A critical security flaw in Apache Camel (CVE-2025-27636) allows attackers to execute arbitrary commands via case-sensitive header injection in versions 4.10.0-4.10.1, 4.8.0-4.8.4, and 3.10.0-3.22.3. This vulnerability enables remote code execution by manipulating HTTP headers, prompting immediate remediation through upgrades and enhanced header filtering. Active exploitation observed in Kubernetes environments highlights broader risks.

M&S issues update as crippling nationwide IT outage still ongoing – The Sun
Marks & Spencer (M&S) halted online orders in the UK and Ireland following a cyber attack, leading to a 5% drop in share price. Physical