Russia’s Sandworm group spent the week working through Cisco firewall management consoles, exploiting a maximum-severity authentication bypass to deploy credential-harvesting implants on networks meant to protect their organizations. Ransomware operators followed close behind, using a different Cisco flaw with hardcoded credentials baked in. Meanwhile, a zero-day named StyleSmuggler (CVSS 10.0) turned Adobe Commerce and Magento storefronts into Rust backdoor delivery vehicles — unauthenticated, no user interaction required.