CTIPilot
Tue · 08 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Tuesday, 8 September 2026

4 verified findings from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

ACT NOW · CRITICALCVE-2026-75650 · exploited · 4 sources · 08 Sep 04:39Z

Adobe rates its own emergency hotfix priority 1 for a flaw stores were already being compromised through since before Sansec published

Sansec disclosed StyleSmuggler on 2026-09-05 after finding active exploitation from 2026-09-04: an unauthenticated remote-code-execution chain in Magento Open Source, Adobe Commerce and Adobe Commerce B2B (all versions 2.4.4 through 2.4.9), assigned CVE-2026-75650 (CVSS 10.0). Adobe shipped an emergency hotfix (APSB26-146) on 2026-09-07, three days after the first confirmed compromise; patch level gave no protection during that window, and Adobe recommends rotating every credential the encryption key protects.

Apply Adobe's VULN-39341 hotfix (APSB26-146) to every Adobe Commerce, Adobe Commerce B2B and Magento Open Source instance today, regardless of patch level, a fully patched 2.4.6-p15 store was compromised before the hotfix existed, and moving session storage to Redis or a database does not stop the attack. Where the hotfix cannot be applied immediately, Sansec's own interim advice for stores not running its Shield product is to temporarily disable GraphQL, since the observed chain arrives via a POST /graphql request; note this breaks headless and progressive-web-app storefronts, which depend on GraphQL, though most classic and Hyvä storefronts do not. Before assuming a store is clean, hunt for a background process masquerading as a kernel worker thread, fc-cache or chronyd, and for a cron entry written directly into the spool file rather than through the crontab command (an empty crontab -l is not evidence of a clean host). Where an implant is found, rotate the store's encryption key and every credential it protects (admin passwords, REST/SOAP/GraphQL tokens, OAuth secrets, payment-gateway API credentials, database and SSH/deploy keys) at the source system, since rotating the encryption key alone does not invalidate anything already read.

Open the full advisory to act →
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Adobe rates its own emergency hotfix priority 1 for a flaw stores were already being compromised through since before Sansec published. Sansec disclosed StyleSmuggler on 2026-09-05 after finding active exploitation from 2026-09-04: an unauthenticated remote-code-execution chain in Magento Open Source, Adobe Commerce and Adobe Commerce B2B (all versions 2.4.4 through 2.4.9), assigned CVE-2026-75650 (CVSS 10.0). Adobe shipped an emergency hotfix (APSB26-146) on 2026-09-07, three days after the first confirmed compromise; patch level gave no protection during that window, and Adobe recommends rotating every credential the encryption key protects.
  2. 02CloudSEK gained admin access to the panel and found custom code specifically written to defeat the one MFA class that structurally resists this attack. CloudSEK gained administrator access to the control panel of BigBear 2.0, an Evilginx2-based adversary-in-the-middle phishing-as-a-service operation exclusively targeting Microsoft 365 across 42 VPS nodes. Custom JavaScript injected into every proxied login page disables FIDO2/WebAuthn to force victims onto phishable MFA methods; the panel has captured 5,137 credential records, including 474 fully MFA-bypassed sessions, from 3,331 victim IPs across 40+ countries, with IT-services/MSP organizations the single largest targeted sector.
  3. 03ANSSI investigates suspected account compromise at the ministry, while an unconfirmed criminal claim names the specific application flaw. France's Ministère de la Transition écologique confirmed on 2026-09-02/03 a sophisticated attack targeting its ministerial mail systems and filed a report with the public prosecutor; ANSSI is separately investigating suspected compromise of user accounts. A criminal using the handle "mondial" separately claims, unconfirmed, exfiltration of 14,656 inspection-controller records and 8,166 user records from systems tied to developpement-durable.gouv.fr via a misconfigured authentication service and an IDOR flaw in OISO, the ministry's inspection-body oversight tool.

01Active threats, incidents & disclosures2 items

NOTABLENATOB3

France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool

France's Ministère de la Transition écologique confirmed to AFP on 2026-09-02/03 that its ministerial IT hub suffered a sophisticated cyberattack targeting mail systems, filed a report with the public prosecutor, and took several public-facing sites (the environmental public-consultation platform and multiple regional-administration sites) into maintenance mode (ICI / Radio France, 2026-09-03). ANSSI, France's national cyber-defense authority, separately confirmed it is intervening at ministry administrations "following suspicions of compromise of certain user accounts" as part of its own investigation, a fact-level statement from the authority itself, distinct from the criminal's unconfirmed claim below (ICI / Radio France, 2026-09-03).

