A critical Magento vulnerability named PolyShell exposes stores to unauthenticated file uploads, remote code execution, and account takeover risks, with active exploitation now observed.
Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.
Huntress reports active exploitation of a newly uncovered Gladinet CentreStack and Triofox vulnerability linked to hard coded cryptographic keys, enabling unauthorized access and remote code execution across affected systems.