Daily cybersecurity intelligence digest from CyberNetSec.io - September 8, 2026
π 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Adobe Patches Critical 'StyleSmuggler' Zero-Day in Commerce & Magento
Adobe has released an emergency patch for a critical zero-day vulnerability, CVE-2026-75650, dubbed 'StyleSmuggler.' This unauthenticated remote code execution (RCE) flaw, with a CVSS score of 10.0, affects Adobe Commerce and Magento Open Source. Threat actors began exploiting the vulnerability on September 4, 2026, before a patch was available, deploying backdoors on e-commerce servers. The exploit chain manipulates Magento's template processing and dependency injection mechanisms. Security firm Sansec discovered the attacks, which have been observed originating from IPs in China and Romania. E-commerce site administrators are urged to apply the patch immediately and investigate for signs of compromise.
2. N-able N-central Hit by CVSS 10.0 Unauthenticated RCE Zero-Day
IT software provider N-able has released an emergency hotfix for CVE-2026-86218, a critical-rated (CVSS 10.0) unauthenticated remote code execution (RCE) zero-day vulnerability in its on-premises N-central endpoint management platform. The flaw was discovered to be under active exploitation, allowing attackers to gain complete control of an N-central server without authentication. Huntress labs observed attacks targeting the platform's API beginning on September 4, 2026. N-able has urged customers to immediately apply the '2026.3 HF4' hotfix and to scan for compromise by checking for newly created user accounts and reviewing logs for scanning activity from the IP range 23.234.64.0/18.
3. MikroTik Patches 'MikroTrick' SSH Zero-Day Exploit Chain in RouterOS
MikroTik has released urgent security updates for its RouterOS software to fix a two-stage exploit chain dubbed 'MikroTrick.' Attackers are actively exploiting the zero-day flaw, which combines a high-severity SSH authentication bypass (CVE-2026-67276, CVSS 9.2) with a privilege escalation vulnerability (CVE-2026-86060). This combination allows for a complete, unauthenticated takeover of internet-exposed routers. Exploitation was observed in the wild starting around September 2, 2026, a day before patches were available. Administrators are urged to update immediately and investigate their devices for signs of compromise, such as newly created privileged accounts.
4. North Korea-Linked Group Hides 'ted backdoor' in HAProxy Software
A North Korea-linked threat actor has been observed targeting South Korean automotive and media companies with a novel Linux toolkit. The campaign's most sophisticated element is a backdoor, dubbed 'ted backdoor,' which is compiled directly into the source code of the widely-used HAProxy load-balancing software. By integrating as a custom plugin using HAProxy's native APIs, the implant evades traditional detection methods while intercepting HTTP traffic, executing commands, and harvesting credentials. The broader toolkit also includes trojanized versions of common Linux daemons like crond and sshd, enabling long-term persistence and surveillance within compromised networks.
5. Vishing Attacks Steal Microsoft 365 Sessions to Extort Companies
A data extortion group, tracked as PREY-0058 and linked to UNC6671, is targeting corporate executives with sophisticated vishing (voice phishing) calls. The attackers impersonate the company's IT help desk to trick victims into providing access to their Microsoft 365 accounts, leading to the theft of session tokens. Using these tokens, the threat actors bypass MFA and exfiltrate large volumes of data from SharePoint, OneDrive, and other SaaS platforms. The attackers use residential proxy networks like NodeMaven to obscure their location and evade security controls. The campaign targets a wide range of industries in the U.S., including finance, healthcare, and construction.
6. PoC for 'FalconFlank' Zero-Day in CrowdStrike Falcon Sensor Released
A security researcher known as Nightmare Eclipse has publicly disclosed 'FalconFlank,' a zero-day local privilege escalation (LPE) vulnerability in the CrowdStrike Falcon Sensor for Windows. A proof-of-concept (PoC) exploit was also released, allowing a local attacker to gain NT AUTHORITY\SYSTEM privileges. The exploit abuses the 'Office malicious macros remediation' feature in the Falcon Sensor, tricking it into loading a malicious DLL with SYSTEM rights. The flaw affects fully patched Windows 11 and Windows Server 2026 systems with the latest Falcon Sensor. CrowdStrike is investigating and has advised customers to disable the specific policy setting as a temporary mitigation.
7. 'BigBear 2.0' PhaaS Targets Microsoft 365 Users with MFA Bypass
A large-scale phishing-as-a-service (PhaaS) operation, named 'BigBear 2.0,' is targeting hundreds of organizations globally with Microsoft 365 credential theft attacks. Researched by CloudSEK, the service uses a customized version of the Evilginx2 adversary-in-the-middle (AiTM) framework to bypass multi-factor authentication (MFA) and steal session cookies. The operation, managed by an actor named 'General Boss,' has compromised over 5,000 records across 40+ countries. The framework uses advanced techniques like custom JavaScript to disable FIDO2/WebAuthn and residential proxies to evade detection. IT service providers and MSPs are primary targets, indicating a potential for supply chain attacks.
8. Report: Fragmented Federal Cyber Reporting Rules Hinder US Response
A joint report by Auburn Universityβs McCrary Institute and the U.S. Chamber of Commerce warns that the current landscape of federal cyber incident reporting in the United States is dangerously fragmented. The report identifies 117 different regulations across 27 federal agencies, creating duplicative and conflicting burdens on private industry during a crisis. This forces organizations to divert critical personnel and resources away from active incident response to focus on compliance paperwork. The report advocates for a streamlined 'report once, use many times' model, anchored by CISA, to harmonize requirements and allow companies to focus on defense and recovery.
π Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)