On 2026-09-02, a criminal using the pseudonym "mondial" posted on a cybercriminal forum, tracked and reported by the specialist outlet French Breaches, claiming exfiltration of two files from systems tied to developpement-durable.gouv.fr (French Breaches, 2026-09-02): a 14,656-record file on approved inspection controllers (names, birthdates, approval numbers, phone numbers, some tied to inspection bodies such as APAVE Exploitation France) and an 8,166-record internal-directory file (unique emails, landline and mobile numbers, professional IDs, unit/directorate affiliations spanning 942 administrative units) (Le Monde Informatique, 2026-09-07). The attacker claims initial access via a misconfigured authentication service, followed by exploitation of an IDOR flaw in OISO (Outil Informatique de Surveillance des Organismes), the ministry's internal tool for monitoring accredited inspection bodies, to enumerate and pull records outside the authenticated session's intended scope (Le Monde Informatique, 2026-09-07). Neither the record counts, the precise nature of the misconfiguration, nor the scope of compromised systems has been independently confirmed as of the article date; this is the criminal's claim, not an established fact, though the underlying intrusion and ANSSI's investigation into it are victim- and authority-confirmed (Le Monde Informatique, 2026-09-07).

This follows a summer of repeated French public-administration intrusions (the Ministry of National Education in July and the tax authority DGFiP in August among them) that, per separate Le Monde Informatique reporting, led Prime Minister Sébastien Lecornu to impose a deadline at a 31 August government seminar for every minister to accelerate implementation of a EUR 200 million state-cybersecurity plan first announced in April; the same report cites ANSSI's own 2025 statistics of 3,586 security events and 1,366 qualified incidents, with ministries and local authorities accounting for 24% of incidents, second only to education and research at 34% (Le Monde Informatique, 2026-09-04). No source ties this intrusion's actor or mechanism to the credential-theft cluster already tracked in the DGFiP entry; the poster here uses a different handle with no stated affiliation.

Triage: sequential or rapidly-incrementing identifier values in an internal application's access logs against a single authenticated session, or access spanning far more organizational units than that account's normal scope, is the vendor-neutral discriminator for this technique class; legitimate bulk reporting by an authorized administrator can produce similar volume, so the sequence and the scope mismatch together are the signal, not either alone.

The ministerial hub was the target of a sophisticated cyberattack last week, targeting messaging tools. (translated from French)

A report was filed with the public prosecutor. (translated from French)

ANSSI, the authority responsible for protecting the country against cybersecurity and cyberdefense threats, stated it is intervening "on behalf of administrations of the Ministry of Ecological Transition, following suspicions of compromise of certain user accounts and as part of investigations". (translated from French)

ICI / Radio France (AFP wire) 2026-09-03

In a post published on 2 September 2026 on a cybercriminal forum, a user under the pseudonym "mondial" claims to have extracted two databases from systems associated with developpement-durable.gouv.fr. (translated from French)

French Breaches 2026-09-02

He then claims the exploitation of an IDOR (Insecure Direct Object Reference) vulnerability. (translated from French)

The authenticity and completeness of the data presented have not been independently confirmed. (translated from French)

Le Monde Informatique 2026-09-07
incident08 Sep 04:43Zmulti-sourceOpen finding ↗
HIGHNATOB2

BigBear 2.0, an Evilginx2-based Microsoft 365 phishing-as-a-service panel that JavaScript-disables FIDO2/WebAuthn to force victims onto phishable MFA, leased to at least five affiliates

CloudSEK's TRIAD team gained administrator access to the control panel of BigBear 2.0, a rebranded, Evilginx2-based adversary-in-the-middle phishing-as-a-service operation targeting Microsoft 365 exclusively, and published full technical findings on 2026-09-07 (CloudSEK, 2026-09-07). Victims reach the operation by clicking a phishing link typically delivered via email, which proxies them to what appears to be the legitimate Microsoft login page (CloudSEK, 2026-09-07). The panel managed 42 VPS nodes running Evilginx2's reverse-proxy engine on a single phishlet that proxies the entire authentication flow between the victim and Microsoft's own login domain: the victim's password is captured in plaintext as it passes through, and after the victim completes MFA, Microsoft's own session cookie is captured off the wire before it reaches the victim's browser, because the proxy terminates the victim's TLS session before opening its own to Microsoft (CloudSEK, 2026-09-07). That cookie is bound to the browser session but not to any device or location, so importing it into an attacker-controlled browser inherits the fully authenticated session, TOTP, push and SMS MFA are all structurally bypassed this way, since the proxy never has to defeat the second factor, only wait for the legitimate user to clear it (CloudSEK, 2026-09-07; BleepingComputer, 2026-09-07).

