September 8, 2026
- StyleSmuggler now has a payload profile. Sansec reports the first exploitation on 4 September against a target running the latest security updates; the exploit abuses Magento's template system via PHP code injection to generate a fake "failed-payment" email that triggers execution, installing a small Rust backdoor disguised as
[kworker/u:8:0], or in newer samples asfc-cacheunder~/.cache/fontconfig/, with a cron job every 30 minutes for persistence. Earlier samples beaconed over TLS/WebSockets; newer ones disguise C2 as NTP, sending UDP to port 123 with time-server-styled hostnames, and checkTracerPid— if tracing is active the malware installs but stays silent. Sansec flags an unexpected surge of "Payment Transaction Failed Reminder" emails as an indicator and recommends disabling GraphQL until Adobe ships a fix (BleepingComputer, SecurityWeek). @Dinosn claims exploitation attempts have been "massive" and says he will publish a PoC and lab after a patch lands — treat the scale claim as unverified (earlier coverage). · Vulnerabilities & Exploits
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited