Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 6, 2026

Attackers have been exploiting an unpatched, unauthenticated code-execution vulnerability in all current versions of Magento Open Source and Adobe Commerce since September 4, planting a persistent Rust backdoor under a fake kernel-thread name; with no vendor fix before Adobe's September 8 release, Sansec and Disrex recommend disabling GraphQL, adding proc_open to disable_functions, mounting /tmp and /dev/shm with noexec, and—on already-compromised hosts—removing the cron entry before killing the process, then rotating the crypt key, all admin passwords, and every payment-provider API key in app/etc/env.php. In the same period, SonicWall confirmed active exploitation of two zero-days in SMA 1000 appliances, a threat actor is actively targeting internet-exposed Sangoma Switchvox instances through a recently patched SQL injection, and JetBrains disclosed that attackers breached its Cadence cloud service via an unpatched TeamCity deserialization flaw, extracting AWS IAM credentials from a 2024 backup and prompting all users to revoke every credential and treat all prior executions as untrusted.

Compiled by the Slugnet Editorial System. Published Sep 6, 2026, 7:24 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    Help Net Security

    Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

    What happened

    Anthropic is locking users out of their Claude accounts after infostealer malware compromised their login sessions. Anthropic locked users out of their Claude accounts after infostealer malware compromised their login sessions.

    Why it ranks #1

    Anthropic locked users out of their Claude accounts after infostealer malware compromised their login sessions.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Check internet-exposed Sangoma Switchvox instances for compromise indicators related to the actively exploited SQL injection flaw (CVE-2026-9586).

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    What happened

    Sansec disclosed that attackers are actively exploiting an unpatched, unauthenticated vulnerability in Magento Open Source and Adobe Commerce to execute code and install a persistent backdoor on store servers. The attack chain plants malicious PHP in a log file and triggers its execution via the platform's standard "Payment Transaction Failed Reminder" email, affecting all current versions including 2.4.9. Sansec advises stores not running its Shield product to temporarily disable GraphQL until Adobe releases a fix, and recommends rotating Magento credentials wherever the backdoor process has been identified.

    Why it ranks #2

    Sansec disclosed that attackers are actively exploiting an unauthenticated zero-day in Magento Open Source and Adobe Commerce to execute code and install a persistent backdoor, a threat affecting all current versions including 2.4.9.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    Schneier on Security

    Security Vulnerability in a Voting System

    What happened

    Bruce Schneier demonstrated that an unpatched vulnerability in voting scanners used by 21 states allows the recovery of ballot order from publicly available cast-vote records and early voting logs. By leveraging AI coding agents, he successfully analyzed voter behavior in Georgia’s May 2026 primary without accessing non-public data or physical machines. This exposure enables the linkage of specific ballots to individual voters, compromising ballot secrecy if the voting sequence is known.

    Why it ranks #3

    Bruce Schneier demonstrated that an unpatched vulnerability in voting scanners used by 21 states allows the recovery of ballot order from publicly available cast-vote records and early voting logs, enabling the linkage of specific ballots to individual voters and compromising ballot secrecy.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Treat election software updates with the same urgency as other security-critical systems.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

    What happened

    Elastic Security Labs identified four persistent modules linked to the REVSTEALER infostealer that remain on infected systems after the primary malware deletes itself. One of these components, LockAppHost, disables Windows Update and Microsoft Defender services to hide a cryptocurrency miner within legitimate system processes. Elastic identified that REVSTEALER reaches victims mainly through game-cheat lures and has been packaged as pirated or impersonated software, including a fake "Claude Opus 5 Free Desktop" application, but did not report observing the four linked modules delivered onto a live host.