What distinguishes this operation from stock Evilginx2 deployments is custom JavaScript injected into every proxied login page that monkey-patches the browser's PublicKeyCredential/navigator.credentials API, forcing a fallback away from FIDO2/WebAuthn, the one MFA class immune to AiTM replay, because its cryptographic assertion is bound to the legitimate origin domain and fails outright when the browser's actual origin is the phishing domain rather than Microsoft's own (CloudSEK, 2026-09-07). The same injected code blocks outbound requests to Microsoft's own anti-phishing telemetry and canary-token endpoints and auto-enables "Keep me signed in" to maximize the stolen session's lifetime (CloudSEK, 2026-09-07). The panel exposes a REST API that automatically replays captured cookies against Microsoft 365, and a keepalive feature abuses captured refresh tokens (typically valid around 90 days on a sliding window) to periodically refresh session cookies well past their nominal expiry (CloudSEK, 2026-09-07). A geo-matched residential-proxy pool spanning 69 countries routes relayed traffic through an IP in the victim's own country, defeating Microsoft's location-anomaly detection and satisfying IP-based Conditional Access checks that key on geolocation rather than device state (CloudSEK, 2026-09-07).

At the time of CloudSEK's writing the panel had captured 5,137 credential records (474 complete MFA-bypassed sessions, 1,032 plaintext passwords, and 4,148 session cookies) from 3,331 unique victim IPs across more than 40 countries (CloudSEK, 2026-09-07). BleepingComputer's own review of CloudSEK's dataset gives the organizational scale directly: 258 distinct organizations had at least one completed MFA-bypass compromise, out of 461 organizations that appear in the broader targeting dataset (BleepingComputer, 2026-09-07). CloudSEK describes the operation as still active as of its report, but also records that the threat actor has deleted 26 of the panel's 42 observed VPS nodes since late July 2026 as apparent counter-forensic activity following detection (CloudSEK, 2026-09-07); BleepingComputer separately reports that, as of its own writing, BigBear's administration panel remains reachable while the phishing infrastructure itself has been offline for nearly three weeks (BleepingComputer, 2026-09-07), consistent with an operator tearing down active phishing nodes under pressure while the panel and its captured-credential dataset persist. The service is leased to at least five identified affiliate operators, each receiving stolen credentials in real time through dedicated Telegram bots (CloudSEK, 2026-09-07; BleepingComputer, 2026-09-07). IT-services and managed-service-provider organizations were the single largest targeted sector, which CloudSEK notes is disproportionate because a compromised IT provider's privileged access to client Azure AD, on-premises AD, RMM tooling and password managers enables downstream supply-chain compromise of its customers (CloudSEK, 2026-09-07).

Triage: the vendor-neutral tell is a session-cookie-authenticated action with no matching interactive MFA challenge in the same session lineage, or a token-issuance event immediately followed by activity from a network location or device-compliance state inconsistent with the device that originally enrolled; a legitimate user re-using a cached session from a known device does not produce this mismatch, which is what separates the AiTM replay from ordinary session persistence.

The panel has exfiltrated 5,137 credential records (including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies) affecting 3,331 unique victim IPs across 40+ countries

Since late July 2026 the threat actor has deleted 26 of the 42 observed VPS nodes from the panel, evidence of active counter-forensic operations in response to detection.

CloudSEK

At the time of writing, the administration panel remains online, while the phishing infrastructure has been offline for nearly three weeks.

BleepingComputer (Bill Toulas) 2026-09-07

FIDO2 (hardware security keys, platform authenticators like Apple Face ID / Windows Hello) uses origin-bound credentials. The cryptographic assertion is tied to the origin domain (e.g., login.microsoftonline.com). When Evilginx2 proxies traffic, the origin seen by the browser is the phishing domain (login.evil-domain.com), not the real Microsoft domain. The FIDO2 assertion fails because the origin does not match the credential's registered origin. This is the only MFA method that structurally prevents AiTM phishing.

CloudSEK

Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the observed operation.

