Skip to content

Sam's News — security — 2026-09-07

Security

8 Nightmare Eclipse group releases zero-day exploits for CrowdStrike, Nvidia, and Avast

Security researcher Nightmare Eclipse released proof-of-concept exploits for zero-day vulnerabilities in CrowdStrike, Nvidia, and Avast antivirus software. PrettyPrague enables privilege escalation in Avast and possibly AVG and Norton; FalconFlank exploits CrowdStrike Falcon Sensor; GreenSection targets Nvidia user-mode components. Vendors have confirmed awareness and issued patches or workarounds.

  • PrettyPrague: privilege escalation in Avast Antivirus and GenDigital products
  • FalconFlank: CrowdStrike Falcon Sensor Office macro remediation privilege escalation bug
  • GreenSection: out-of-bounds memory write in Nvidia user-mode components
  • GenDigital patched Avast vulnerability; CrowdStrike issued workaround guidance

Sources: SecurityWeek AI Web Searched

8 Adobe Commerce zero-day vulnerability exploited to backdoor online stores

A zero-day vulnerability in Magento and Adobe Commerce called StyleSmuggler is being actively exploited to install Linux backdoors on affected systems.

  • Vulnerability affects all current Magento versions including 2.4.9 and Adobe Commerce 2.4.6-p15 with July/August 2026 patches
  • Active attacks began September 4, 2026; at least two stores confirmed breached
  • Adobe has not published CVE, advisory, or patch as of September 6; next security release scheduled September 8
  • Sansec's interim workaround: disable GraphQL (breaks headless and PWA storefronts)
  • Researcher-reported vulnerability name: StyleSmuggler

Sources: SecurityWeek RSS, BleepingComputer RSS Update to: Unpatched Magento and Adobe Commerce zero-day actively exploited to backdoor stores

7.5 N-able releases fourth hotfix in five weeks for critical N-central RCE vulnerability

N-able released its fourth hotfix in five weeks for CVE-2026-86218, an unauthenticated remote code execution vulnerability in N-central affecting all builds before version 2026.3.1.14. N-able's communications conflict on exploitation status, with the incident notice stating the flaw "has been observed being exploited in the wild" while release notes claim no production exploitation confirmations.

  • CVE-2026-86218: unauthenticated remote code execution, CVSS 10.0
  • Static code injection flaw (CWE-96) affecting all N-central builds before 2026.3.1.14
  • Fourth hotfix in five weeks; Hotfix 3 released eight hours before Hotfix 4
  • Hosted N-central instances already patched; on-premises customers must upgrade immediately
  • Huntress recommends IP allowlisting, VPN restriction, or taking servers offline until patching

Sources: The Hacker News AI Web Searched, BleepingComputer RSS

7.5 Hackers exploit MikroTik RouterOS vulnerabilities to hijack exposed routers

Attackers are exploiting a chain of two recently disclosed MikroTik RouterOS flaws to take control of routers with SSH services exposed to the internet.

  • Vulnerability termed 'MikroTrick' involves two unidentified flaws bypassing SSH authentication
  • Affected RouterOS: 6.0.0–6.49.20, 7.0.0–7.23.3, 7.24.0–7.24.1
  • Patches released: 6.49.21, 7.23.5, 7.24.2
  • Attacks documented since at least September 2, 2026
  • Post-compromise indicators: Flagged status warnings, unknown accounts, ssh:-2@ pattern in logs

Sources: BleepingComputer RSS Update to: MikroTik Routers Compromised Via Unauthenticated Internet-Exposed SSH Access

7.5 JSCeal malware bypasses Google authentication using stolen session cookies

JSCeal, a sophisticated JavaScript malware, bypasses Google authentication using stolen session cookies and performs credential harvesting and surveillance. Distributed via malvertising campaigns using fake cryptocurrency trading sites, it has been actively targeting retail traders and cryptocurrency investors across 12 countries in multiple languages since late 2024.

