Podium IT Tech Briefing
Adobe Commerce, TeamCity and hidden malware: what to ask your IT providers
Two actively exploited security flaws and malware designed to evade detection. Here’s what to ask your website and IT providers, and which checks matter.
Watch the video briefingCybercriminals are increasingly using crypters to hide malware from security software, making it harder for defenders to detect. Meanwhile, a critical vulnerability has been discovered in Adobe Commerce and Magento stores, which could allow attackers to execute code remotely. These developments highlight the evolving nature of cyber threats and the need for organisations to stay vigilant.
Introduction
Cybercriminals are using crypters to hide malware from security software, making it harder for defenders to detect. This is because security software and platforms such as VirusTotal are becoming more advanced, making it harder for cybercriminals to operate effectively.
Crypters and Malware
Crypters are financially motivated cybercriminals who typically advertise their services on dark web forums. They use specialised software to scramble the contents of a file, making it harder for security software to detect. This process creates a new ‘crypted malware’ file that hides its content and behaviour from detection services.
Adobe Commerce and Magento Vulnerability
A critical vulnerability has been discovered in Adobe Commerce and Magento stores, which could allow attackers to execute code remotely. The vulnerability is tracked as CVE-2026-75650 and is rated 10.0 on the CVSS scale. It is not clear how many stores in Australia are at risk, but the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has advised organisations to review their networks and environments for vulnerable versions of the ecommerce platforms.
A sensible next step
To protect against these threats, organisations should review their security software and ensure it is up to date. They should also review their ecommerce platforms and apply any necessary patches. Additionally, organisations should consider implementing a web application firewall (WAF) to detect and prevent attacks. The IT team should be responsible for implementing these measures and ensuring they are effective.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
