SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

Cybersecurity experts are sounding the alarm over a critical vulnerability in SAP Commerce Cloud, a popular e-commerce platform used by thousands of businesses worldwide. The flaw, discovered by researchers, allows unauthenticated attackers to execute arbitrary code on affected systems, giving them full control over sensitive data and operations. The issue affects SAP Commerce Cloud versions … Read more

Wesco confirms security incident after ExfilSquad claims data theft

Wesco, a global supply chain and distribution giant, has confirmed that it is investigating a cybersecurity incident after threat actors claimed to have stolen sensitive information from its systems. The company’s cloud-based customer relationship management (CRM) environment appears to be at the center of the breach. ExfilSquad, a notorious data extortion group, has been linked … Read more

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

A Critical Flaw in Cisco’s Firewalls Exposes Networks to Devastating Remote DoS Attacks A critical vulnerability has been discovered in Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls, which have already been exploited in the wild. Attackers can take advantage of this flaw to launch a remote denial-of-service (DoS) attack on affected … Read more

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

A zero-day vulnerability in Microsoft’s Defender antivirus software has been exploited by hackers to gain SYSTEM-level access on vulnerable systems, according to a proof-of-concept (PoC) exploit published online. This devastating flaw allows attackers to bypass security patches and gain unfettered access to sensitive data, making it a serious concern for organizations worldwide. The vulnerability, which … Read more

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

**Critical Flaw in SAP Commerce Cloud Exposes Businesses to Unauthenticated Attacks** A critical vulnerability in the SAP Commerce Cloud platform has been discovered, allowing unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive systems. The flaw, which affects all versions of the software, has significant implications for businesses that rely on the … Read more

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has rolled out two new cumulative updates for Windows 11 – KB5121003 and KB5120240 – which bring a host of security patches, bug fixes, and new features to the operating system. These mandatory updates are part of the August 2026 Patch Tuesday release, addressing over 400 vulnerabilities discovered in previous months. The updates will … Read more

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft’s August Patch Tuesday Update Fixes 400 Vulnerabilities, Including Three Zero-Day Flaws Today, Microsoft released its highly anticipated August Patch Tuesday update, addressing a staggering 400 security vulnerabilities across its software products. Among these critical flaws are three zero-day vulnerabilities, with one already being actively exploited in attacks and two publicly disclosed. The sheer scale … Read more

Microsoft releases Windows 10 KB5120249 extended security update

Microsoft Delivers Critical Security Update for Windows 10 Users Windows 10 users are in for a dose of good news as Microsoft has released an extended security update (ESU) for versions 22H2 and 21H2. The KB5120249 update is mandatory, containing the August 2026 Patch Tuesday security updates that address critical vulnerabilities and bugs. This update … Read more

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Cybersecurity experts have been sounding the alarm about a sophisticated social engineering campaign, attributed to the notorious Russian threat group Sandworm. This campaign targets IT professionals and system administrators with fake job offers, tricking them into downloading a trojanized VPN client that compromises their systems. The Ukrainian Computer Emergency Response Team (CERT-UA) has been tracking … Read more