SAP Commerce Cloud CVE-2026-58231 targeted in exploitation attempts
A maximum-severity vulnerability affecting SAP Commerce Cloud, tracked as CVE-2026-58231, is being targeted in exploitation attempts only days after SAP released a security update.
Our Managed Detection and Response Services provide continuous monitoring from a team who’ll neutralise any breaches at speed...
Gain access to malware experts to quickly contain threats and reduce future exposure to attacks...
Integrity360 has been recognised as a Gartner Representative Vendor.
Many organisations are choosing CyberFire MDR to strengthen their defences. Discover how it can protect your business in our brochure.
Cyber attacks often seem faceless, but hidden behind the headlines of financial loss and technical details there are very real human stories.
In 2025, we’re witnessing a shift in how ransomware operates, who it targets, and the consequences of falling victim.
Stay ahead of the latest cybersecurity industry developments, advancements and threats, and understand how you can best protect your organisation.
Do you know what your company’s network vulnerabilities are? Businesses that invest in penetration testing do.
If your business handles credit card data, PCI DSS compliance isn’t optional—it’s critical. From retailers and e-commerce platforms to service providers and financial institutions, securing credit card data is critical to customer trust and preventing fraud.
Stay informed with the latest cybersecurity news with our weekly threat roundups.
Confused about cybersecurity? Our A-Z Glossary of terms can help you navigate this complicated industry.
For many small and mid-sized businesses, cybersecurity can feel overwhelming.
SOC 2 certification reflects Integrity360’s continued investment in strengthening cyber resilience for clients across highly regulated and high-risk industries.
Leading Canadian cybersecurity services provider Advantus360 joins Integrity360 creating the group’s first hub in North America
Posts about:
A maximum-severity vulnerability affecting SAP Commerce Cloud, tracked as CVE-2026-58231, is being targeted in exploitation attempts only days after SAP released a security update.
CEVA Logistics, a global logistics and supply chain provider and subsidiary of CMA CGM Group, has disclosed a cyber incident impacting portions of its European contract logistics operations. The attack, which reportedly began on or around 29 July 2026, disrupted operations across at least eight European warehouses and resulted in shipment delays for multiple customers.
Digital Risk solutions provider CloudSek has published a list of organisations affected by a high profile campaign by TeamPCP.
Cisco has released security updates addressing 24 vulnerabilities across multiple enterprise products, including several critical-severity flaws affecting Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability, CVE-2026-20079, impacts FMC and carries a CVSS score of 10.0, enabling unauthenticated remote attackers to bypass authentication and gain root-level access. Cisco has also disclosed critical flaws in IOS XE and Catalyst SD-WAN that could allow command injection, privilege escalation, and unauthorized access.
On August 4, 2026, a sophisticated software supply chain attack dubbed ChainDrop struck the npm ecosystem through the compromise of a maintainer's GitHub account for the widely used Keyv and Cacheable open-source packages. The resulting self-propagating worm spread to over 2251 versions of 452 unique packages with approximately 2 billion monthly downloads, affecting organisations including Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.
A critical vulnerability was discovered by N-Able in it's product N-Central, a remote management appliance used for IT administration.
The "wp2shell" exploit chain represents a critical security event targeting the fundamental architecture of the WordPress ecosystem. This is a pre-authentication Remote Code Execution (RCE) vulnerability residing entirely within WordPress Core. It requires no third-party plugins, themes, or authenticated access to execute. A single crafted HTTP request against a default, "stock" installation can result in unauthenticated attacker gaining full system control.
Check Point has disclosed and patched a critical zero-day vulnerability, CVE-2026-16232, affecting its SmartConsole management platform. The flaw is an authentication bypass vulnerability that enables unauthenticated remote attackers to obtain a valid application login token and authenticate with administrator-level privileges under specific conditions. Check Point confirmed that the vulnerability is being actively exploited and has impacted a limited number of customers.
Security researchers have observed increased activity involving ACR Stealer, an information-stealing malware family associated with the Amatera Stealer ecosystem. The activity was particularly prevalent from late April through mid-June 2026 and has successfully compromised enterprise environments.
Ubiquiti has released security updates addressing seven critical vulnerabilities across multiple UniFi products. The flaws could allow attackers with network access to perform remote command execution (RCE), privilege escalation, unauthorised device modifications, and server-side request forgery (SSRF). Several vulnerabilities carry CVSS scores between 9.0 and 10.0, representing a significant risk to organisations using affected UniFi deployments.