A critical vulnerability (CVE-2025-27218) in Sitecore Experience Platform allows unauthenticated attackers to execute arbitrary code on unpatched systems. Discovered by Assetnote, it exploits insecure deserialization in versions 8.2-10.4. Sitecore recommends immediate upgrades to patch the flaw, while emphasizing the need for secure deserialization practices to mitigate risks of mass attacks and server compromise.

Hacked health firm HCRG demanded journalist ‘take down’ data breach reporting, citing UK court order
A US cybersecurity journalist, going by the pseudonym Dissent Doe, has refused to comply with a UK court-ordered injunction, which demanded the removal of two