BleepingComputer
threat08 Sep 04:45Zmulti-sourceOpen finding ↗

02Research, reports & policy1 item

NOTABLENATOB2

Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other

Sekoia's TDR team and Kudelski Security, a Switzerland-based research firm, jointly published a reassessment of how North Korea's offensive-cyber apparatus is organized (Kudelski Security, 2026-09-07). The authors now track the historical "Lazarus umbrella" as six distinct sub-clusters (TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, the last already tracked here as an alias of the North Korean fraudulent-IT-worker cluster) each carrying a different primary mandate spanning strategic espionage, dual espionage-and-revenue operations, and pure financially motivated crime (Kudelski Security, 2026-09-07). The espionage-focused clusters under GRIB (formerly RGB), TEMP.Hermit among them, are the authors' own described inheritors of both the historical Lazarus umbrella and the Kimsuky cluster's lineage, even where their precise bureau affiliation is debated within the CTI community (Kudelski Security, 2026-09-07). The authors date the Lazarus umbrella's internal reorganization into specialized sub-clusters to a 2018–2023 transition phase alongside the global expansion of the cryptocurrency market, out of which APT38 itself emerged as the financially-motivated sub-cluster; APT38 has since, per the authors' own current research, further split into two of these (CryptoCore and Jade Sleet) both exclusively financially motivated and focused on cryptocurrency, Web3 and blockchain targets, though the authors do not date this more recent split.

The most defender-relevant finding is a documented pattern of commodity-ransomware adoption by nominally espionage-focused units: Andariel, a dual-mandate cluster, used its own custom ransomware (Maui, H0lyGh0st) and separately collaborated with the criminal Play ransomware-as-a-service operation in 2024, citing prior reporting from Unit 42; Moonstone Sleet deployed its own custom malware (FakePenny) the same year and then adopted the Qilin ransomware-as-a-service in 2025, within two months of Andariel's own RaaS adoption (Kudelski Security, 2026-09-07). The authors note it is "interesting" that the two clusters integrated RaaS into their campaigns within two months of each other, a single observed timing overlap, not a claimed broader trend, though it is consistent with the general possibility that DPRK clusters rent commodity ransomware infrastructure alongside, or instead of, running only bespoke tooling.

The report also states that "Reaper" (already tracked here as an alias of ScarCruft/APT37) is the cluster aligned with North Korea's newly renamed National Intelligence Agency (formerly the Ministry of State Security, renamed June 2026), tasked with surveillance of defectors and South Korean NGOs and activists. Kudelski Security's own separate prior research, cited in this report, found that DPRK fake-IT-worker infrastructure and offensive-APT infrastructure share the same VPN exit nodes, a concrete pivot point for correlating IT-worker-fraud indicators against APT intrusion infrastructure (Kudelski Security, 2026-09-07). Separately, the report documents a Cambodia-based money-laundering hub, the Huione Group (flagged by the US Treasury's FinCEN as a primary money-laundering concern) whose executives the authors say have shown indications of direct ties to North Korean actors, with an estimated USD 37.6 million in DPRK-linked cryptocurrency laundered through it between 2021 and 2025 via stablecoins and technical tooling that let North Korea convert illicit proceeds into ostensibly legitimate assets (Kudelski Security, 2026-09-07).

We notably made our clustering evolved by splitting the Lazarus umbrella into six distinct sub-clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima.

Sekoia TDR team / Kudelski Security

Of note, Andariel is particular as it used custom ransomware (Maui and H0lyGh0st) for financial theft, as well as ransomware-as-a-service (RaaS) developed by an operator of the Russian cybercrime ecosystem. It was notably observed collaborating with Play in 2024. Another DPRK cluster, Moonstone Sleet, acted similarly by deploying its custom malware FakePenny in 2024, but also the Qilin RaaS in 2025. It is interesting to note that the two clusters integrated RaaS in their campaigns within two months of each other.

Kudelski Security observed that fake IT workers and offensive teams often share the same VPN exit nodes.

Kudelski Security

Builds on: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy

research08 Sep 04:41Zsingle-sourceOpen finding ↗

03Updates to prior coverage3 items

HIGHupdatedNATOA1

TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant

First published 2026-08-31 · open finding →

Updaterun 2026-09-08T0411Z-intelupdated_atentitiestagssourcesevidenceverificationclassificationsourcing_notebody

Germany's BSI independently confirms this campaign's technique against a real-world case it investigated (the Berlin Landesnetz compromise) and supplies the campaign's first named-actor attribution: Rhysida's operators, tracked by BSI as Vice Spider. Verification moves from single-source to multi-source; credibility moves from 2 to 1 on the same independent national-CERT confirmation that moved the sibling Berlin entry.

