
Autonomous penetration-testing agents rely on target responses. These responses guide both subsequent actions and the final report. A deceptive response can therefore redirect both the attack trajectory and the agent's verification process. However, final

Binary code representation learning is a fundamental problem in software security and reverse engineering. Existing methods mainly learn function-level embeddings that capture coarse-grained semantic relationships between binary functions, but they largel



Attackers have wasted no time exploiting a maximum-severity vulnerability in SAP Commerce Cloud, with multiple security outlets reporting active attacks just days after the vendor shipped a fix. BleepingComputer reported that threat intelligence company Defused observed the remote code execution flaw, tracked as CVE-2026-58231, already being targeted in attacks. eSecurity Planet echoed that finding, reporting that the SAP Commerce Cloud flaw is being actively exploited in the wild. "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused." The speed of exploitation underscores how quickly threat actors move once a patch exists, and the underlying issue is especially dangerous. SOCRadar described CVE-2026-58231 as a maximum-severity improper authorization vulnerability in the Data Hub Adapter for SAP Commerce Cloud, while cysecurity.news noted it carries a perfect CVSS score of 10.0 and stems from insufficient authorization checks and inadequate input validation. "An unauthenticated attacker can abuse a default authentication client, potentially enabling arbitrary code execution." That ease of abuse likely explains the rapid targeting, and security guidance now centers on getting systems patched before attackers can find exposed instances. fieldeffect.com urged organizations to prioritize patching internet-accessible systems, verify that updates have been fully deployed to production environments, and restrict access to exposed integration interfaces while remediation activities are underway. "Prioritize patching internet-accessible systems, verify that updates have been fully deployed to production environments, and restrict access to exposed integration interfaces while remediation activities are underway." Given SAP Commerce Cloud's role in customer-facing sales operations and its connections to business-critical systems, fieldeffect.com said organizations should review integrations, service account permissions, and network connectivity to understand the potential business impact. The Cyber Web Spider Blog likewise reported that hackers are exploiting the critical flaw and urged enterprises to patch immediately.

Frustrated customers have been left in the dark about deliveries that never arrived after the furniture seller took its systems down following a cyberattack last week.
A recent series of cyberattacks on U.S. water systems has exposed vulnerabilities across critical infrastructure during the Iran war.

eSecurity PlanetSAP Commerce Cloud RCE Flaw Actively Exploited














