daily2026-09-08covers → generated glm-5.3-flash1 · https://zerohour.day/brief/2026-09-08
ZeroHour Daily Brief — 2026-09-08
Top story
Adobe shipped an emergency hotfix (VULN-39341) for CVE-2026-75650, a CVSS 10.0 zero-day in Adobe Commerce and Magento Open Source dubbed StyleSmuggler, under exploitation since September 4 (details). The flaw enables unauthenticated RCE via PHP code injection in Magento's template system; attackers plant a Rust-based Linux backdoor and PHP web shells, with C2 disguised as an NTP server (Sansec). Affected: Adobe Commerce 2.4.4–2.4.9, Commerce B2B 1.3.3–1.5.3, and Magento Open Source 2.4.6–2.4.9 — patch now.
Exploitation & threats
- No new CISA KEV additions in the past 24 hours.
- MikroTik: CERT Poland confirms exploitation since September 2 of the "MikroTrick" chain — CVE-2026-67276 (SSH RSA authentication bypass) plus CVE-2026-86060 (privilege escalation via crafted username) — creating an "ops" account from 82.192.72.4 and 103.102.31.18 (link).
- N-able: pre-auth RCE zero-day CVE-2026-86218 (CVSS 10) in N-central is exploited in the wild, with attempts from 23.234.64.0/18 since September 4 (link).
- Agentic attacks: Google GTIG, drawing on Mandiant telemetry, reports threat actors running autonomous multi-agent AI frameworks for scanning, credential harvesting, and IP rotation — including a six-hour harvesting campaign and a recon panel with 23,800 secrets (link).
- BigBear 2.0: CloudSEC entered the Evilginx2-based phishing-as-a-service panel run by "General Boss," finding 5,137 Microsoft 365 records across 461 organizations, including 474 complete MFA-bypassed sessions (link).
Patch priorities
- Adobe Commerce/Magento: apply hotfix VULN-39341 for CVE-2026-75650 today.
- MikroTik RouterOS: update to 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 for six flaws, including CVE-2026-67277 (8.8) beyond the exploited pair (link).
- N-able N-central: on-prem admins must apply 2026.3 HF4, which supersedes patches for chained CVE-2026-86206/86207 (CVE).
- FreeIPA: 4.13.4 fixes CVE-2026-76578 (9.8); chained with 389-ds CVE-2026-76560, anonymous clients gain admin on default installs (link).
- Chrome: 152.0.7977.82 fixes V8 type confusion CVE-2026-85046 (8.8, sandboxed RCE, public PoC).
- SonicWall SMA 1000: patch both exploited zero-days, including CVE-2026-83548 (CVSS 10.0) (link).
Breaches & incidents
- Vietnam: an exposed Elasticsearch cluster ("pax-info," ~107 GB, Viettel space in Hanoi) held 210,318,069 passenger and 10,465,631 crew records — passport numbers and flight details spanning 2017–2026 — reachable via chained misconfigurations (link).
- Liquid Network: roughly 4,000 BTC (~$320M) was withdrawn from the federation wallet backing Blockstream's Bitcoin sidechain; the hacker, described as a white hat, returned about 3,400 BTC after the bug was fixed (1, 2).
- Mathspace: 1,079,819 Australian and New Zealand users exposed via the Metabase SQL-injection zero-day CVE-2026-72898 (CVSS 10, patched August 6); access ran from August 10, and ShinyHunters claimed the hacks (link).
- Baylor Genetics: 2.8M patients and employees affected, SSNs included; Check Point's roundup also covers Thomson Reuters C-Track court records and ~5,000 Dropbox accounts (link).
- Springfield Public Schools (MA): closed Tuesday after a cyber incident disrupted essential operations; scope under investigation (link).
- Leak sites: 30 new ransomware posts in 24 hours, including the State of Florida DMV (ShinyHunters), NorthShore Health Centers (Insomnia), and Partners Group SK (Qilin).
AI
- Mistral: €3B Series D at €21B+ post-money — the largest European tech equity round — led by Samsung with EQT's Scaleup Europe Fund and PSG Equity co-leading; Advent, BlackRock, and Luxembourg joined (link).
- Anthropic: up to $517B in compute contracts over eleven months, adding at least 14.8 GW since October 2025; Bloomberg puts annualized revenue above $65B, versus OpenAI's $40B+ as of July (link).
- ChatGPT sandbox leak: Check Point found cross-account data leakage between supposedly isolated code-execution containers via a shared JFrog Artifactory instance, with Gmail exfiltration in a proof of concept (link).
- Trace decryption: researchers can extract encrypted reasoning traces from Anthropic, OpenAI, and Google APIs by injecting them into weaker sibling models from the same provider; 315,320 scraped blocks were analyzed (link).
- AI extortion: Mandiant details crews stealing proprietary AI models, prompts, and research for ransom; TeamPCP (UNC6780) has run open-source supply-chain attacks on PyPI, npm, and Docker Hub since March (link).
- Releases: Gemini 3.8 Flash API docs, OpenEvidence Darwin, and MiniCPM5-2B (2B, Apache 2.0).
Watchlist
- StyleSmuggler: expect broad scanning of exposed Magento hosts; hunt for the NTP-disguised C2 and PHP web shells.
- N-able: review N-central logs for 23.234.64.0/18 traffic and unrecognized accounts created since September 4.
- Agentic AI: GTIG's findings and the GLM 5.3-flash "abliterated" essay both point to cheaper, automated hacking capability — shorten patch cycles accordingly (link).
- Liquid Network: watch for Blockstream's postmortem and any federation custody changes after the ~$320M withdrawal.