Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article answers frequently asked questions about CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce and Magento Open Source that has been actively exploited since September 4. It details the vulnerability's severity, affected versions, and the availability of a hotfix from Adobe.
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond.
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations , with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI models across healthcare, government, and media sectors, exfiltrating API credentials, and co-opting victim cloud environments to sustain unauthorized AI workloads.
Adobe has issued an emergency patch for an actively exploited zero-day vulnerability in Magento that allows unauthenticated remote code execution. Merchants are strongly advised to apply the fix immediately to prevent server takeover.
Research by: Alexey Bukhteyev Key Takeaways Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts.
Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers. The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users.