Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Cybersecurity researchers have discovered a critical zero-day vulnerability in Magento and Adobe Commerce, two popular e-commerce platforms used by thousands of online stores. This flaw allows attackers to remotely backdoor websites, giving them full control over sensitive data and operations. The vulnerability, which has been actively exploited since August 2026, affects versions 2.4.x and earlier … Read more

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

A Critical Flaw in VMware’s Virtualization Software Exposes VM Admins to Host Code Execution Risks VMware, a leading provider of virtualization software, has disclosed a critical vulnerability that affects its Workstation and Fusion products. The flaw, tracked as CVE-2026-1234, allows administrators with privileges within a virtual machine (VM) to execute code on the host operating … Read more

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

A Critical Vulnerability in JetBrains Cadence Exposed Thousands of AWS Credentials Thousands of developers and organizations using JetBrains’ project management tool, Cadence, have been left vulnerable to a critical security breach after attackers exploited an unpatched vulnerability in TeamCity, a closely related service. The attack allowed hackers to extract sensitive AWS credentials, compromising the security … Read more

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked websites are being used as unwitting accomplices in a massive cybercrime operation that’s delivering malicious payloads stored on the BNB Smart Chain (BSC) blockchain. This sprawling campaign involves thousands of compromised small-business sites, with most built on WordPress and PrestaShop platforms. Researchers at cloud security firm Netskope have uncovered the scope of … Read more

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

A major security breach has rocked cryptocurrency hardware wallet provider Trezor, with a staggering 67,000 U.S. customers’ data potentially compromised in a hacking incident that’s left many wondering how such a massive vulnerability could be overlooked. The breach, which occurred at ShipMonk, a third-party logistics company used by Trezor for order fulfillment and shipping, has … Read more

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Critical Flaw in VMware Workstation and Fusion Exposes Host Systems to Unauthorized Access A severe vulnerability has been discovered in VMware’s popular virtualization software, Workstation and Fusion. The flaw allows administrators of virtual machines (VMs) to execute code on the underlying host system with escalated privileges, potentially leading to unauthorized access and data breaches. The … Read more

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

A Critical Vulnerability in JetBrains Cadence Exposes AWS Credentials, Leaving Thousands of Developers at Risk In a disturbing revelation, cybersecurity researchers have uncovered an alarming security breach that has compromised thousands of developers worldwide. Attackers exploited an unpatched vulnerability in JetBrains TeamCity, a popular continuous integration and continuous deployment (CI/CD) tool used by numerous organizations, … Read more

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

A critical vulnerability in the Elementor Pro WordPress plugin has been exploited by hackers to compromise numerous websites, with over 190,000 exploit attempts blocked so far. The bug, tracked as CVE-2026-32475, allows an attacker to upload arbitrary PHP files to a website’s server, potentially leading to full site takeover. The vulnerability affects all versions of … Read more

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked sites serve malicious payloads stored on the blockchain, compromising thousands of users each day. A massive cybercriminal operation has been leveraging thousands of compromised small-business websites to deliver malicious payloads stored in smart contracts on the BNB Smart Chain (BSC). Researchers at cloud security platform Netskope have identified over 5,400 hacked websites, … Read more

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

A shocking data breach has left over 67,000 U.S. customers of ShipMonk exposed, and it gets even worse – their sensitive information was allegedly deleted from the compromised system, only to resurface in a cybersecurity report. The incident raises questions about the true nature of data deletion and highlights the ongoing struggle with identity exposure. … Read more