PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks

1 month ago

Sansec found a Magento and Adobe Commerce REST API flaw, named PolyShell, which allows unauthenticated file uploads and possible XSS…

7,500+ Magento sites defaced in global hacking campaign

1 month ago

Hackers defaced 7,500 Magento sites since Feb 27, uploading files across 15,000 hostnames, mostly opportunistic attacks. Since February 27, a…

Navia data breach impacts nearly 2.7 Million people

1 month ago

Navia Benefit Solutions data breach exposed 2.7M people after attackers accessed systems from December 2025 to January 2026. Navia Benefit…

Apple urges iPhone users to update as Coruna and DarkSword exploit kits emerge

1 month ago

Apple warns that outdated iPhones are vulnerable to Coruna and DarkSword exploit kits and urges users to update iOS. Apple…

Global law enforcement operation targets AISURU, Kimwolf, JackSkid botnet operators

1 month ago

DoJ disrupted IoT botnets’ C2 infrastructure with global partners, targeting operators behind AISURU, Kimwolf, JackSkid, and others. The U.S. DoJ…

French aircraft carrier Charles de Gaulle tracked via Strava activity in OPSEC failure

1 month ago

A French aircraft carrier was tracked in real time via a sailor’s Strava activity, exposing a persistent operational security flaw.…

Critical Ubiquiti UniFi UniFi security flaw allows potential account hijacking

1 month ago

Ubiquiti fixed two UniFi vulnerabilities, including a critical flaw that could let attackers take over user accounts. Ubiquiti patched two…

U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog<gwmw style="display:none;"></gwmw>

1 month ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Cisco FMC and Cisco SCC Firewall Management to…

<gwmw style="display: none; background-color: transparent;"></gwmw>Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376<gwmw style="display: none; background-color: transparent;"></gwmw>

1 month ago

Russian APT exploits a critical XSS flaw in Zimbra, tracked as CVE-2025-66376, running scripts via HTML emails to target users…

DarkSword emerges as powerful iOS exploit tool in global attacks

1 month ago

DarkSword, a new iOS exploit kit, is used by multiple actors to steal data in campaigns targeting Saudi Arabia, Turkey,…

This website uses cookies.