Magento, JetBrains and PostgreSQL Under Attack as OpenAI Funds Defense
Listen now
Stream the full 4:19 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and decision-makers, each episode distills the threats, breaches, and technology developments that could affect your organisation. Today’s five stories:
- 01
Attackers are exploiting StyleSmuggler, an unpatched zero-day in Magento Open Source and Adobe Commerce, to execute code and install persistent backdoors on online stores. Merchants face risks including session theft, silent reinfection, and compromise of connected systems while no official fix is available.
- 02
JetBrains confirmed that attackers used a critical TeamCity flaw to access its Cadence cloud service and extract a backup containing AWS credentials, configurations, logs, and personal data. Current and former users should rotate credentials, investigate connected systems, and treat stored data and execution results as potentially compromised.
- 03
OpenAI has committed $1 billion in subsidised AI cybersecurity tools, training, and support for critical infrastructure and other under-resourced defenders. The initiative prioritises sectors such as water, energy, local government, banking, and open-source software, where limited security capacity increases exposure to accelerating AI-enabled attacks.
- 04
Abliteration.ai has launched browser and API access to open-weight AI models with safety guardrails removed. Supporters see value for offensive security testing and red-teaming, but critics warn that uncensored models could lower the barrier to harmful misuse.
- 05
A severe PostgreSQL vulnerability, CVE-2026-6471, allows attackers with low-level replication privileges to execute code, escalate privileges, and establish persistent access. Organisations should patch urgently and review replication permissions, as compromised backup or pipeline accounts could enable complete database takeover.