A curated dispatch from GajShield

The GajShield Gazette

Lead story

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Critical Adobe Commerce Account-Takeover Flaw Shows Why Session Identity Must Never Be Trusted Without Server-Side AuthorizationThe critical CVE-2026-71362 vulnerability affecting Adobe Commerce and Magento Open Source demonstrates how a relatively subtle authorization fai…

Also today
In brief

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Three Actively Exploited Vulnerabilities, Highlighting Risks Across Firewalls, Windows Endpoints and Analytics PlatformsCISA’s ad…

Aug 12, 2026

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Delta Flight Wi-Fi Incident Shows Why Rogue Wireless Networks Remain an Effective Tool for Phishing and DisruptionDelta Air Lines’ investig…

Aug 12, 2026

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

Sandworm Fake Job Campaign Shows Why IT Professionals Are Becoming Strategic Initial-Access TargetsThe Sandworm-linked UAC-0145 campaign ta…

Aug 12, 2026

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Zoom Annotation Vulnerabilities Show How a Routine Meeting Feature Can Become a Zero-Click Attack SurfaceThe newly disclosed vulnerabilitie…

Aug 12, 2026

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Actively Exploited Cisco ASA and FTD VPN Flaw Shows Why Availability of Security Infrastructure Is Itself a Security RequirementCisco’s war…

Aug 12, 2026

TCS Flags Employee Data Leak Claims, Rules Out Customer Impact - BW People

TCS Employee Data Leak Claims Highlight Why Historical Workforce Information Remains a Security RiskTata Consultancy Services’ disclosure t…

Aug 12, 2026

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Sandworm’s Trojanized WireGuard Campaign Shows Why IT Professionals Are Becoming High-Value Social Engineering TargetsA new campaign attrib…

Aug 12, 2026

Wesco confirms security incident after ExfilSquad claims data theft

Wesco Security Incident Highlights Why Cloud CRM Platforms Have Become High-Value Data-Theft TargetsWesco International’s confirmation of a…

Aug 11, 2026

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla GPG Key Exposure Shows Why Software Signing Infrastructure Must Be Protected Like Production CodeMozilla’s decision to revoke and r…

Aug 11, 2026

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Gunra Ransomware Campaign Shows How Edge and OT Vulnerabilities Can Become Gateways to Enterprise-Wide CompromiseThe growing activity assoc…

Aug 11, 2026

Exclusive: Jeju Air Customer Data Exposed on Naver

Jeju Air Customer Data Exposure Shows Why Sensitive Information Must Be Protected at Every LayerThe reported exposure of Jeju Air customer …

Aug 11, 2026