daily cyber × ai intelligence

index

tagged

[stylesmuggler]

4 editions · 4 items

September 8, 2026

  • StyleSmuggler now has a payload profile. Sansec reports the first exploitation on 4 September against a target running the latest security updates; the exploit abuses Magento's template system via PHP code injection to generate a fake "failed-payment" email that triggers execution, installing a small Rust backdoor disguised as [kworker/u:8:0], or in newer samples as fc-cache under ~/.cache/fontconfig/, with a cron job every 30 minutes for persistence. Earlier samples beaconed over TLS/WebSockets; newer ones disguise C2 as NTP, sending UDP to port 123 with time-server-styled hostnames, and check TracerPid — if tracing is active the malware installs but stays silent. Sansec flags an unexpected surge of "Payment Transaction Failed Reminder" emails as an indicator and recommends disabling GraphQL until Adobe ships a fix (BleepingComputer, SecurityWeek). @Dinosn claims exploitation attempts have been "massive" and says he will publish a PoC and lab after a patch lands — treat the scale claim as unverified (earlier coverage). · Vulnerabilities & Exploits

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited

September 7, 2026

  • StyleSmuggler, the unpatched Magento/Adobe Commerce RCE, gained a second implant build on 6 September: Sansec reports arm64 and x86-64 variants that masquerade as fc-cache instead of [kworker/u:8:0], copy themselves to ~/.cache/fontconfig/fc-cache, install a cron entry restarting them twice an hour, and disguise C2 as time sync. The Rust backdoor beacons to 99.84.67.186; Sansec says it has no indication the backdoor has been weaponised yet and that no other vendor detects it. The unauthenticated chain reproduces on clean 2.4.7, 2.4.8 and 2.4.9, and the first victim was on 2.4.6-p15 with July and August patches applied. Adobe's next scheduled security release is 8 September; it is not yet known whether it covers this. Interim mitigation is disabling GraphQL (earlier coverage). · Exploitation & Active Attacks

in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart