Vendor
high
advisory
AI-Automated Campaign Targeting Online Retailers
3 TTPsA Chinese-speaking threat actor is leveraging a triad of autonomous AI agents (Strix, Cairn, and Hermes) to conduct vulnerability research, exploitation, and data exfiltration against hundreds of online retail platforms.
Magento +1
ai-threats
financial-crime
web-application-security
3t
critical
advisory
Mirasvit Full Page Cache Warmer for Magento 2 PHP Object Injection RCE (CVE-2026-45247)
2 rules 2 TTPs 1 CVEMirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability (CVE-2026-45247) that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Full Page Cache Warmer for Magento 2 +1
php-object-injection
rce
magento
web-application
cve-2026-45247
2r
2t
1c