September 9, 2026
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
September 8, 2026
- StyleSmuggler now has a payload profile. Sansec reports the first exploitation on 4 September against a target running the latest security updates; the exploit abuses Magento's template system via PHP code injection to generate a fake "failed-payment" email that triggers execution, installing a small Rust backdoor disguised as
[kworker/u:8:0], or in newer samples as fc-cache under ~/.cache/fontconfig/, with a cron job every 30 minutes for persistence. Earlier samples beaconed over TLS/WebSockets; newer ones disguise C2 as NTP, sending UDP to port 123 with time-server-styled hostnames, and check TracerPid — if tracing is active the malware installs but stays silent. Sansec flags an unexpected surge of "Payment Transaction Failed Reminder" emails as an indicator and recommends disabling GraphQL until Adobe ships a fix (BleepingComputer, SecurityWeek). @Dinosn claims exploitation attempts have been "massive" and says he will publish a PoC and lab after a patch lands — treat the scale claim as unverified (earlier coverage).
· Vulnerabilities & Exploits
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 7, 2026
- StyleSmuggler, the unpatched Magento/Adobe Commerce RCE, gained a second implant build on 6 September: Sansec reports arm64 and x86-64 variants that masquerade as
fc-cache instead of [kworker/u:8:0], copy themselves to ~/.cache/fontconfig/fc-cache, install a cron entry restarting them twice an hour, and disguise C2 as time sync. The Rust backdoor beacons to 99.84.67.186; Sansec says it has no indication the backdoor has been weaponised yet and that no other vendor detects it. The unauthenticated chain reproduces on clean 2.4.7, 2.4.8 and 2.4.9, and the first victim was on 2.4.6-p15 with July and August patches applied. Adobe's next scheduled security release is 8 September; it is not yet known whether it covers this. Interim mitigation is disabling GraphQL (earlier coverage).
· Exploitation & Active Attacks
in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
September 6, 2026
- An unpatched Magento and Adobe Commerce zero-day called StyleSmuggler is already backdooring stores. The RCE has no fix identified in the available reporting. The Hacker News details the active exploitation, and watchTowr recommends disabling GraphQL pending remediation.
· Vulnerabilities & Exploits
in One Loophole, 100 Agents, 27 Minutes
August 16, 2026
- Adobe Commerce / Magento CVE-2026-71362 now has a reproducible lab — a Docker environment reproducing the customer-session identity-switch account-takeover flaw (APSB26-92, CVSS 9.1) was published, lowering the bar to study a bug already seen exploited within hours of disclosure (earlier coverage). @Dinosn
· Vulnerabilities & Exploits
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
August 14, 2026
- Adobe Commerce/Magento CVE-2026-71362 is being exploited within hours of disclosure. The critical flaw lets attackers hijack customer accounts; exploitation attempts were observed almost immediately after Adobe shipped the patch. (BleepingComputer, SecurityWeek)
· Vulnerabilities & Exploits
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 13, 2026
- An inverse language model reconstructs a proprietary prompt from an LLM's output with near-perfect accuracy. Researchers at IIT Bombay and Adobe Research say their "Previous-Token Prediction" method needs no model weights and generalizes across models — a direct threat to organizations relying on secret system prompts, per The Decoder.
· AI & Model Security
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
August 3, 2026
- Adobe Campaign Classic patched CVE-2026-48449, a CVSS 10.0 incorrect-authorization bug allowing code execution with no user interaction, The Hacker News reports. No exploitation reported yet, but the unauthenticated profile makes it one to prioritize.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 23, 2026
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 3, 2026
- Adobe patched seven CVSS 10.0 flaws in ColdFusion (APSB26-68) and Campaign Classic, enabling arbitrary code execution, privilege escalation, arbitrary file read, and security-feature bypass; watchTowr published a detailed breakdown centered on RDS path-validation and upload-endpoint fixes. Adobe is moving to a twice-monthly bulletin cadence, attributing the surge to frontier AI models finding bugs. watchTowr, The Hacker News.
· Vulnerabilities & Exploits
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire