural data, just in different formats. The feature is opt-in for now, but the direction of travel is clear: AI assistants that know everything you type. For Australian users, this intersects with the Privacy Act's collection-minimisation principles and is worth watching as the government consults on its AI and privacy reform agenda.

The Register

OpenAI and Anthropic Are in a Price War — Chinese AI Is Why

OpenAI and Anthropic have both cut model prices and released cheaper tiers in what's shaping up as a full-scale price war with Chinese AI competitors. Chinese labs — benefiting from lower infrastructure costs and, in some cases, state backing — have been undercutting US frontier model pricing by significant margins, forcing American labs to respond. The dynamic is compressing the revenue runway that both companies need to fund their next-generation model development, which is expensive. The strategic question is whether the price floor in AI inference is being set by labs that don't need to be profitable — and what that means for the long-term competitive landscape.

Ars Technica

Schneier and Sanders: Nationalise OpenAI and Anthropic If Markets Won't Fund Them

Bruce Schneier and Nathan Sanders have published a provocative op-ed in The Guardian arguing that if OpenAI and Anthropic fail to attract sustainable commercial funding, the US government should nationalise them rather than let them be acquired by or subsumed into big tech. Their core argument: both labs were founded explicitly to prevent concentrated corporate control of transformative AI, but each has since drifted towards conventional commercial structures that undermine that founding mission. Public ownership, they argue, might be the only mechanism that preserves genuine independence. It's a deliberately uncomfortable proposal — and worth reading on its merits rather than as a provocation.

Schneier on Security

Meta Patents AI Glasses That Identify Strangers by Face and Cut Dinner-Party Highlight Reels

A newly published Meta patent describes AI-enabled glasses that use real-time facial recognition to identify people in the wearer's field of view, then automatically assemble highlight reels of social occasions. It's a significant step beyond the existing Ray-Ban Meta glasses, which already raised privacy concerns when researchers demonstrated they could be used to identify strangers on the street. A patent isn't a product, but it does signal Meta's intended direction. Australia's Privacy Act includes facial recognition under its biometric data provisions, and the Office of the Australian Information Commissioner has previously scrutinised similar technologies. The Online Safety Act's trajectory is also relevant here.

404 Media

New Zealand Intelligence: China Used Space Investments to Gather Domestic Intel

New Zealand's Security Intelligence Service has publicly accused China of attempting to exploit space-sector investments as a vehicle for gathering intelligence on domestic New Zealand affairs. It's a relatively rare public attribution from a Five Eyes member — particularly one as diplomatically cautious as New Zealand — and suggests the intelligence community assessed the activity serious enough to warrant naming. The finding aligns with broader Five Eyes warnings about investment-as-intelligence-collection across critical and emerging technology sectors. Australia faces near-identical risks in its own space and deep-tech investment landscape, and the Foreign Investment Review Board's technology-screening function is directly relevant.

The Register

Google Ordered to Make Rival App Stores Visible in Google Play — Within a Week

A US federal judge has given Google one week to modify the Google Play Store to make it easier for users to discover and download third-party Android app stores. The order is part of the ongoing antitrust remedy proceedings stemming from Google's 2023 trial loss. If implemented as ordered, it would mark a meaningful shift in how Android's app ecosystem works — alternative stores would gain a visibility foothold they've never had before. The ruling matters beyond the US: the EU's Digital Markets Act has been pushing similar requirements, and Australia's ACCC has been closely watching app-store competition as part of its Digital Platform Services inquiry.

Ars Technica

Google Cloud's Post-Quantum Roadmap: Full Readiness by 2029

Google Cloud has published a detailed post-quantum cryptography roadmap, targeting key migration milestones in 2027 and 2028 with full readiness by 2029. The timeline aligns broadly with NIST's recently finalised post-quantum standards and US government mandates requiring federal agencies to begin migrations. For enterprise cloud customers — including Australian government agencies that use Google Cloud under the Certified Cloud Services List — the roadmap provides a useful planning anchor. Organisations should be auditing their current use of RSA and elliptic-curve cryptography now, even if 2029 feels distant: cryptographic migrations in large environments routinely take longer than planned.

SecurityWeek

Sources consulted