TruthSoc
Continuous cybersecurity monitoring — Switzerland, Europe and worldwide. Alerts, vulnerabilities (CVE), actively exploited flaws (KEV) and official advisories (NCSC-CH, CISA, BSI, CERT-FR, NCSC-UK, DCOD), normalised and classified automatically.
Actively exploited
6latest yesterdayConfirmed exploitation — treat first, whatever the date
Vulnerabilities
8 / 8latest 33 minutes agoA vulnerability allows OS command injection in token-optimizer-mcp's smart_user tool due to improperly sanitized username input in get-user-info.
A high-severity macOS vulnerability (CVE-2026-65400) allowing full system control is under active exploitation, enabling attackers to install crypto miners via screen sharing flaws.
A recently patched critical remote code execution flaw in SAP Commerce Cloud is being actively targeted in attacks.
A remote, anonymous attacker could exploit multiple vulnerabilities in Golang Go to cause a denial of service, perform cross-site scripting, bypass security measures, or manipulate data.
A remote, authenticated attacker could exploit multiple vulnerabilities in Budibase to manipulate files, disclose sensitive data, gain elevated privileges, and bypass security measures.
An anonymous remote attacker can exploit multiple flaws in Apache Struts to bypass protections, expose or alter data, or trigger a denial of service.
An unauthenticated remote attacker can exploit a Perl flaw to perform a Denial of Service attack.
A local attacker can exploit a flaw in Podman to perform an unspecified attack and disclose information.
Threats & campaigns
10 / 18latest 2 hours agoA cheap electronic implant can manipulate critical flight data in a Boeing 737, highlighting avionics system vulnerabilities.
The canton of Bern suspended automated vehicle surveillance after a court-ordered security gap was found in the cantonal police law.
AI-powered vulnerability research is overwhelming systems, leading NIST to assess whether AI could help address the growing number of software flaws.
Apple alerts hundreds of users about highly targeted mercenary spyware attacks requiring immediate verification.
Apple alerts users about new spyware campaigns aimed at journalists, activists, politicians, and diplomats, advising Lockdown Mode activation for protection.
Researchers showed how a Boeing 737's autopilot could be manipulated through an accessible maintenance port.
A fake LinkedIn job scam involving malware during a coding assessment bypassed multi-factor authentication to access a code repository, costing $11.8 million.
Security researchers found a side-channel vulnerability in older AMD processors enabling access to protected RAM regions through the PSP security controller.
Organizations must adopt broader defenses against Google Workspace threats, including stolen OAuth tokens, beyond phishing, per Material Security.
A 'City-Forum' cyberattack campaign targets Salesforce and ServiceNow systems, exposing user data and linked to the ShinyHunters group.
Advisories
9 / 9latest 2 hours agoA video interview highlights how Standard Chartered's CISO transitioned from technical roles to strategic leadership while discussing AI's impact on cybersecurity in banking.
The FBI documented $20.8 billion in cybercrime losses in 2025, with $11.37 billion linked to cryptocurrency crimes.
Smart glasses equipped with concealed cameras raise privacy concerns, while legal recourse is available for victims of unauthorized recordings.
Datavault AI completes the acquisition of CyberCatch through an all-cash transaction to enhance its AI-driven cyber risk mitigation platform.
The hacking group Clop claims to have stolen massive data from 50 companies, including Shell and Philips.
Oracle released a free six-month security tool to centrally manage database security risks amid rising threats and AI-driven bug discovery.
Meta is testing an optional Scam Alert feature on WhatsApp that uses on-device AI to flag likely scam messages from non-contacts, without automatic blocking.
Google integrates a selfie video method to restore access to blocked accounts by analyzing head movements.
The free DecryptAds service aggregates and cross-references adtech data to help users identify tracking entities and potential privacy risks.
Ransomware
2 / 2latest 9 hours agoA Russia-linked ransomware group claims to have breached global corporations Shell and Philips, impacting nearly 50 other entities.
Shell investigates a possible security breach following Clop ransomware gang's claim of stealing 89GB of its data.
Data breaches
10 / 13latest 1 hour agoA major cyberattack causing a data leak has significantly damaged Liechtenstein's financial sector and government reputation.
Hackers allegedly linked to Iran breached multiple US water utility systems in a recent coordinated cyberattack wave.
German online retailer About You confirms it was affected by a data breach at Ceva Logistics, following incidents impacting Bijenkorf and Bol.
The French tax authority disclosed a breach exposing data from 678,000 taxpayer accounts, with an apology issued to affected individuals.
Three public data breaches this week exposed potentially millions of French citizens' data amid government plans to expand identity verification systems.
A Scottish government agency reported a data breach at the Prosecutor's Office that may affect other agencies serviced by the same third party.
A data breach at France's tax portal in late June, disclosed on August 13, underscores underinvestment in cybersecurity despite AI deployment priorities.
Researchers confirmed that the extortion group ExfilSquad accessed and leaked sensitive data from at least 13 organizations.
A flaw in UMC Utrecht's guest system leaked personal data of 5,000 people, excluding medical records.
A cyberattack on France's tax authority exposed cadastral files and personal data of taxpayers, raising phishing risks.
Incidents & attacks
10 / 10latest 55 minutes agoNippon Reizo reports a potential leak of employee personal data following a cyberattack in July 2026.
Liechtenstein's Prime Minister Brigitte Haas ruled out paying a ransom following a cyberattack that exposed data of 31,000 entities in the country's beneficial ownership registry.
Four cybercriminals arrested in Brazil and three charged in Europe for exploiting a Commerzbank service provider flaw to steal €30M.
Police Scotland warns that strong security measures are essential to prevent attacks on proposed AI data centres near Edinburgh due to expected public resistance.
VINclarity releases findings from an investigation into a suspected scam and fraudulent reputation attack targeting search and AI systems.
Fortum and Smartly among Finnish companies hit by a March 2026 supply chain cyberattack with no confidential data compromised.
Autonomous AI agents are increasingly deployed in cyber attacks, particularly against Taiwan, signaling a dangerous shift in digital conflict and Western security threats.
France's tax authority admitted a June 2026 cyberattack where hackers stole data of 2 million taxpayers, though officials deny ongoing system access.
AI-powered autonomous cyberattacks have already targeted critical infrastructure in Taiwan and the U.S., posing a national security risk.
Security analysis shows over 95% of 2,500 compromised organizations were exposed before malicious LiteLLM packages were published, implicating Trivy as the primary cause.
Free access: you are viewing the last 7 days. The Pro plan unlocks the full history, CSV/JSON export, the API and a digest tailored to your sector. See the plans →