vulnerability SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a critical security flaw in its Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability stems from insufficient authorization checks and input validation, posing a significant risk to data confidentiality, integrity,… The Hacker News · Aug 12, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-34265securitypatcharbitrary code execution
vulnerability 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A 29-year-old vulnerability, dubbed Squidbleed (CVE-2026-47729), exists in the Squid web proxy due to a heap over-read. This allows an attacker with proxy access to leak cleartext HTTP requests, including credentials and… The Hacker News · Jun 22, 2026 Medium CVE-2026-47729CVE-2026-50012heap_overflowhttpftp
vulnerability CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a widespread compromise of credentials associated with Fortinet devices, dubbed ‘FortiBleed.’ Approximately 74,000 Forti… CISA Advisories · Jun 18, 2026 High USGBcredentialsfirewallvpn
threat-intel The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th) This article highlights a significant security gap in Cloud Access Security Broker (CASB) deployments due to the increasing use of the QUIC protocol. CASBs, traditionally designed to inspect TCP traffic, fail to detect w… SANS Internet Storm Center · Jun 17, 2026 High quiccasbssl