# Archive
Browse past daily curated stories
Tuesday, September 08, 2026
-
1BleepingComputer generalMagento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce is being actively exploited to deploy a Linux backdoor on online stores. The flaw allows unauthenticated code execution, and no patch was available at time of disclosure, making immediate mitigation critical for the large population of e-commerce merchants running these platforms.
-
2SecurityWeek generalAdobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day in Adobe Commerce and Magento enables attackers to execute arbitrary code and install a stealthy backdoor across all current versions of both platforms. Active exploitation in the wild targeting online stores means payment data and customer PII are at immediate risk for unpatched merchants.
-
3BleepingComputer generalHackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively chaining two recently disclosed MikroTik RouterOS vulnerabilities to gain full administrative control over routers with SSH exposed to the internet, with confirmed exploitation dating to at least September 2, 2026 per CERT Polska. The worm-like propagation potential across internet-exposed MikroTik devices makes this a high-priority patching issue for network administrators.
-
4The Hacker News generalAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska issued an attack warning on September 5, 2026 documenting unauthenticated exploitation of MikroTik routers via internet-exposed SSH, with successful compromises confirmed from at least September 2. Attackers gain full administrative control without credentials, posing severe risk to the large global install base of MikroTik edge devices.
-
5BleepingComputer generalN-able patches max severity N-central flaw amid ongoing attacks
N-able released a fourth emergency hotfix in five weeks for its N-central RMM platform to address a maximum-severity unauthenticated remote code execution flaw, with all on-premises builds below version 2026.3.1.14 remaining vulnerable including those patched with Hotfix 3 the previous day. N-able's incident notice indicates the flaw has been exploited in the wild, making immediate patching critical for MSPs relying on N-central to manage client infrastructure.
-
6The Hacker News generalN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able's fourth N-central hotfix in five weeks (Hotfix 4) addresses an unauthenticated RCE flaw affecting every on-premises build below 2026.3.1.14, including systems updated to Hotfix 3 just one day prior. The contradictory messaging between N-able's incident notice (confirming wild exploitation) and release notes (calling it unconfirmed) creates uncertainty for MSPs urgently assessing their exposure.
-
7BleepingComputer generalBigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
The BigBear 2.0 phishing-as-a-service framework successfully bypassed MFA at 258 organizations and harvested over 5,000 Microsoft 365 credentials using adversary-in-the-middle token theft techniques. The scale and MFA-bypass capability of this platform underscores that TOTP and push-based MFA alone are insufficient against AitM proxy-based credential theft.
-
8SecurityWeek generalNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
A threat actor named Nightmare Eclipse has published proof-of-concept zero-day exploits targeting CrowdStrike, Nvidia, and Avast products, with each exploit achieving privilege escalation to SYSTEM-level shell access. The simultaneous release of PoCs against three high-profile security and driver vendors significantly raises the risk surface for enterprise endpoints running these products.
-
9The Hacker News generalRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Huntress documented three unrelated incidents where backdoored ConnectWise ScreenConnect clients are spreading a four-stage VBScript malware chain to every newly connected host in a worm-like propagation pattern. Initial access vectors included Quick Assist tech-support scams, phishing-delivered MSI installers, and a fake software package, indicating multiple threat actors are abusing legitimate RMM tooling for lateral movement.
-
10The Hacker News generalTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
TantoSec released a working public exploit chain that leverages an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution, though only against applications in a specific non-default configuration. Progress patched the vulnerability chain in July 2026, but the public PoC release substantially raises exploitation risk for organizations that have not yet applied the patch.