A critical vulnerability (CVE-2025-26849) in Docusnap allows attackers to decrypt sensitive system data due to a static encryption key used for inventory files. This flaw grants domain users read access to files, facilitating data extraction. Despite attempts to patch the issue, researchers found hardcoded keys still present in newer versions. Users should audit permissions and apply necessary patches.

M&S boss urges shoppers to visit stores in person as it battles cyber-attack – The Guardian
Marks & Spencer’s CEO, Stuart Machin, apologized for recent service disruptions caused by a cyber attack, assuring customers that the company is working tirelessly to