Adobe Magento Under Attack: CVE‑2025‑54236 Exploited in the Wild
Frank Marano Frank Marano

Adobe Magento Under Attack: CVE‑2025‑54236 Exploited in the Wild

The foundation of many online stores is cracking. A critical vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE‑2025‑54236 and nicknamed SessionReaper, is now under active attack. In just one day, researchers observed 250+ exploitation attempts targeting multiple e‑commerce sites.

Read More
Bring Your Own Car (BYOC): When Your Ride Becomes a Cybersecurity Risk
Frank Marano Frank Marano

Bring Your Own Car (BYOC): When Your Ride Becomes a Cybersecurity Risk

I love cars — from a 2015 Ferrari 458 Speciale to a 2026 Honda Civic Hybrid Sport Touring. But here’s the question: are they a hidden threat? Could the car you drive actually become an initial access method for attackers?

Researchers recently demonstrated a BYOC (Bring-Your-Own-Car) attack that turned a parked vehicle into a launchpad for infiltrating Linux and ESXi servers inside a corporate network.

Read More
Think Twice Before Installing That Chrome Extension: 131 Malicious Clones Hijack WhatsApp
Frank Marano Frank Marano

Think Twice Before Installing That Chrome Extension: 131 Malicious Clones Hijack WhatsApp

Browser extensions are supposed to make life easier — but sometimes they make it a lot riskier. Cybersecurity researchers have uncovered a coordinated campaign leveraging 131 rebranded clones of a WhatsApp Web automation extension for Google Chrome. The attackers’ goal was simple: spam at scale. By hijacking these extensions, they were able to blast outbound WhatsApp messages in a way that bypassed the platform’s built‑in rate limits and anti‑spam controls.

Read More
F5 BIG-IP Breach: 266,000 Devices Exposed and 44 Vulnerabilities Patched — Here’s What You Need to Know
Frank Marano Frank Marano

F5 BIG-IP Breach: 266,000 Devices Exposed and 44 Vulnerabilities Patched — Here’s What You Need to Know

F5 BIG-IP has some big problems. In one of the most serious security incidents of the year, nation-state hackers breached F5’s internal network, gaining long-term access to its product development environment. The attackers exfiltrated source code and details on undisclosed BIG-IP vulnerabilities, raising alarms across the cybersecurity community.

The timing couldn’t be worse: over 266,000 F5 BIG-IP instances are currently exposed to the public internet, with nearly half located in the United States. These devices are widely used for application delivery, traffic management, and security enforcement — making them prime targets for exploitation.

Read More