Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days ago, is already being actively exploited in attacks. Threat intelligence firm Defused has observed the flaw being targeted, highlighting the rapid weaponization of newly disclosed vulnerabilities.
French authorities are investigating a data breach at the Directorate General of Public Finances after a hacker claimed to have stolen data from 600,000 victims. The unauthorized access occurred in late June through identity theft or misuse.
This article details the post-exploitation phase of a simulated attack on a Kibana and Elasticsearch environment, demonstrating data exfiltration and persistence techniques. After gaining initial access through exposed ports and exploiting known vulnerabilities, the attackers show how they maintain access and steal data.
Mustang Panda (HoneyMyte) has been caught using an updated CoolClient backdoor paired with a signed Windows kernel rootkit, msagent.sys. The rootkit communicates with the user-mode component via IOCTL requests, hiding malicious artifacts at the kernel level.
Apple has expanded its threat-notification system for mercenary spyware, now displaying warnings directly on the iPhone lock screen and in Settings. These high-confidence alerts aim to make it harder for targeted individuals to overlook the risk, complementing email and account page notifications.
Cyera's $1 billion acquisition of Oasis Security aims to merge data security and identity management into a unified control plane for AI agents. The deal redefines privileged access using business context instead of static roles, reflecting the growing need to secure AI-driven workflows.