Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 8, 2026

Adobe shipped the VULN-39341 hotfix for CVE-2026-75650 (StyleSmuggler), a template-injection flaw in Magento's payment-reminder pipeline that Sansec confirmed under active exploitation since September 4, with threat actors deploying a Rust-based Linux backdoor and a PHP web shell; Adobe requires both the patch and encryption-key rotation across affected Adobe Commerce and Magento Open Source versions through 2.4.9-2026-aug. In the same window, CERT Polska confirmed active exploitation of the MikroTrick chain (CVE-2026-67276 and CVE-2026-86060) against SSH-enabled MikroTik RouterOS devices, fixed in 6.49.21, 7.23.4, and 7.24.2, while Google patched a V8 type-confusion zero-day (CVE-2026-85046) under active exploitation in Chrome 152.0.7977.82.

Compiled by the Slugnet Editorial System. Published Sep 8, 2026, 7:30 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    What happened

    Adobe released a hotfix for CVE-2026-75650, a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that Sansec identified as being actively exploited since September 4, 2026. The flaw, dubbed StyleSmuggler, allows unauthenticated attackers to inject PHP code into the template system to achieve remote code execution. Threat actors have used this vulnerability to deploy a Rust-based Linux backdoor and a PHP web shell on compromised e-commerce servers.

    Why it ranks #1

    Adobe released a hotfix for CVE-2026-75650, a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that Sansec identified as being actively exploited since September 4, 2026.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    What happened

    N-able released hotfixes for two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that allow unauthorized authentication bypass, alongside a maximum-severity flaw (CVE-2026-86218) enabling pre-authenticated remote code execution. While N-able has not confirmed production exploitation, Huntress observed signs that attackers likely leveraged the authentication bypass flaws to compromise a customer’s fully patched environment.

    Why it ranks #2

    N-able released hotfixes for two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that allow unauthorized authentication bypass, alongside a maximum-severity flaw (CVE-2026-86218) enabling pre-authenticated remote code execution, while Huntress observed signs that attackers likely leveraged the authentication bypass flaws to compromise a customer’s fully patched environment.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    What happened

    TantoSec published a working exploit chain for Telerik UI for ASP.NET AJAX that leverages a padding oracle in the RadAsyncUpload control to achieve unauthenticated remote code execution. The attack forges encrypted client-side state to trigger the deserialization of an attacker-controlled .NET type, loading a malicious DLL into the IIS worker process. Progress patched the vulnerability in version 2026.2.708, though no confirmed in-the-wild exploitation has been reported as of the disclosure.

    Why it ranks #3

    TantoSec released a public exploit chain for Telerik UI that achieves unauthenticated remote code execution by forging encrypted state to trigger malicious .NET deserialization in IIS worker processes.

    Who should care

    Application security teams, CISOs and security leaders, IT and platform operations, SOC and incident response teams

    What to do

    Upgrade to Telerik UI for ASP.NET AJAX 2026.2.708 (2026 Q2 SP1) or later to replace flawed AES-CBC with authenticated encryption and close the vulnerability chain.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Schneier on Security

    Stealing AI Reasoning Traces

    What happened

    Researchers identified an architectural flaw in how LLM providers handle encrypted reasoning traces, allowing attackers to swap encrypted blocks between different models within the same ecosystem. By injecting a trace from a capable model into a weaker, less safeguarded model, adversaries can force the system to decode and output the proprietary reasoning in plaintext. This technique bypasses anti-distillation controls and enables the extraction of private data, including credentials and PII, from publicly shared session logs.

    Why it ranks #4

    Researchers identified an architectural flaw in LLM providers' handling of encrypted reasoning traces that allows attackers to swap encrypted blocks between models within the same ecosystem, forcing the system to decode and output proprietary reasoning in plaintext and bypassing anti-distillation controls.

    Who should care

    CISOs and security leaders

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    What happened

    SOCRadar disclosed PEEP, a post-exploitation toolkit that masquerades as a browser extension to convert compromised Chrome and Edge instances into persistent backdoors. The tool bypasses Web Store checks by forging Secure Preferences integrity values and uses a native-messaging bridge to execute host-level shell commands, manage files, and exfiltrate session cookies.

