// #architecture
1 article
Commentary tagged #architecture
The Third-Party Plugin Is the Perimeter Now — Magento Today, Your Stack Next
CVE-2026-45247 in the Mirasvit Magento extension continues a pattern that security teams have been watching for years: the attack surface of any complex platform is not defined by the core platform's security — it is defined by every third-party component installed on it. This is not a Magento problem. It is an architecture problem that affects every enterprise platform stack.
CipherWatch Editorial
Security Intelligence Platform
Hypervisor Escapes Should Change How Enterprise Architects Design Isolation — They Rarely Do
VMware ESXi cross-tenant code execution at Pwn2Own Berlin 2026 demonstrates again that virtualisation is not a security boundary. Yet enterprise architecture continues to treat hypervisor isolation as equivalent to physical isolation. The security implication of this assumption has been known for years and consistently under-acted upon.
CipherWatch Editorial
Security Intelligence Platform
Managed File Transfer Is a Permanent Attack Surface and You Should Treat It That Way
MOVEit's latest critical vulnerability is not a surprise — it is the latest instalment in an unending series. The industry keeps treating each managed file transfer vulnerability as an exceptional event requiring exceptional response, when the correct model is to treat MFT platforms as inherently hostile internet-facing infrastructure requiring architectural controls that assume compromise is inevitable.
CipherWatch Editorial
Security Intelligence Platform