    Why it ranks #4

    Elastic Security Labs identified four persistent modules linked to the REVSTEALER infostealer that remain on infected systems after the primary malware deletes itself, with one component, LockAppHost, disabling Windows Update and Microsoft Defender services to hide a cryptocurrency miner within legitimate system processes.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Change passwords and terminate active sessions, as the stealer captures session cookies and Chrome App-Bound Encryption keys, making a simple password reset insufficient.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    BleepingComputer

    IDScan sued over alleged data breach affecting 153 million drivers

    What happened

    A dark-web service called “Nexus” advertised the sale of over 153 million U.S. and Canadian driver’s license scans, a leak that Brian Krebs traced to identity verification provider IDScan. The FBI’s New Orleans office has confirmed an investigation into the incident, while multiple lawsuits have been filed in Louisiana alleging that IDScan failed to protect client data. IDScan has not publicly confirmed the breach or the number of affected individuals.

    Why it ranks #5

    A dark-web service advertised 153 million driver’s license scans traced to IDScan, prompting an FBI investigation and lawsuits, though IDScan has not confirmed the breach.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    What happened

    JetBrains disclosed that threat actors exploited CVE-2026-63077, an unpatched critical vulnerability in TeamCity, to breach its Cadence cloud service between August 8 and 24, 2026. The intrusion allowed attackers to access a 2024 server backup containing AWS IAM credentials, user email addresses, and potentially synchronized source code. JetBrains has taken the affected server offline and is urging users to revoke all credentials and treat recent executions as untrusted.

    Why it ranks #6

    JetBrains disclosed that threat actors exploited CVE-2026-63077, an unpatched critical vulnerability in TeamCity, to breach its Cadence cloud service between August 8 and 24, 2026, accessing a 2024 server backup containing AWS IAM credentials, user email addresses, and potentially synchronized source code.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    BleepingComputer

    Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

    What happened

    Netskope researchers identified a campaign using over 5,400 compromised WordPress and PrestaShop sites to deliver ClickFix payloads stored in BNB Smart Chain smart contracts. The initial lure instructs users to execute a PowerShell command, while a newer variant establishes a covert WebRTC data channel to fetch and run JavaScript directly in browser memory.

    Why it ranks #7

    Netskope identified a campaign using over 5,400 compromised sites to deliver ClickFix payloads stored in BNB Smart Chain smart contracts, with variants executing PowerShell or fetching JavaScript via WebRTC.

    Who should care

    CISOs and security leaders

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    What happened

    Broadcom released security updates for VMware Workstation and Fusion 25H2 and 26H1 to address two vulnerabilities, including CVE-2026-59346, an integer overflow that permits local administrators to execute arbitrary code on the host. The second flaw, CVE-2026-59347, is a stack-based buffer overflow in HGFS that allows local attackers to run code as the VMX process. Broadcom confirmed that no workarounds exist and that the issues are resolved in the 26H1u1 releases.

    Why it ranks #8

    Broadcom released security updates for VMware Workstation and Fusion 25H2 and 26H1 to address two vulnerabilities, including CVE-2026-59346, an integer overflow that permits local administrators to execute arbitrary code on the host.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

    What happened

    Trezor disclosed that a breach at its shipping provider, ShipMonk, exposed the names, contact details, and order numbers of 67,000 U.S. customers. The incident resulted from the zero-day exploitation of a critical SQL injection flaw in Metabase, which allowed unauthorized access to data that ShipMonk had previously confirmed was deleted.

    Why it ranks #9

    Trezor disclosed that a zero-day SQL injection exploit in Metabase allowed unauthorized access to the names, contact details, and order numbers of 67,000 U.S. customers at its shipping provider, ShipMonk, despite ShipMonk's prior confirmation that this data had been deleted.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Schneier on Security

    Using a VM to Contain an AI Agent

    What happened

    Schneier argues that standard virtual machines fail to contain modern, cyber-capable AI agents because the necessary features for useful work, such as network access and displays, introduce exploitable attack surface. The post notes that once an agent requires credentials or fresh data to perform tasks, the sandbox boundaries leak by design, shifting the security risk from the code the agent executes to the data it chooses to transmit outward.

    Why it ranks #10

    Schneier argues that standard virtual machines fail to contain modern, cyber-capable AI agents because the necessary features for useful work, such as network access and displays, introduce exploitable attack surface.

    Who should care

    CISOs and security leaders

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email