# Archive

Browse past daily curated stories

Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05

Tuesday, September 08, 2026

  1. 1
    0
    BleepingComputer general
    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    A zero-day vulnerability dubbed 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce is being actively exploited to deploy a Linux backdoor on online stores. The flaw allows unauthenticated code execution, and no patch was available at time of disclosure, making immediate mitigation critical for the large population of e-commerce merchants running these platforms.

  2. 2
    0
    SecurityWeek general
    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    The StyleSmuggler zero-day in Adobe Commerce and Magento enables attackers to execute arbitrary code and install a stealthy backdoor across all current versions of both platforms. Active exploitation in the wild targeting online stores means payment data and customer PII are at immediate risk for unpatched merchants.

  3. 3
    0
    BleepingComputer general
    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    Attackers are actively chaining two recently disclosed MikroTik RouterOS vulnerabilities to gain full administrative control over routers with SSH exposed to the internet, with confirmed exploitation dating to at least September 2, 2026 per CERT Polska. The worm-like propagation potential across internet-exposed MikroTik devices makes this a high-priority patching issue for network administrators.

  4. 4
    0
    The Hacker News general
    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    CERT Polska issued an attack warning on September 5, 2026 documenting unauthenticated exploitation of MikroTik routers via internet-exposed SSH, with successful compromises confirmed from at least September 2. Attackers gain full administrative control without credentials, posing severe risk to the large global install base of MikroTik edge devices.

  5. 5
    0
    BleepingComputer general
    N-able patches max severity N-central flaw amid ongoing attacks

    N-able released a fourth emergency hotfix in five weeks for its N-central RMM platform to address a maximum-severity unauthenticated remote code execution flaw, with all on-premises builds below version 2026.3.1.14 remaining vulnerable including those patched with Hotfix 3 the previous day. N-able's incident notice indicates the flaw has been exploited in the wild, making immediate patching critical for MSPs relying on N-central to manage client infrastructure.

  6. 6
    0
    The Hacker News general
    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    N-able's fourth N-central hotfix in five weeks (Hotfix 4) addresses an unauthenticated RCE flaw affecting every on-premises build below 2026.3.1.14, including systems updated to Hotfix 3 just one day prior. The contradictory messaging between N-able's incident notice (confirming wild exploitation) and release notes (calling it unconfirmed) creates uncertainty for MSPs urgently assessing their exposure.

  7. 7
    0
    BleepingComputer general
    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    The BigBear 2.0 phishing-as-a-service framework successfully bypassed MFA at 258 organizations and harvested over 5,000 Microsoft 365 credentials using adversary-in-the-middle token theft techniques. The scale and MFA-bypass capability of this platform underscores that TOTP and push-based MFA alone are insufficient against AitM proxy-based credential theft.

  8. 8
    0
    SecurityWeek general
    Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    A threat actor named Nightmare Eclipse has published proof-of-concept zero-day exploits targeting CrowdStrike, Nvidia, and Avast products, with each exploit achieving privilege escalation to SYSTEM-level shell access. The simultaneous release of PoCs against three high-profile security and driver vendors significantly raises the risk surface for enterprise endpoints running these products.

  9. 9
    0
    The Hacker News general
    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Huntress documented three unrelated incidents where backdoored ConnectWise ScreenConnect clients are spreading a four-stage VBScript malware chain to every newly connected host in a worm-like propagation pattern. Initial access vectors included Quick Assist tech-support scams, phishing-delivered MSI installers, and a fake software package, indicating multiple threat actors are abusing legitimate RMM tooling for lateral movement.

  10. 10
    0
    The Hacker News general
    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    TantoSec released a working public exploit chain that leverages an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution, though only against applications in a specific non-default configuration. Progress patched the vulnerability chain in July 2026, but the public PoC release substantially raises exploitation risk for organizations that have not yet applied the patch.