Macs are being broken into through a Screen Sharing flaw patched on August 6, 1.6 million RingCentral account records were dumped online, and Gemini's visible AI watermark becomes optional

Update your Mac now — a Screen Sharing flaw is being used in real attacks

Apple released macOS updates on August 6 that fix a flaw in the Screen Sharing service, and attackers have now started using it. The versions that contain the fix are macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, all listed on Apple's security releases page. The flaw, tracked as CVE-2026-65400, is in the part of the Screen Sharing service that checks whether a connection is allowed in, and the check can be made to report success when it should not — so no password is needed.

Reports of active abuse describe attackers reaching Macs that have Screen Sharing switched on and exposed to the internet, gaining full administrator access and installing cryptocurrency mining software. A mined machine is not quiet about it: fans run constantly, the computer is slow, and it stays that way. The published analysis is also clear that the usual half-measures do not help here, because the attack happens before any password is checked — changing the Screen Sharing password or removing permitted users makes no difference.

Why it matters: Screen Sharing is the feature people turn on once so a family member or an IT helper can connect, and then forget about for years. Open System Settings, then General, then Software Update, and install the update today — if your Mac is on macOS Sonoma or Sequoia the fix is a security update, not a version upgrade, so it is a small download. If you cannot update right now, go to System Settings, then General, then Sharing, and switch Screen Sharing off until you can.

Names, addresses and phone numbers for 1.6 million RingCentral accounts are now public

RingCentral, a business phone and video service used by a great many small companies, was breached in July through what the company describes as a sophisticated social engineering campaign — meaning staff were tricked, rather than software being broken into. An extortion group has now published the data it took, and the breach-notification service Have I Been Pwned added 1.6 million RingCentral records to its database on August 13 after analysing the published archive. The exposed fields are names, email addresses, phone numbers and physical addresses.

The company says the incident did not affect the core RingCentral platform, that services continued running, and that it is contacting affected customers directly. No passwords or call recordings are described as being in the published set.

Why it matters: the danger in a list of names, work phone numbers and addresses is not the data itself, it is the convincing phone call that comes afterwards — someone who already knows your name, your company and your number calling to "verify" something. Enter your email address at haveibeenpwned.com to see whether you are in this one, and warn anyone in your business who answers the phone or handles invoices that callers quoting correct details about the company are not thereby proven genuine. If a call asks you to approve a login, change payment details, or read out a code, hang up and call back on a number you already had.

A new free service shows which ad and data companies operate on a site or app

A group of researchers has launched a free service that reads the disclosure files websites and apps are required to publish about their advertising partners, and turns them into something a person can actually search. The write-up explains that you can look up any site or app and see which ad companies and data brokers operate there, which of those partners are registered data brokers, what they collect, and which are based in countries that raise particular concerns. Basic use is free; a paid account adds programming access for researchers.

The write-up is equally clear about the limits. The service can only report what companies themselves disclose, and the advertising industry does not publish a full picture of who is passing data to whom. It is a window, not an audit.

Why it matters: the practical use for a small business is checking your own site. If you run ads, use an analytics tool, or installed a marketing tag a while ago and never looked again, this shows you which third parties are riding along on visits to your pages — which is the same list you are implicitly promising about in your privacy policy. Look your own domain up first, and if you find partners you cannot account for, that is a conversation to have with whoever maintains the site.

Gemini's visible AI watermark becomes optional, but an invisible one stays

Google is rolling out a setting that lets people switch off the visible watermark that has appeared in the corner of images, video and music made with Gemini. The toggle is found in Gemini's settings under Media Watermark, applies to the Nano Banana, Omni and Lyria models, and works in the Gemini app and in Google's Flow video editor, with support in Search described as coming. Google's own announcement states that invisible SynthID watermarks and C2PA provenance data stay embedded in the file regardless, so the marking does not disappear — it stops being something you can see.

Why it matters: two practical consequences. If you make marketing images or video with Gemini, the corner mark that made them look obviously machine-made can now be turned off, which is the reason many people were not using them. And going the other way: from now on, the absence of a visible corner watermark tells you nothing about whether an image was generated, so it is no longer a signal worth relying on when judging a photo someone sends you.

The price of the big AI models is falling

The large American AI companies have been cutting the prices of some models as customers test cheaper alternatives from Chinese developers. Coverage of the shift reports that OpenAI cut the price of its fastest and cheapest model by around 80 percent, and that Anthropic positioned its Opus 5 model at roughly half the price of its most capable one, while models from Chinese developers such as DeepSeek and Moonshot AI are priced well below both. The reporting also notes that rising AI bills have pushed companies to cap spending and try lower-cost options.

Why it matters: if you pay for AI by usage rather than by monthly subscription — anything wired into a tool through an API, which is most automations a developer set up for you — the rate you agreed to months ago is probably no longer the going rate. Two things are worth doing this quarter: ask whoever built your setup which model it calls and what it costs per month now, and check whether a cheaper tier of the same family would do the job. Note that this affects usage-based pricing, not the flat monthly consumer subscriptions, which have not moved.