A critical RCE vulnerability (CVE-2025-32432) in Craft CMS, affecting versions prior to 3.9.15, 4.14.15, and 5.6.17, is actively exploited to steal data. Attackers use a chain of vulnerabilities, prompting Craft CMS to release patches. Users should update immediately or block suspicious payloads. Compromised systems require security key resets and user credential rotations.

M&S issues update as crippling nationwide IT outage still ongoing – The Sun
Marks & Spencer (M&S) halted online orders in the UK and Ireland following a cyber attack, leading to a 5% drop in share price. Physical