Magento zero-day vulnerability actively exploited without a patch
A Magento zero-day vulnerability is reportedly being actively exploited, and no patch is available. Organizations using affected Magento systems may face immediate compromise risk.
Cyber incidents, service outages and reported data exposure, explained through their concrete effects on users and organizations.
Ordered by reported development. Each article describes what was known at the time shown.
A Magento zero-day vulnerability is reportedly being actively exploited, and no patch is available. Organizations using affected Magento systems may face immediate compromise risk.
Germany's federal government is establishing a virtual institute focused on AI safety, using the UK as a model. The supplied headline gives no further operational details.
A law firm is investigating reports that See's Candies may have exposed customers' personal information. The supplied report provides no details on the scope or type of data affected.
Austria is set to apply cybersecurity standards under the EU NIS2 Directive from October. The measure concerns strengthened obligations for covered organizations.
Artificial intelligence, military decision-making procedures and potentially rogue AI agents are discussed. No specific attack, breach or operational incident is identified.
The supplied report compares election disinformation to phishing, indicating concern about deceptive digital influence during a campaign. No specific attack, breach or operational disruption is described.
Hackers reportedly published personal data belonging to British politicians and military personnel on the dark web. The supplied report does not specify the number of people affected or the source of the data.
Germany’s Interior Ministry is reportedly planning a protective shield against Russian sabotage following a drone incident. The report describes a planned response, not a confirmed attack or implemented measure.
Following a drone incident in Leipzig, Chancellor Friedrich Merz warned that further hybrid attacks could occur. The supplied report does not provide details about damage, attribution or specific new measures.
A reported vulnerability in a common PC startup component could allow attackers to compromise systems before the operating system loads. The supplied headline does not provide technical or scope details.
A report examines how vulnerable infrastructure in Germany is to cyberattacks. No specific attack, breach or outage is identified in the supplied headline.
A prankster created a lookalike Republican midterm convention website that sends visitors to documents known as the Epstein files.
The Green Party is pressing the NHS over its use of a technology company. The supplied headline does not specify the company, system or any confirmed disruption.
A report describes a dispute over Microsoft's response to a security researcher concerning a zero-day vulnerability.
A report alleges that JetBrains Cadence was compromised by exploiting a vulnerability in its TeamCity environment.
A fraudulent recruitment scheme reportedly caused a person to lose all of their savings during a job interview. The supplied information does not establish broader scale or systemic impact.
A cyberattack reportedly resulted in the theft of $1.6 million from a regional body of UMC.
Hackers linked to an airport-related incident have published personal data belonging to a judge, politicians and celebrities on the dark web. The supplied headline does not identify the airport, attackers or the scale of the exposure.
A report says Germany has raised an alarm following a hacker attack. The supplied headline does not identify the victim, scope or operational impact.
AI-generated advertisements are appearing widely on social media ahead of Victoria’s election. The supplied report questions who is behind the campaign.
A data leak involving a U.K. airport has affected thousands of Dutch individuals. The supplied report says the British prime minister’s Dutch wife may also be included.
Authorities indicted 57 people over an alleged voice-cloning romance scam involving approximately NT$900 million. The scheme reportedly used synthetic voices to defraud victims.
An investigation reportedly found that public information officers exploited the Agniveer recruitment ecosystem for espionage. The supplied headline does not provide operational details or confirmed damage.
A report examines Germany’s efforts to counter unspecified invisible threats described as hybrid warfare.
A data breach has exposed 153 million driver's license records. The scale of the exposure creates a substantial risk of identity theft and other misuse.
An EtherHiding campaign reportedly compromises 5,400 websites, which load malicious code from the BSC testnet. The supplied headline does not specify the victims, payload or measured harm.
A second wave of attacks is reportedly affecting schools and higher-education institutions using PaperCut NG. The supplied headline does not provide details on the attack method, scope or impact.
A report examines a cyberattack and data leak in Germany. The supplied information does not specify the affected organization, scale of the breach or operational impact.
A report alleges irregularities and ethical questions surrounding the handling of a ransomware incident in the Concello de Cangas.
Taiwan's Ministry of National Defense is reported to be planning a cyber hunt team. The headline provides no evidence of a current attack or disruption.
CSIST has been told to fix its system following a hack. The supplied information does not establish the scale of the breach or wider disruption.
The report describes Russian agents conducting sabotage operations in Europe. The supplied headline does not identify specific incidents, targets or confirmed damage.
New reporting says data on Berlin's critical infrastructure was leaked in a hacking incident, prompting opposition calls for consequences. The supplied information does not specify the systems affected or the extent of operational impact.
A report highlights significant gaps in the Philippines' cybersecurity defenses. The supplied information does not specify a particular attack or breach.
The report discusses practical implementation of an AI system, including API quota issues and defenses against prompt injection.
The US military has disabled advertising identifiers amid concerns that they could be used to track troops. The measure addresses a potential operational-security and privacy vulnerability.
The headline warns that perpetrators have known for years where Germany is vulnerable. It does not identify the perpetrators, targets or a specific attack.
Swiss authorities, including Foreign Minister Ignazio Cassis, reportedly discussed a Russian cyberattack against Switzerland. The supplied headline does not provide details on the affected systems or extent of disruption.
A church commission in the Czech Republic has warned about pro-Russian disinformation.
Google Chrome has patched its sixth zero-day vulnerability of 2026, involving an exploit in the V8 JavaScript engine that was reportedly used in attacks.