TruthSoc
Continuous cybersecurity monitoring — Switzerland, Europe and worldwide. Alerts, vulnerabilities (CVE), actively exploited flaws (KEV) and official advisories (NCSC-CH, CISA, BSI, CERT-FR, NCSC-UK, DCOD), normalised and classified automatically.
Actively exploited
6latest yesterdayConfirmed exploitation — treat first, whatever the date
Vulnerabilities
10 / 22latest 20 minutes agoThe canton of Bern halted automated vehicle surveillance due to a court-ordered security gap in the cantonal police law.
The canton of Bern suspends automated vehicle detection after discovering a security vulnerability in its system.
Four cybercriminals arrested in Brazil and three charged in Europe for exploiting a Commerzbank service provider flaw to steal €30M.
A recently patched critical remote code execution flaw in SAP Commerce Cloud is being actively targeted in attacks.
Chinese AI startup Z.ai states its open-source GLM-5.3 model performs nearly as well as Anthropic's restricted Mythos 5 in cyber-defence vulnerability detection.
An iX/heise workshop teaches how to methodically plan, commission, and analyze penetration tests to identify IT vulnerabilities.
Roundup of recent cybersecurity incidents including layoffs at Rapid7, vulnerabilities in Boeing 737 systems, and flaws in refrigeration systems, alongside geopolitical and aviation issues.
An unauthenticated remote attacker can exploit a flaw in PJSIP to manipulate files.
A remote, anonymous attacker could exploit multiple vulnerabilities in Golang Go to cause a denial of service, perform cross-site scripting, bypass security measures, or manipulate data.
A remote, authenticated attacker could exploit multiple vulnerabilities in Budibase to manipulate files, disclose sensitive data, gain elevated privileges, and bypass security measures.
Threats & campaigns
10 / 10latest 4 hours agoAttackers are leveraging a macOS authentication bypass vulnerability to deploy Monero mining malware following the public release of exploit code.
Organizations must adopt broader defenses against Google Workspace threats, including stolen OAuth tokens, beyond phishing, per Material Security.
A 'City-Forum' cyberattack campaign targets Salesforce and ServiceNow systems, exposing user data and linked to the ShinyHunters group.
Apple warned iPhone users in 110 countries on August 13, 2026, that their devices were targeted by mercenary spyware.
A trader lost $550,000 after clicking a phishing link promoted in Google ads that led to a fake Hyperliquid website.
A new Linux botnet called Evooo1Bot, derived from Mirai, turns edge devices into persistent proxies with advanced features.
Apple expands its threat-notification system to display high-risk alerts directly on iPhones for mercenary spyware targets, urging immediate protective actions.
Cybercriminals are hijacking Google Workspace accounts to send phishing emails from legitimate domains, making fraudulent messages harder to detect.
WindRelay, a new Android malware, captures live payment card data via NFC and relays it to fraudsters in real time, often paired with SpyNote for remote access.
AmnesiaStealer, a new macOS infostealer, spreads via ClickFix and enables remote browser control to steal cookie data.
Advisories
7 / 7latest 4 hours agoDatavault AI completes the acquisition of CyberCatch through an all-cash transaction to enhance its AI-driven cyber risk mitigation platform.
The hacking group Clop claims to have stolen massive data from 50 companies, including Shell and Philips.
Oracle released a free six-month security tool to centrally manage database security risks amid rising threats and AI-driven bug discovery.
Meta is testing an optional Scam Alert feature on WhatsApp that uses on-device AI to flag likely scam messages from non-contacts, without automatic blocking.
Google integrates a selfie video method to restore access to blocked accounts by analyzing head movements.
The free DecryptAds service aggregates and cross-references adtech data to help users identify tracking entities and potential privacy risks.
HateAid demands a halt to smart glasses sales due to privacy risks from covert recording capabilities.
Ransomware
2 / 2latest 6 hours agoA Russia-linked ransomware group claims to have breached global corporations Shell and Philips, impacting nearly 50 other entities.
Shell investigates a possible security breach following Clop ransomware gang's claim of stealing 89GB of its data.
Data breaches
10 / 11latest 47 minutes agoThe French tax authority disclosed a breach exposing data from 678,000 taxpayer accounts, with an apology issued to affected individuals.
Three public data breaches this week exposed potentially millions of French citizens' data amid government plans to expand identity verification systems.
A Scottish government agency reported a data breach at the Prosecutor's Office that may affect other agencies serviced by the same third party.
A data breach at France's tax portal in late June, disclosed on August 13, underscores underinvestment in cybersecurity despite AI deployment priorities.
Researchers confirmed that the extortion group ExfilSquad accessed and leaked sensitive data from at least 13 organizations.
A flaw in UMC Utrecht's guest system leaked personal data of 5,000 people, excluding medical records.
A cyberattack on France's tax authority exposed cadastral files and personal data of taxpayers, raising phishing risks.
French tax authority systems were breached in late June after a hacker claimed 600,000 victims, prompting an investigation by authorities.
H&M disclosed unauthorized access to sensitive customer data in South Korea.
A data breach at France's tax authority in June may have exposed personal and professional data, with unauthorized access confirmed.
Incidents & attacks
8 / 8latest 2 hours agoPolice Scotland warns that strong security measures are essential to prevent attacks on proposed AI data centres near Edinburgh due to expected public resistance.
VINclarity releases findings from an investigation into a suspected scam and fraudulent reputation attack targeting search and AI systems.
Fortum and Smartly among Finnish companies hit by a March 2026 supply chain cyberattack with no confidential data compromised.
Autonomous AI agents are increasingly deployed in cyber attacks, particularly against Taiwan, signaling a dangerous shift in digital conflict and Western security threats.
France's tax authority admitted a June 2026 cyberattack where hackers stole data of 2 million taxpayers, though officials deny ongoing system access.
AI-powered autonomous cyberattacks have already targeted critical infrastructure in Taiwan and the U.S., posing a national security risk.
Security analysis shows over 95% of 2,500 compromised organizations were exposed before malicious LiteLLM packages were published, implicating Trivy as the primary cause.
A subcontractor for France's public health agency suffered a cyberattack exposing 80,000 data records, with guidance provided for affected individuals.
Free access: you are viewing the last 7 days. The Pro plan unlocks the full history, CSV/JSON export, the API and a digest tailored to your sector. See the plans →