Patching StyleSmuggler Will Not Evict an Attacker From Your Magento Store

Adobe has patched the exploited StyleSmuggler flaw. Magento and Commerce operators still need to check for compromise, verify the right hotfix and rotate exposed credentials.

Adobe has patched the exploited StyleSmuggler flaw. Magento and Commerce operators still need to check for compromise, verify the right hotfix and rotate exposed credentials.

Attackers diverted Coder's trusted Terraform registry to malicious modules that searched provisioners for cloud keys, tokens, SSH credentials and secrets.

A BGP hijack diverted Softaculous traffic, obtained a valid TLS certificate and delivered a malicious Virtualizor update to real servers.

Phishing victims installed a legitimate Faronics Deploy agent that enrolled their computers into attacker-controlled management consoles.

Berlin says Rhysida released a further stolen-data package containing access credentials, forcing additional safeguards and possible service restrictions.

Cronos halted its entire network after an exploit in Tectonic. The incident turns a DeFi collateral failure into a test of chain-wide emergency governance.
Ten malicious npm releases carried valid provenance because an outsider could drive the project’s trusted GitHub Actions publishing workflow.

Microsoft observed attackers turning exposed LiteLLM gateways into credential-harvesting, database-access and persistence hubs. The public exploit chain makes AI gateways a Tier-0 patching priority.

Hasbro says a compromised employee account exposed personal and financial information. Massachusetts records identify 436 affected residents, while the worldwide total remains undisclosed.

McKesson confirmed unauthorised access to third-party applications and data exfiltration. ShinyHunters claims 284 million patient-related data rows, but the scale and data types remain unverified.