SAP COMMERCE CLOUD ZERO-DAY UNDER ACTIVE ATTACK
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being exploited in the wild just three days after the company released a patch. Threat intelligence firm Defused confirmed active targeting of the flaw.
■ MORE FROM THE SECURITY DESK
Flock Safety announced new safeguards for its license plate recognition cameras following reports that law enforcement used the system to target immigrants and track people seeking out-of-state abortions. The company operates a network processing 20 billion monthly scans across the US.
The Netherlands' National Cyber Security Centre is warning of active exploitation of a macOS authentication bypass vulnerability. Hackers are using the flaw to deploy Monero miners on compromised systems.
The Administrative Office of the U.S. Courts will begin disclosing how frequently judges authorize government use of spyware for wiretapping suspects, marking a shift toward greater transparency in surveillance practices.
Shell has launched an investigation into a potential security incident following claims by the Clop ransomware gang that it stole 89GB of company data. The oil giant confirmed the probe but has not yet disclosed details about the breach's scope or impact.