PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks

Sansec found a Magento and Adobe Commerce REST API flaw, named PolyShell, which allows unauthenticated file uploads and possible XSS in older versions. Sansec disclosed a critical flaw in the Magento and Adobe Commerce REST API that allows attackers to upload executable files without authentication. The issue affects versions up to 2.4.9-alpha2 and could also […]

Read More >>

Russian hackers target US officials, military personnel, and journalists on Signal, thousands of accounts compromised: FBI

Russian intelligence is actively compromising thousands of Signal accounts, targeting US officials, military, and journalists. Hackers impersonate support staff to trick users into revealing sensitive information, enabling full account takeovers. This …

Read More >>