MEDIUMVulnerability
Global

ASOS Breach Reveals the Risks in Customer-Facing SaaS

·Source: Dark Reading

Updated:

Executive Summary

The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.

Analysis

The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.
Source Attribution

Originally published by Dark Reading on Oct 9, 2026.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-108707 — Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit...

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

CVE-2026-108707
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108598 — Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE...

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

CVE-2026-108598
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108551 — openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit...

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe

CVE-2026-108551
NIST NVD