Germany's BSI published an advisory on 2026-09-04 describing the compromise of an anonymized "state institution" whose technique matches this campaign, the advisory itself never names Berlin (BSI, BITS-2026-287419-1032, 2026-09-04). The same day, BSI posted on its official Mastodon account that it was intensively involved in handling the Berlin incident and separately linked to its detailed TerminalFix security notice; heise reports that juxtaposition as confirmation that TerminalFix is specifically the vector Rhysida's operators used against Berlin's two affected Senate administrations (heise online, citing BSI, 2026-09-07), the first independent confirmation of this campaign beyond Microsoft's own telemetry, and its first named-actor attribution. BSI attributes the campaign, via a malware family it names LoremIpsumLoader (also known as AxolotLoader) observed in incident reports, to a financially motivated group it tracks as Vice Spider, the same group responsible for the Rhysida ransomware and leak site, cross-referenced against the aliases Vice Society, WhiteNefas, White Hekate, DEV-0832 and Vanilla Tempest (BSI, BITS-2026-287419-1032, 2026-09-04). BSI assesses the campaign as opportunistic, purely financially motivated cybercrime with no established state or political link, and notes the CAPTCHA lure's own JavaScript has been observed on several hundred historical websites, evidence of a reusable watering-hole kit rather than one-off, victim-specific infrastructure (BSI, BITS-2026-287419-1032, 2026-09-04).

HIGHupdatedNATOB1

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

First published 2026-08-30 · open finding →

Updaterun 2026-09-08T0411Z-intelupdated_atentitiestechniquessourcesevidencesourcing_noteconfidenceclassificationbody

Germany's BSI officially confirms, for the first time, both the intrusion technique and the actor attribution this entry had previously carried only from investigative journalism: the compromise matches BSI's own TerminalFix campaign advisory, and Rhysida is attributed to a group BSI tracks as Vice Spider (aka Vice Society, WhiteNefas, White Hekate, DEV-0832, Vanilla Tempest). BSI's advisory adds that operators staged exfiltration into attacker-controlled Azure cloud storage using the vendor's own azcopy tool and separately names the malware family LoremIpsumLoader (aka AxolotLoader) as attributed to the same group. Confidence moves from medium to high on the strength of this national-CERT technical confirmation.

Germany's BSI published an advisory on 2026-09-04 describing the compromise of an anonymized "state institution" whose technique matches the multi-stage TerminalFix campaign Microsoft documented on 2026-08-28, the advisory itself never names Berlin (BSI, BITS-2026-287419-1032, 2026-09-04). The same day, BSI posted on its official Mastodon account that it was intensively involved in handling the Berlin incident and separately linked to its detailed TerminalFix security notice; heise reports that juxtaposition as confirmation that TerminalFix is specifically the attack vector the Rhysida operators used against Berlin's two affected Senate administrations (heise online, citing BSI, 2026-09-07), the first technical confirmation, reported by heise, of both the access vector and the attribution this entry had previously carried only from investigative journalism. BSI attributes the Rhysida ransomware and leak site to a financially motivated group it tracks as Vice Spider, cross-referenced against the aliases Vice Society, WhiteNefas, White Hekate, DEV-0832 and Vanilla Tempest, active since at least mid-2021 and using the Rhysida ransomware and leak site almost exclusively since June 2023 (BSI, BITS-2026-287419-1032, 2026-09-04). BSI's advisory adds a detail beyond what Microsoft's original write-up described: reporting organizations told BSI that TerminalFix operators have staged exfiltration into attacker-controlled cloud storage, for example Azure, using the cloud provider's own transfer tooling such as azcopy (BSI, BITS-2026-287419-1032, 2026-09-04). BSI further states that incident reports place a malware family it names LoremIpsumLoader (also known as AxolotLoader) within the campaign, and attributes that loader to the same group responsible for Rhysida (BSI, BITS-2026-287419-1032, 2026-09-04). BSI assesses the campaign as opportunistic, purely financially motivated cybercrime with no established link to a state or politically motivated actor, and states Rhysida shows no particular regional focus on Germany, concentrating instead on education and healthcare, with public administration a more distant top-five target sector (BSI, BITS-2026-287419-1032, 2026-09-04).

HIGHCVE-2026-19490 +1exploitedupdatedNATOA1

CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed

First published 2026-08-20 · open finding →

Updaterun 2026-09-08T0411Z-intelupdated_atcvestagsactionssourcesevidenceclassificationsourcing_notebody

A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03, and vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching it from multiple source IPs within 24 hours, with continued activity through 2026-09-07. NCSC-NL updated its advisory the same day to state PoC code is public and that it assesses imminent widespread exploitation as highly likely. Status moves from patch-available-only to poc-public and exploited; EPSS scores are now recorded for both CVEs. Credibility moves from 2 to 1 given independent confirmation from a national CERT and a vulnerability-intelligence firm's own sensor telemetry.

