Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
9 / 9 results
criticalbug_reportVulnerabilityGiveWP WordPress plugin RCE allows unauthenticated server takeover
GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).
criticalbug_reportVulnerabilityAdobe Commerce critical vulnerability under active exploitation
Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.
criticalbug_reportVulnerabilitySAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch
SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.
criticalbug_reportVulnerabilityAdobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts
Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.
criticalbug_reportVulnerabilitySAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)
SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.
highbug_reportVulnerabilityQuick.Cart stores hardcoded admin credentials in plaintext config file
OpenSolution Quick.Cart all versions through 6.7. Vulnerability requires attacker access to server file system to retrieve hardcoded plaintext admin credentials from configuration file.
highbug_reportVulnerabilityShopify Shop app abused for callback phishing via fake order receipts
Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.
highpublicGeopoliticalSouth Korea issues record $409M fine to Coupang for 37M-user breach
The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.
criticalbug_reportVulnerabilitySAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud
SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.