Skip to Content

Security News Update: How Were BigCommerce Stores Exposed Through the Ribon App Integration? and more

BigCommerce Stores Exposed Through Compromised App

Attackers used stolen Ribon credentials to access merchant customer data without breaching BigCommerce’s core platform.

Exposed information included customer names, email addresses, phone numbers, and shipping addresses, creating potential opportunities for follow-on social engineering.

I’d use this incident to ask how much customer data an attacker could reach if one of your third-party credentials were stolen today.

Inventory connected applications, enforce least privilege, and monitor for unusual API activity or unexpected data exports.

Apple Patches iPhone Zero-Day Under Attack

Apple patched a CoreGraphics zero-day reportedly used in targeted iPhone attacks, though details remain limited.

CVE-2026-86950 can allow arbitrary code execution when a vulnerable device processes a maliciously crafted file.

Without knowing the file type or delivery method, defenders have little to hunt for, so quickly patching vulnerable devices can reduce the window of exposure.

Apply the patch and review device telemetry for unusual processes or activity after suspicious files are opened.

ShinyHunters Revives PeopleSoft Attacks With WAF Bypass

ShinyHunters is exploiting a critical PeopleSoft flaw using a one-character URL change to bypass WAF rules and deploy web shells.

Successful exploitation can give attackers unauthenticated remote code execution and potentially full control of affected PeopleSoft systems.

If attackers can bypass a WAF rule by changing one character, I’d treat that rule as temporary protection while getting the actual vulnerability patched.

Patch affected systems, hunt for web shells, and rotate credentials accessible to the PeopleSoft service account.

Storm-2570 Reuses Playbook Across Ransomware Attacks

Microsoft says Storm-2570 has used four ransomware families while reusing the same attack tactics.

The group repeatedly uses RMM tools, credential theft, tunneling, and security tampering across attacks.

What I’d look for is legitimate RMM showing up where it doesn’t belong. By the time an obvious ransomware indicator appears, you may have already missed much of the intrusion.

Baseline approved RMM tools and alert on unauthorized deployments, renamed binaries, and attempts to disable endpoint protections.

AI Agents Need a Smaller Blast Radius

AI agents are gaining access to sensitive data and operational workflows, creating new risks when autonomous actions extend beyond what their operators intended.

Least privilege is only a starting point because agents also need hard limits on transactions, data transfers, and other high-impact actions.

Valid credentials don’t make an agent’s actions safe. I’d require separate human approval for anything that can expose data, move money, or alter production systems.

Define each agent’s blast radius and enforce limits on what it can access and do.

Still on iOS 26? Patch Apple’s Zero-Day

Apple has patched a CoreGraphics zero-day that can trigger arbitrary code execution the second a vulnerable device processes a sketchy file. Apple warned that CVE-2026-86950 may have already been exploited in an “extremely sophisticated” attack against specific targets running versions prior to iOS 27. Conveniently, the company hasn’t disclosed exactly how the malicious payload is being delivered.

If you’re still dragging your feet on updating, the procrastination train stops here. Install iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1 immediately. Or just rip the Band-Aid off and make the jump to OS 27. Navigate to Settings or System Settings > General > Software Update, and verify that your managed fleet actually swallowed the patch.

That “Remind Me Later” button has had enough chances.

FBI Breach May Expose Entire Workforce

The FBI is operating under the comforting assumption that the ShinyHunters breach of FBIJobs.gov exposed the personal data of literally every single employee. While the ultimate scope remains unconfirmed, records reviewed by The New York Times include home addresses, Social Security numbers, emergency contacts, and sensitive unit assignments.

The hackers pinky-promised they won’t publish the full trove, although a sample exposing thousands of personnel is already circulating. Because the leak is an absolute counterintelligence nightmare ripe for harassment, the bureau’s groundbreaking advice to its agents is to simply ignore unknown callers and flag suspicious texts.

Calling it a “marketing campaign” won’t make the data disappear.