Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

A critical vulnerability has been discovered in Adobe’s Commerce and Magento e-commerce platforms, potentially allowing hackers to hijack customer accounts. This flaw, identified as CVE-2026-71362, is just one of seven issues addressed by Adobe in a recent security update. Despite the software vendor’s claim that it is not aware of exploits in the wild for … Read more

Android malware combo takes out loans and relays victims’ credit cards

A New Android Malware Combo Steals Credit Cards and Takes Out Loans via Phone Calls Cyber attackers have devised a sophisticated scheme to steal credit card information and take out loans using a combination of malware tools on Android devices. The malicious operation involves phone calls, social engineering, and the exploitation of Accessibility Services permissions … Read more

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

Cybersecurity researchers have uncovered a sophisticated data theft campaign targeting organizations worldwide. Dubbed City-Forum by SaaS security firm Reco, the attacks exploit vulnerable configurations on Salesforce and ServiceNow portals, allowing attackers to steal sensitive information exposed to anonymous users. The City-Forum campaign has been linked to a single server hosted in Germany by Contabo, which … Read more

Walmart’s "Trusted Agent" Approach to Purple Teaming

Walmart’s groundbreaking approach to cybersecurity has just been revealed, and it’s a game-changer. The retail giant has ditched traditional siloed red and blue teams in favor of a collaborative “Trusted Agent” model, where both offensive and defensive security practitioners work together to improve the company’s overall security posture. At the heart of this innovative approach … Read more

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow, Exposing Sensitive Information Worldwide A sophisticated cyber threat actor has been conducting a long-running campaign of data theft against organizations using Salesforce and ServiceNow platforms, compromising sensitive information from multiple sectors around the world. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has … Read more

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Hackers are exploiting a critical vulnerability in Adobe Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The bug, identified as CVE-2026-71362, is an incorrect authorization vulnerability that can be leveraged without authentication or administrator privileges. This means that attackers do not need to have existing account information or interact with users … Read more

Android malware combo takes out loans and relays victims’ credit cards

Android Malware Combo Takes Out Loans and Relays Victims’ Credit Cards in Real-Time A disturbing combination of malware has been used by attackers to steal card data from unsuspecting Android users, taking out loans and making unauthorized purchases using their credit cards. The malicious duo, consisting of the SpyNote remote administration tool (RAT) and WindRelay … Read more

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

A sophisticated data theft campaign has been targeting organizations worldwide, exploiting a common vulnerability in Salesforce Experience Cloud and ServiceNow customer portals. Dubbed “City-Forum” by SaaS security firm Reco, these attacks have been ongoing for over a year, with activity increasing steadily. The attackers are not exploiting vulnerabilities in the platforms themselves but rather stealing … Read more

Hackers leverage new Microsoft SharePoint exploit in attacks

A Critical Microsoft SharePoint Vulnerity is Being Exploited in Real-World Attacks, Putting Thousands at Risk A highly critical security vulnerability in Microsoft’s popular collaboration platform, SharePoint, has been found to be actively being used by hackers in real-world attacks. The flaw, tracked as CVE-2026-55040, allows attackers to bypass authentication and gain access to sensitive data … Read more

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Cybersecurity Threats Lurking in the Hiring Process: How Fake Remote Workers Gain Access The traditional threat landscape is filled with phishing emails, exploited vulnerabilities, and malicious code. However, a more insidious threat has been lurking in plain sight – one that exploits the very process of hiring new employees to gain access to corporate networks. … Read more