Latest Security Updates

View All →
Security Research

GorgonAgora: Inside the 4,800-Storefront Checkout Skimming Machine

Security researcher Hunter Heaivilin has been mapping a skimming operation called GorgonAgora since August 2025. The dataset he handed to Sansec confirmed 4,880 fake storefronts — and urlscan.io’s CSS fingerprint matching suggests the real number is already above 6,000.

The attack pattern …

Security Research

CVE-2026-45247 (CRITICAL) CVSS 9.8

🔴 Severity: CRITICAL (CVSS 9.8)

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers …