Adobe Magento Under Attack: CVE‑2025‑54236 Exploited in the Wild
The foundation of many online stores is cracking. A critical vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE‑2025‑54236 and nicknamed SessionReaper, is now under active attack. In just one day, researchers observed 250+ exploitation attempts targeting multiple e‑commerce sites.
Windows SMB Vulnerability Exploited: Why Annual Patching Isn’t Enough
Threat actors are once again proving that old vulnerabilities are their favorite weapon. A high‑severity flaw in Microsoft’s Windows SMB client, patched during the June 2025 Patch Tuesday, is now being actively exploited in the wild.
Bring Your Own Car (BYOC): When Your Ride Becomes a Cybersecurity Risk
I love cars — from a 2015 Ferrari 458 Speciale to a 2026 Honda Civic Hybrid Sport Touring. But here’s the question: are they a hidden threat? Could the car you drive actually become an initial access method for attackers?
Researchers recently demonstrated a BYOC (Bring-Your-Own-Car) attack that turned a parked vehicle into a launchpad for infiltrating Linux and ESXi servers inside a corporate network.
Think Twice Before Installing That Chrome Extension: 131 Malicious Clones Hijack WhatsApp
Browser extensions are supposed to make life easier — but sometimes they make it a lot riskier. Cybersecurity researchers have uncovered a coordinated campaign leveraging 131 rebranded clones of a WhatsApp Web automation extension for Google Chrome. The attackers’ goal was simple: spam at scale. By hijacking these extensions, they were able to blast outbound WhatsApp messages in a way that bypassed the platform’s built‑in rate limits and anti‑spam controls.
F5 BIG-IP Breach: 266,000 Devices Exposed and 44 Vulnerabilities Patched — Here’s What You Need to Know
F5 BIG-IP has some big problems. In one of the most serious security incidents of the year, nation-state hackers breached F5’s internal network, gaining long-term access to its product development environment. The attackers exfiltrated source code and details on undisclosed BIG-IP vulnerabilities, raising alarms across the cybersecurity community.
The timing couldn’t be worse: over 266,000 F5 BIG-IP instances are currently exposed to the public internet, with nearly half located in the United States. These devices are widely used for application delivery, traffic management, and security enforcement — making them prime targets for exploitation.