ADOBE COMMERCE FLAW ENABLES ACCOUNT HIJACKING
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A critical vulnerability in Adobe Commerce and Magento platforms is being actively exploited to compromise customer accounts. The flaw, tracked as CVE-2026-71362, poses immediate risk to e-commerce operations worldwide.
■ MORE FROM THE SECURITY DESK
A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.
A new Android malware combo pairs NFC relay malware called WindRelay with the SpyNote remote administration tool to steal credit card data and conduct fraud in real time.
Unknown actors are conducting widespread vulnerability scans while impersonating AI assistants like ClaudeBot, according to reports circulating in security communities.
Security researchers have disclosed "Plug and Pwn" attacks that abuse Windows Plug and Play functionality to install malicious vendor software and achieve SYSTEM-level privileges. The vulnerability leverages legitimate Windows features to bypass security controls.