A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03 (NCSC-NL, 2026-09-07). Vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching that PoC from three distinct source IPs, geolocated to Australia, the United States and Germany, on 2026-09-03 (BleepingComputer, citing Previdian, 2026-09-04), and Previdian's own tracker, refreshed 2026-09-08, now records 18 exploitation attempts total from 9 unique attacker IPs across 5 countries (Australia, Germany, Japan, Taiwan and the United States) (up from the three-IP, three-country snapshot reported four days earlier) with sensor activity most recently observed 2026-09-07: evidence of exploitation attempts, though not confirmation of successful compromise (Previdian, 2026-09-08). Field Effect separately reported on the same activity and adds an operationally important precondition detail: on some newer builds the bypass additionally requires a configured SAML authentication action, while on older affected versions a Gateway or AAA virtual server configuration alone is enough, consistent with, and sharpening, this entry's own version-dependent exposure boundary above (Field Effect Security Intelligence Team, 2026-09-04). NCSC-NL updated its advisory on 2026-09-07 specifically to flag that PoC code is now public and that it assesses imminent widespread exploitation as highly likely (translated from Dutch) (NCSC-NL, 2026-09-07). CVE-2026-19490 has not been added to CISA's KEV catalog as of this update.

04Deep dive1 item

CRITICALCVE-2026-75650exploitedNATOA1

CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed

Sansec found StyleSmuggler on 2026-09-04 at 22:40 UTC and published the following day specifically because stores were already being compromised, reproducing the full unauthenticated chain on clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 within hours (Sansec, 2026-09-05). The bug abuses Magento's own template engine through the styles property, reached via a POST /graphql request carrying the malicious styles parameter, to smuggle PHP past existing input safeguards, and runs in two stages: first the attacker poisons a location Magento itself writes to and later re-renders through its template filter; Sansec's own published check searches a failure report under var/report/, but Magento hosting firm Disrex Group, which handled two live compromises, found both of its infections instead poisoned var/log/system.log, a location Sansec's check misses entirely (The Hacker News, 2026-09-06), with attacker-controlled PHP; second, the attacker triggers Magento's built-in "Payment Transaction Failed Reminder" customer-notification email, and the poisoned content executes the moment Magento renders that template (Sansec, 2026-09-05). Nobody needs to open the email, and the attack succeeds even when delivery fails (Sansec, 2026-09-05). Adobe assigned CVE-2026-75650 (CVSS 10.0, CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine) and shipped an emergency hotfix, APSB26-146, on 2026-09-07 at 20:20 UTC with its highest priority rating, three days after the first confirmed exploitation (Adobe PSIRT, 2026-09-07; Sansec, 2026-09-05). The fix ships as a composer patch (VULN-39341) rather than a full point release, tested against the 2026-aug release branch of Adobe Commerce, Adobe Commerce B2B and Magento Open Source 2.4.4 through 2.4.9; older versions in those branches are affected too, but Sansec reports the patch is unverified there (Sansec, 2026-09-05).

Disrex's own two compromises, reported independently of Sansec, sharpen the timeline and the triage picture. Both stores were breached inside the roughly eight-hour window between Sansec's first observed exploitation and the moment any defense existed, and Disrex states patch level was irrelevant during that window; one victim ran Magento Open Source 2.4.8 as a Sansec Shield customer with the module installed, enabled and licensed, and was still hit hours before Shield's first blocking rule went live (The Hacker News, 2026-09-06). Disrex reports a concrete false-negative worth defenders' attention: its own eComscan run on one compromised store returned clean eleven hours after the implant first executed, because the scheduled scan was scoped to the store's document root while the implant had installed itself one directory above it, under the site account's home directory, a scan-scope gap, not a detection-engine failure. Disrex also names a reliable success indicator the exploit itself leaves behind: a TypeError from array_merge() with an integer argument, logged immediately after the poisoned include executes; a stealthier variant instead returns an empty array and leaves nothing to find, so its absence does not clear a host. One of Disrex's two compromises first surfaced through exactly the "Payment Transaction Failed Reminder" tell this entry describes above: a merchant forwarded a failed-transaction email whose template variables had never resolved (raw {{var ...}} tags, a customer address on an invalid domain, a zero-value total) and that forward alone started the investigation that found the implant within the hour (The Hacker News, 2026-09-06).

