ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-08covers generated glm-5.3-flash1

ZeroHour Daily Brief — 2026-09-08

Top story

Adobe shipped an emergency hotfix (VULN-39341) for CVE-2026-75650, a CVSS 10.0 zero-day in Adobe Commerce and Magento Open Source dubbed StyleSmuggler, under exploitation since September 4 (details). The flaw enables unauthenticated RCE via PHP code injection in Magento's template system; attackers plant a Rust-based Linux backdoor and PHP web shells, with C2 disguised as an NTP server (Sansec). Affected: Adobe Commerce 2.4.4–2.4.9, Commerce B2B 1.3.3–1.5.3, and Magento Open Source 2.4.6–2.4.9 — patch now.

Exploitation & threats

  • No new CISA KEV additions in the past 24 hours.
  • MikroTik: CERT Poland confirms exploitation since September 2 of the "MikroTrick" chain — CVE-2026-67276 (SSH RSA authentication bypass) plus CVE-2026-86060 (privilege escalation via crafted username) — creating an "ops" account from 82.192.72.4 and 103.102.31.18 (link).
  • N-able: pre-auth RCE zero-day CVE-2026-86218 (CVSS 10) in N-central is exploited in the wild, with attempts from 23.234.64.0/18 since September 4 (link).
  • Agentic attacks: Google GTIG, drawing on Mandiant telemetry, reports threat actors running autonomous multi-agent AI frameworks for scanning, credential harvesting, and IP rotation — including a six-hour harvesting campaign and a recon panel with 23,800 secrets (link).
  • BigBear 2.0: CloudSEC entered the Evilginx2-based phishing-as-a-service panel run by "General Boss," finding 5,137 Microsoft 365 records across 461 organizations, including 474 complete MFA-bypassed sessions (link).

Patch priorities

  • Adobe Commerce/Magento: apply hotfix VULN-39341 for CVE-2026-75650 today.
  • MikroTik RouterOS: update to 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 for six flaws, including CVE-2026-67277 (8.8) beyond the exploited pair (link).
  • N-able N-central: on-prem admins must apply 2026.3 HF4, which supersedes patches for chained CVE-2026-86206/86207 (CVE).
  • FreeIPA: 4.13.4 fixes CVE-2026-76578 (9.8); chained with 389-ds CVE-2026-76560, anonymous clients gain admin on default installs (link).
  • Chrome: 152.0.7977.82 fixes V8 type confusion CVE-2026-85046 (8.8, sandboxed RCE, public PoC).
  • SonicWall SMA 1000: patch both exploited zero-days, including CVE-2026-83548 (CVSS 10.0) (link).

Breaches & incidents

  • Vietnam: an exposed Elasticsearch cluster ("pax-info," ~107 GB, Viettel space in Hanoi) held 210,318,069 passenger and 10,465,631 crew records — passport numbers and flight details spanning 2017–2026 — reachable via chained misconfigurations (link).
  • Liquid Network: roughly 4,000 BTC (~$320M) was withdrawn from the federation wallet backing Blockstream's Bitcoin sidechain; the hacker, described as a white hat, returned about 3,400 BTC after the bug was fixed (1, 2).
  • Mathspace: 1,079,819 Australian and New Zealand users exposed via the Metabase SQL-injection zero-day CVE-2026-72898 (CVSS 10, patched August 6); access ran from August 10, and ShinyHunters claimed the hacks (link).
  • Baylor Genetics: 2.8M patients and employees affected, SSNs included; Check Point's roundup also covers Thomson Reuters C-Track court records and ~5,000 Dropbox accounts (link).
  • Springfield Public Schools (MA): closed Tuesday after a cyber incident disrupted essential operations; scope under investigation (link).
  • Leak sites: 30 new ransomware posts in 24 hours, including the State of Florida DMV (ShinyHunters), NorthShore Health Centers (Insomnia), and Partners Group SK (Qilin).

AI

  • Mistral: €3B Series D at €21B+ post-money — the largest European tech equity round — led by Samsung with EQT's Scaleup Europe Fund and PSG Equity co-leading; Advent, BlackRock, and Luxembourg joined (link).
  • Anthropic: up to $517B in compute contracts over eleven months, adding at least 14.8 GW since October 2025; Bloomberg puts annualized revenue above $65B, versus OpenAI's $40B+ as of July (link).
  • ChatGPT sandbox leak: Check Point found cross-account data leakage between supposedly isolated code-execution containers via a shared JFrog Artifactory instance, with Gmail exfiltration in a proof of concept (link).
  • Trace decryption: researchers can extract encrypted reasoning traces from Anthropic, OpenAI, and Google APIs by injecting them into weaker sibling models from the same provider; 315,320 scraped blocks were analyzed (link).
  • AI extortion: Mandiant details crews stealing proprietary AI models, prompts, and research for ransom; TeamPCP (UNC6780) has run open-source supply-chain attacks on PyPI, npm, and Docker Hub since March (link).
  • Releases: Gemini 3.8 Flash API docs, OpenEvidence Darwin, and MiniCPM5-2B (2B, Apache 2.0).

Watchlist

  • StyleSmuggler: expect broad scanning of exposed Magento hosts; hunt for the NTP-disguised C2 and PHP web shells.
  • N-able: review N-central logs for 23.234.64.0/18 traffic and unrecognized accounts created since September 4.
  • Agentic AI: GTIG's findings and the GLM 5.3-flash "abliterated" essay both point to cheaper, automated hacking capability — shorten patch cycles accordingly (link).
  • Liquid Network: watch for Blockstream's postmortem and any federation custody changes after the ~$320M withdrawal.

Stories in this brief