Subscribe
Experience Digest

Flagship

Security intelligence for enterprise commerce — analysis of the Adobe Commerce & Experience Manager landscape, and the preemptive takes the automated bulletins can’t provide.

Latest analysis

Supply Chain Lead story

You Can't Shop Your Way to a Safe Extension Stack

Sansec’s public vulnerability database for Magento extensions is topped by the biggest, most established vendors — not because they’re careless, but because scale and honest disclosure are what put a module on the list. It cuts both ways, and the lesson isn’t which vendors to …

· 6 min read Read the analysis →
Pattern Analysis

Adobe Keeps Patching the Same Cracks: Inside July's Critical Commerce and AEM Bulletins

July 14 wasn’t one bulletin — it was a week. APSB26-73 shipped seven Adobe Commerce CVEs (two critical RCEs); the parallel AEM bulletin …

security

Two Patch Cycles, Same Cracks: What Commerce's 2026 CVE Pattern Is Telling You

APSB26-05 and APSB26-49 landed two months apart. Both lean hard on Incorrect Authorization and Stored XSS. That’s not a coincidence — it’s …

security

APSB26-56: thirty-plus XSS findings in one AEM bulletin — what the batch tells you

Adobe’s June 2026 AEM bulletin contains 27 confirmed stored XSS and 9 DOM-based XSS CVEs, all CVSS 5.4. The count is the signal — not the …

security

Before the Next Wave: What Magento Shops Must Do After the Composer Token Leak

GitHub is rolling out its token format change again. If your CI still pins Composer or hasn’t tightened workflow permissions, you’re not …

Analysis

GorgonAgora: Inside the 4,800-Storefront Checkout Skimming Machine

Sansec research reveals 4,880+ fake .shop storefronts impersonating real brands with a custom checkout SDK and real-time 3DS relay. The attack …

Attack Analysis

The Perforce Driver You Never Knew You Had: Composer CVE-2026-40261 and CVE-2026-40176

Two command injection vulnerabilities in Composer’s Perforce driver are exploitable even if you’ve never touched Perforce. For Magento …

Attack Analysis

Three Signals from November: What the Bulletins Don't Say

The November 2025 bulletin wave included a CVSS 9.1 session takeover, a stored XSS in Magento-lts, and an active Xurum webshell campaign. Read …

Follow via RSS or on Micro.blog.