StyleSmuggler Zero-Day Leaves Every Current Magento and Adobe Commerce Store Exposed to Takeover
A newly disclosed zero-day dubbed StyleSmuggler lets attackers hijack Magento Open Source and Adobe Commerce stores by smuggling PHP code through routine GraphQL requests and triggering it via...
Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...
Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories
Revolut disclosed that a fraudulent request sent from an official government email domain led to the release of highly sensitive customer records. The incident shows why authenticated email...
Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover
Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...
AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response
AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...
Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks
Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...
Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root
A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...
Cloud and SaaS Resilience Starts With Identity, Dependency Mapping and Tested Recovery
Cloud and SaaS adoption has replaced a clear network perimeter with overlapping identity and supplier dependencies. Organizations can limit cascading failures by mapping concentration risk, prioritizing exposed systems,...