Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Hacker News reports that hackers compromised Adform's advertising script to swap cryptocurrency wallet addresses on customer sites. The supply chain attack redirected crypto payments to attacker-controlled wallets.
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.
Adobe has issued critical security updates to address vulnerabilities in its Campaign Classic (ACC) platform, an enterprise marketing automation tool. The most severe flaw, CVE-2026-48449, carries a CVSS score of 10.0 and allows arbitrary code execution without user interaction due to incorrect authorization.
Adobe released security updates for Campaign Classic, addressing a maximum-severity vulnerability (CVE-2026-48449) that could allow arbitrary code execution without user interaction. A second high-severity SQL injection flaw (CVE-2026-48448) could also enable arbitrary file reads.
Hijacked hotel Wi-Fi networks are used to deliver CornFlake RAT by redirecting users to fake browser updates. The campaign, attributed to Midnight Blizzard, exploits captive portal control to manipulate DNS and push malware.
The Hacker News reports attackers hijacked hotel Wi-Fi networks to push fake software updates delivering surveillance malware. The campaign targets business travelers by spoofing legitimate update prompts.