    Why it ranks #5

    SOCRadar disclosed PEEP, a post-exploitation toolkit that masquerades as a browser extension to convert compromised Chrome and Edge instances into persistent backdoors for host-level command execution.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    What happened

    Huntress identified a worm-like campaign in August 2026 where rogue ConnectWise ScreenConnect clients distribute a four-stage VBScript chain to newly connected hosts. The scripts profile the target system and deploy payloads ranging from user-level backdoors to cryptocurrency miners, propagating the infection through subsequent ScreenConnect sessions.

    Why it ranks #6

    Huntress identified a worm-like campaign in August 2026 where rogue ConnectWise ScreenConnect clients distribute a four-stage VBScript chain to newly connected hosts, with the scripts profiling the target system and deploying payloads ranging from user-level backdoors to cryptocurrency miners that propagate through subsequent ScreenConnect sessions.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    What happened

    The source text does not mention Cisco Talos, cryptocurrency theft, or the Google Visualization API, so the rejected sentence cannot be supported by the provided material. Arctic Wolf reported that the PREY-0058 threat cluster uses IT help desk vishing to direct executives to authentication-themed URLs, where an adversary-in-the-middle flow harvests Microsoft 365 credentials and MFA approvals to obtain session tokens for replay attacks from residential proxies.

    Why it ranks #7

    Arctic Wolf reported that the PREY-0058 threat cluster uses IT help desk vishing to direct executives to authentication-themed URLs, where an adversary-in-the-middle flow harvests Microsoft 365 credentials and MFA approvals to obtain session tokens for replay attacks from residential proxies.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Implement Conditional Access, deploy phishing-resistant MFA, restrict SharePoint data access, and train staff on vishing risks.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Cisco Talos Blog

    ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    What happened

    Cisco Talos identified a cryptocurrency theft campaign that abuses the Google Visualization API to deliver obfuscated JavaScript into victims' browsers. The injected code hooks the browser's fetch API to replace legitimate deposit addresses with attacker-controlled wallets and hijacks clipboard actions to divert funds.

    Why it ranks #8

    Cisco Talos identified a cryptocurrency theft campaign that abuses the Google Visualization API to deliver obfuscated JavaScript into victims' browsers, where the injected code hooks the fetch API to replace legitimate deposit addresses with attacker-controlled wallets and hijacks clipboard actions to divert funds.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    BleepingComputer

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    What happened

    CloudSEK researchers accessed the control panel for BigBear 2.0, an Evilginx2-based phishing-as-a-service framework that bypassed multi-factor authentication at 258 organizations. The operation exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications and 4,148 session cookies, from 3,331 unique victim IPs across more than 40 countries.

    Why it ranks #9

    CloudSEK researchers accessed the control panel for BigBear 2.0, an Evilginx2-based phishing-as-a-service framework that bypassed multi-factor authentication at 258 organizations, exfiltrating 5,137 credential records including 474 complete MFA-bypassed authentications and 4,148 session cookies from 3,331 unique victim IPs across more than 40 countries.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Reset exposed passwords, revoke sessions, refresh tokens, and force re-authentication for high-privileged accounts potentially affected by BigBear activity.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    220 million traveler records exposed in Vietnam-linked APIS leak

    What happened

    Kinryū Labs discovered an exposed Elasticsearch cluster in Vietnam that held 220 million passenger and crew records, including passport numbers and flight details, spanning from January 2017 to April 2026. The researchers accessed the database by chaining a cloud-based misconfiguration with default credentials, a vulnerability that was remediated on June 8. It remains unclear whether malicious actors copied or exploited the data before the exposure was closed.

    Why it ranks #10

    Kinryū Labs identified an exposed Elasticsearch cluster in Vietnam containing 220 million passenger and crew records, including passport numbers and flight details from January 2017 to April 2026, which was accessed via a cloud misconfiguration and default credentials before being remediated on June 8.

    Who should care

    CISOs and security leaders

    Impact
    critical
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email