  • First documented by Check Point Research in July 2025
  • Distributed via malvertising with fake TradingView installers on Facebook and Google ads
  • Related SourTrade campaign disclosed by Confiant in August 2026, active since late 2024
  • Targets retail traders and cryptocurrency investors across 12 countries in 25 languages
  • Capabilities: enumerate installed browsers, query saved secrets, cookies, and OAuth tokens
  • Obfuscation uses javascript-obfuscator with RC4-protected strings and control-flow flattening

Sources: The Hacker News AI Web Searched

7.5 BigBear phishing-as-a-service bypasses MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has successfully bypassed multi-factor authentication at 258 organizations and stolen over 5,000 Microsoft 365 credentials.

Sources: BleepingComputer RSS

7.5 Weekly security digest: Chrome zero-day, router hijacks, supplier chain attack, and QR code bypass

A weekly security roundup identified four major threats: Chrome zero-day CVE-2026-85046 (type confusion in V8, CVSS 8.8) under active exploitation, MikroTik RouterOS flaws being actively exploited, a software supply chain credential theft attack, and QR code phishing that bypasses image-blocking email defenses. N-able also patched three critical N-central vulnerabilities with CVSS 10.0 rated pre-authenticated RCE, with signs of active exploitation observed post-September 4.

  • Chrome CVE-2026-85046: type confusion in V8, CVSS 8.8, versions prior to 152.0.7977.82
  • N-able N-central: three critical flaws (CVE-2026-86206/86207/86218), CVSS 10.0 pre-authenticated RCE
  • QR code phishing: scannable codes built from text characters bypass image-blocking defenses
  • MikroTik RouterOS flaws actively exploited; software supply chain attack delivered credential theft code

Sources: The Hacker News AI Web Searched

7.5 North Korean hackers deploy new Linux espionage toolkit targeting automotive and media sectors

North Korean threat actors deployed a sophisticated Linux toolkit against South Korean automotive and media organizations to conduct long-term surveillance. The toolkit embeds a backdoor called 'ted backdoor' into HAProxy and includes trojanized system tools. Initial access was gained through a Groupware portal vulnerability, followed by credential harvesting and lateral movement across target infrastructure.

  • Ted backdoor embeds into HAProxy 2.8.12, trojanizes agetty, atd, crond, polkitd, sshd
  • Supports remote command execution, credential harvesting, script injection into web traffic
  • CurlRAT polls C2 servers every 12 hours for commands
  • Framework likely in use since late 2024; initial access via Groupware login portal vulnerability
  • Ted backdoor leverages HAProxy's filter API, memory pools, event scheduler to evade monitoring

Sources: SecurityWeek AI Web Searched

7.5 PEEP post-exploitation toolkit disguised as browser extension enables host command execution

Researchers disclosed PEEP, a post-exploitation toolkit disguised as a Chrome/Edge bookmarks extension that executes host commands on compromised systems. It bypasses browser security, exfiltrates browsing data and credentials, and communicates with command servers every 30 seconds—requiring prior administrative access to install.

  • Masquerades as "Smart Bookmarks" extension (ID: ejkndncpkdcjcikfhiamcdehdoegilbj)
  • Polls C2 server (206.237.30.232 or xfjcc.fun) every 30 seconds over plaintext HTTP
  • Steals browsing history, cookies, session metadata, system info, and credentials
  • Built on RedExt framework; includes Chinese-language code artifacts suggesting Chinese-speaking actor
  • Requires prior admin or code execution access; post-compromise toolkit with no initial vector

Sources: The Hacker News AI Web Searched

AI

7 OpenAI rolls out ChatGPT Astra to $20 Plus subscription tier

OpenAI is making ChatGPT Astra, its most powerful model, available to $20 Plus subscribers, with no announced timeline for free user access.

Sources: Digital Trends RSS, BleepingComputer RSS