DAILY BRIEFING
Max severity SAP Commerce Cloud flaw now targeted in attacks
Today's briefing covers active attacks on a critical SAP Commerce Cloud flaw, a major RingCentral data exposure, a ransomware investigation at Shell, and a insider extortion conviction.
5 stories2 min read

Threat actors are demonstrating rapid turnaround times between patch disclosures and active exploitation. Organizations face immediate pressure to remediate critical software flaws as attackers actively probe internet-facing systems shortly after vulnerabilities are published.
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched three days ago is actively being exploited in attacks, according to threat intelligence firm Defused.
- Why it matters
- Organizations running unpatched instances of SAP Commerce Cloud face immediate risk of remote code execution and system compromise by active attackers.
Shell investigates 'potential incident' after Clop data theft claims
Shell is investigating a potential security incident following claims by the Clop ransomware gang that it stole 89GB of data from the energy company.
- Why it matters
- If confirmed, the breach could expose sensitive operational or corporate data belonging to Shell.
RingCentral data breach exposed info of 1.6 million accounts
The ShinyHunters extortion group stole personal information belonging to 1.6 million RingCentral accounts following a July breach, according to Have I Been Pwned.
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software was sentenced to two years in prison for attempting to extort $2.5 million from his former employer after stealing corporate data.
Who’s Tracking You? Use This New Service to Find Out
Security researchers launched DecryptAds, a free service that aggregates and correlates public adtech transparency files like ads.txt, app-ads.txt, and sellers.json to help identify tracking entities, malvertising sources, and supply-chain integrity issues across websites and mobile apps.
- Why it matters
- Adtech ecosystems conceal privacy risks, malicious ad networks, and fraudulent domains through complex supply chains that are difficult to trace using single manifest files.
- What to do
- Use DecryptAds to audit third-party ad tracking partnerships and inspect digital supply-chain risks.
Key takeaways
- Patched critical SAP Commerce Cloud RCE vulnerability is facing active exploitation attempts within days of patch release.
- ShinyHunters extortion group compromised 1.6 million RingCentral accounts during a July security breach.
- Shell is actively investigating a potential security incident following Clop ransomware group's claim of stealing 89GB of data.
- A former contractor received a two-year prison sentence for a $2.5 million insider data theft and extortion scheme against Brightly Software.
- DecryptAds launched a free adtech transparency service to help researchers map supply chain security and privacy threats across websites and apps.