The rundown
- 1 Attackers are exploiting StyleSmuggler, an unpatched zero-day in Magento Open Source and Adobe Commerce, to execute code and install persistent backdoors on online stores. Merchants face risks including session theft, silent reinfection, and compromise of connected systems while no official fix is available.
- 2 JetBrains confirmed that attackers used a critical TeamCity flaw to access its Cadence cloud service and extract a backup containing AWS credentials, configurations, logs, and personal data. Current and former users should rotate credentials, investigate connected systems, and treat stored data and execution results as potentially compromised.
- 3 OpenAI has committed $1 billion in subsidised AI cybersecurity tools, training, and support for critical infrastructure and other under-resourced defenders. The initiative prioritises sectors such as water, energy, local government, banking, and open-source software, where limited security capacity increases exposure to accelerating AI-enabled attacks.
+2 more stories