ZeroHour

Search: “Shopware”

13 stories

Shopware fixes Store API vulnerability allowing administrator takeover

Sansec discovered a Shopware 6 Store API flaw enabling administrator takeover; merchants should immediately update to 6.7.13.1 or 6.6.10.23.

Security firm Sansec discovered and confirmed a vulnerability in Shopware 6.7.12.2, then the latest stable release, that allows attackers to take over administrator accounts through the Store API. Shopware has released patches, and merchants are urged to update immediately to 6.7.13.1 or 6.6.10.23. No exploitation activity or CVE identifier is mentioned in the disclosure text.

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 21d agoPolicy & legal1