Patch level offered no protection during the exposure window: the first confirmed victim ran Magento 2.4.6-p15 with the July and August 2026 security patches applied (the latest patch level Adobe offers for that release line) and a clean security:patch-status (Sansec, 2026-09-05; The Hacker News, 2026-09-06), and Sansec's own Shield product blocked a probe against an already-current 2.4.7-p10 store on 2026-09-07, confirming that current patch level was no defense during the exposure window (Sansec, 2026-09-05). Moving session storage to Redis or a database is not a mitigation either: one merchant's session-storage defense stopped one attempt, and the same operator succeeded eight seconds later by routing the poisoned payload through a file uploaded via Magento's custom options instead (Sansec, 2026-09-05). On success, the implant is a small Rust binary (Disrex describes the sample from its own compromises as stripped and statically linked) that installs itself under a hidden directory outside the web root and re-persists via a cron entry written directly into the cron spool file rather than through the crontab command, so the change leaves no corresponding audit line and an empty crontab -l is not evidence of a clean host (Sansec, 2026-09-05; The Hacker News, 2026-09-06). The implant renames its own process to masquerade as a kernel worker thread, the fontconfig cache builder, or the genuine NTP daemon, and one observed build re-dropped and renamed itself mid-run from one masquerade to another while keeping the same underlying agent identity, a process-naming change with no corresponding new infection (Sansec, 2026-09-05). It reads /proc/self/status for TracerPid before beaconing: if a debugger or tracer is attached, the implant still installs itself but never calls out, which matters for anyone attempting to reproduce or analyze it live (Sansec, 2026-09-05).

Command-and-control is disguised as time synchronization: every 60 seconds the implant sends short UDP datagrams to port 123 shaped to resemble NTP server replies, carrying a chunked telemetry record (host, user, operating system, resource usage, and implant version) rather than legitimate time data, traffic that passes most egress filtering unremarked because it looks like a routine NTP exchange (Sansec, 2026-09-05). Two details separate it from a genuine NTP client for a defender who does look: a real client issues one query per interval, where one observed build burst nine datagrams roughly ten milliseconds apart every sixty seconds; and every datagram is marked NTP server-mode, which a client has no legitimate reason to send at all (Sansec, 2026-09-05). Sansec has so far found no evidence the backdoor has been used beyond installation and beaconing (Sansec, 2026-09-05).

Sansec separately documents a second, apparently unrelated actor exploiting the same flaw: a reconnaissance probe sent as an ordinary-looking GraphQL request carries PHP code inside a request header rather than the request body, reads the host's kernel/OS string, PHP user, working directory, and whether the media directory is writable, then exfiltrates that single-line answer one fragment at a time as a sequence of externally-resolved hostname labels to a public callback service; a technique that needs no response body at all, since the operator reconstructs the answer from the callback log (Sansec, 2026-09-05). Only when that probe reports the media directory writable does the same actor follow up with a web shell planted inside the product-image cache directory, reachable solely with a custom request header (Sansec, 2026-09-05).

Every version of Adobe Commerce, Adobe Commerce B2B and Magento Open Source in the 2.4.4–2.4.9 line is affected with no authentication or user interaction required (Adobe PSIRT, 2026-09-07); Switzerland's NCSC has issued its own advisory confirming the exploitation and backdoor-persistence risk for its constituency (NCSC Switzerland / GovCERT.ch, 2026-09-07). Any public body or supplier running a storefront, ticketing portal or fee-payment system on this platform (tourism boards, cantonal shops, public-transport ticketing among them) is in the affected population even without a Swiss-specific victim yet reported.

Triage: the exploitation trigger is Magento's own "Payment Transaction Failed Reminder" email, so an unexplained burst of these messages (especially containing unresolved template placeholders or Magento's template-error fallback text) is a Magento-specific tell that costs no additional tooling to check; legitimate declined-payment traffic can produce the same notification, so treat the burst as a lead, not a confirmation. On the network side, a web-tier host that only ever needs outbound HTTPS suddenly emitting repeated small UDP datagrams to port 123 is not a legitimate NTP client, which issues a single periodic query rather than a burst of server-mode replies; filtering by process name alone is insufficient once an implant has renamed itself to match the very daemon a defender would otherwise exclude from suspicion.

Sansec is publishing early because stores are being compromised right now.

