Sam's News โ security โ 2026-09-08¶
Security¶
8.5 Adobe patches critical Commerce and Magento vulnerability exploited for Rust backdoor deployment¶
Adobe released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability in Magento and Adobe Commerce called StyleSmuggler.
- Vulnerability affects all current Magento versions including 2.4.9 and Adobe Commerce 2.4.6-p15 with July/August 2026 patches
- Active attacks began September 4, 2026; at least two stores confirmed breached
- Adobe has not published CVE, advisory, or patch as of September 6; next security release scheduled September 8
- Sansec's interim workaround: disable GraphQL (breaks headless and PWA storefronts)
- Researcher-reported vulnerability name: StyleSmuggler
Sources: The Hacker News RSS, BleepingComputer RSS Update to: Adobe Commerce zero-day vulnerability exploited to backdoor online stores
8.5 Microsoft September 2026 Patch Tuesday addresses record 966 vulnerabilities including two zero-days¶
Microsoft released a record-breaking security patch fixing 974 vulnerabilities, including two actively exploited zero-days.
Sources: BleepingComputer RSS, SecurityWeek RSS
8 Vietnam-linked APIS database exposes 220 million passenger records¶
A publicly exposed Advance Passenger Information System database containing 220 million passenger and crew records spanning 2017โ2026 was discovered on an unsecured cloud platform.
Sources: BleepingComputer RSS
8 AI-powered credential harvesting attacks compromise thousands in hours¶
Threat actors deployed autonomous AI agents to harvest thousands of credentials in a large-scale attack completed in under six hours.
Sources: The Hacker News RSS, BleepingComputer RSS
8 N-able Patches Critical Zero-Day in N-central Management Platform¶
N-able released a patch for a critical zero-day vulnerability in its N-central management platform affecting administrator access.
Sources: SecurityWeek RSS
7.5 Mathspace breach exposes data of over 1 million students and parents¶
Educational platform Mathspace disclosed a data breach affecting 1.08 million students, parents, and staff members.
Sources: Help Net Security RSS, teiss RSS, SecurityWeek RSS, Hackread RSS Update to: Mathspace data breach affects 1.07 million users
7.5 OpenAI's GPT-6 Astra Reaches Critical Cybersecurity Capability Level¶
OpenAI discloses that GPT-6 Astra has the capability to find zero-day vulnerabilities but is difficult to monitor for safety.
Sources: BleepingComputer RSS, bleepingcomputer.com RSS Update to: OpenAI's Astra model crosses critical cybersecurity threshold
7.5 ChatGPT Flaw Allowed Planted Prompt to Exfiltrate User Gmail Data¶
Check Point Research discovered that a concealed instruction in a ChatGPT conversation could silently extract a user's Gmail data and send it to an attacker's account.
Sources: The Hacker News RSS
7.5 WeChat zero-click worm spreads via incoming calls on iPhone and Android¶
Security researchers demonstrated a worm that takes over WeChat accounts through incoming calls without user interaction, potentially spreading across multiple devices.
Sources: The Hacker News RSS
7.5 FreeIPA vulnerability chain allows anonymous clients to create admin credentials¶
A security flaw in FreeIPA allows unauthenticated clients to create arbitrary Kerberos identities and gain administrator group membership.
Sources: The Hacker News RSS