Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Magento Zero-Day: Unpatched Adobe Commerce RCE Is Backdooring Online Stores

On 4 September 2026, attackers began exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce. Dutch e-commerce security firm Sansec disclosed the issue on 5 September and named it StyleSmuggler. The company said it published early because stores were being compromised in real time.

One Identity CEO talks winning CISO board pitch & identity fabric

Breaches will impact an organization greatly, regardless of industry or your role in it, and Larry Chinski, VP of enterprise strategy, caught up with CEO Praerit Garg to explore the challenges facing CISOs in trying to communicate this fact. Tune in for insights on learning to speak the ROI-focused language of the board when pitching a security budget. And keep watching for a discussion on the benefits behind a comprehensive identity fabric for your identity security.

Evaluating Risk Remediation Software for Enterprise Scalability

Enterprise software delivery is accelerating with more applications, more teams, more pipelines, more third-party code shipping faster than ever. And you can add the compounding risks of AI onto all of that. At the same time, compliance pressure is rising across development, security, and audit teams.

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of the platform. The vulnerability is classified as static code injection (consistent with CWE-96) in a public-facing application endpoint.

When Vulnerability Databases Are No Longer Enough

The NIST’s changes in how the National Vulnerability Database (NVD) operates have fundamentally shifted how organizations interpret the vulnerabilities published in this go-to registry. In the past, the NVD provided vulnerability enrichment data, such as CVSS scores, affected products, CWE classifications, and reference links.

What Is SIEM? How It Works With DLP to Detect Data Threats

Most security teams don’t lose the fight against data breaches because they lack tools. They lose because their tools don’t talk to each other. This is exactly the loophole that SIEM and DLP were built to close, together. Security information and event management gives you visibility into what’s happening across your entire environment. At the same time, data loss prevention gives you the control to stop sensitive information from leaving in the first place.

What is Identity Governance and Administration (IGA)?

Enterprises today manage thousands of identities across employees, contractors, applications, APIs, and machine-driven systems. In most environments, identities have become the primary security boundary, yet access remains fragmented, overprovisioned, and difficult to track. According to IBM's X-Force Threat Intelligence Index, identity-based attacks now account for nearly one-third of all intrusions, highlighting how identity has become one of the most targeted layers in modern cybersecurity.

How to Reduce Payment Fraud Risk Without Adding Customer Friction

Reducing payment fraud risk requires giving existing fraud controls enough context to distinguish higher-risk interactions from routine activity, rather than applying more checks to every customer. That distinction matters. UK Finance reported that criminals stole almost £1.3 billion through authorized and unauthorized fraud in the UK during 2025. Authorized push payment fraud alone accounted for £576.4 million, up 19% year over year.

Becoming a trusted business partner: 5 partnership strategies for Australian MSPs

A reliable service desk earns confidence. A trusted business partner earns a place in decisions about risk, growth and continuity. For Australian MSPs, that distinction matters because clients increasingly need more than a list of tools. They need clear advice about which risks to address, which outcomes to prioritise and how technology supports the business. Australian Cyber Security Centre guidance encourages organizations to scrutinize the cybersecurity measures used in outsourced ICT services.