Sansec Forensics Team 2026-09-05

Adobe is aware of CVE-2026-75650 being exploited in the wild.

Adobe PSIRT (APSB26-146) 2026-09-07

The fix ships as a hotfix, not as a full release.

Moving sessions to Redis or the database does not stop the attack. One merchant reported an attempt that failed against session storage and, eight seconds later, a second attempt that succeeded by using a file uploaded through Magento's custom options instead.

Sansec Forensics Team 2026-09-05

Successful exploitation allows unauthenticated attackers to achieve remote code execution and establish persistent backdoors on affected e-commerce servers via network access.

NCSC Switzerland / GovCERT.ch, Cyber Security Hub 2026-09-07
vulnerability08 Sep 04:39Zmulti-sourceOpen finding ↗

05Action items1 item

Verification & coverage notes1 run

2026-09-08T0411Z-intel · Sonnet 5 · window 26 h · 4 entries published

Verification & coverage notes

Standard window (gap_hours ≈ 24.0, all research completed within its time budget). Four new entries published, three existing entries updated through their changelog.

Cross-domain merges: the StyleSmuggler/CVE-2026-75650 finding surfaced independently from both vulnerability-focused and investigative-journalism coverage, composed as one entry from both. The same BSI advisory confirming TerminalFix/Rhysida attribution surfaced independently across home-region, research and incident coverage, composed as two update records (one per affected entry: the Berlin Landesnetz incident and the TerminalFix campaign), since this is one source pivoted onto two entries it materially updates, not duplicate research. The France Ministry of Ecological Transition breach surfaced independently from both home-region and incident coverage, composed as one entry.

Store-wide dedup catch (outside the 14-day in-context window): the Citrix NetScaler finding (CVE-2026-19490/CVE-2026-19489) matched an existing entry from 2026-08-20, caught via the store-wide CVE index rather than the 14-day coverage read. Composed as an update record (exploitation-status change: patch-available-only → poc-public + exploited) rather than a new entry.

Deep dive: StyleSmuggler (CVE-2026-75650), category web-app-rce, criterion 1 (active in-the-wild exploitation + non-trivial exposure for any public-sector storefront/ticketing portal on Magento/Adobe Commerce). Category not used in the prior 7 days (last web-app-rce deep dive: 2026-08-29).

Single-source item: the Sekoia/Kudelski Security DPRK six-cluster-split entry is verification: single-source, the two firms co-published identical content the same day, so this is one assessor's own novel clustering framework, not independent corroboration.

Reduced-confidence inclusion: the France Ministry of Ecological Transition entry holds confidence: medium despite multi-source confirmation of the underlying incident (ministry + ANSSI both independently confirmed to AFP), the claimed mechanism (IDOR flaw, specific record counts) is a single uncorroborated criminal claim relayed by French Breaches.

Coverage-backlog work this run (state/coverage_backlog.md): re-checked and unchanged (still blocked), Boston Scientific (no named mechanism), Insel Gruppe/inside-it.ch (whole-host 429 after initial RSS success), Ixa Systems/TheGentlemen, UICC/Krybit, Ville de Libercourt/Kairos (all still bare leak-site claims, no victim confirmation or Admiralty A/B journalism), NovoCure 8-K (confirmed access but no named mechanism). Struck as published-elsewhere: the Rapid7 Ted backdoor/curlRAT item (one of a four-item row) as 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy, and the Recorded Future H1 2026 Malware and Vulnerability Trends row as 2026-09-07/recordedfuture-h1-2026-tool-stack-reuse, both published by the prior day's fire.

Coverage gaps: ssd-disclosure (fetch_method already blocked, confirmed still unreachable on every transport, 5th consecutive run, a further search corroboration found nothing new); cisa-directives (bridge/reader returned only nav chrome, no listing content); several standard-tier research-lab listing pages returned stale or JS-rendered-empty content with no in-window items (trendmicro-research, yeswehack, hadrian-labs, prodaft, google-tag, intrinsec, cert-lv, mandiant-gtig, sysdig, sentinellabs, volexity, zscaler-threatlabz, proofpoint, jamf-threat-labs, novee-security, dcod-ch, openssf-policy, jpcert, nl-times, safeonweb-be), all reachable (200), genuinely quiet in-window, not transport failures; sans-newsbites and cisa-news not directly attempted this run (cross-checked indirectly via other sources).

Essential-coverage: all essential-tier sources attempted; no misses.

No borderline drops this run, the completeness sweep found every returned item (including the cross-domain-flagged StyleSmuggler item) already accounted for in a disposition above.