Skip to content

Sam's News โ€” security โ€” 2026-09-08

Security

8.5 Adobe patches critical Commerce and Magento vulnerability exploited for Rust backdoor deployment

Adobe released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability in Magento and Adobe Commerce called StyleSmuggler.

  • Vulnerability affects all current Magento versions including 2.4.9 and Adobe Commerce 2.4.6-p15 with July/August 2026 patches
  • Active attacks began September 4, 2026; at least two stores confirmed breached
  • Adobe has not published CVE, advisory, or patch as of September 6; next security release scheduled September 8
  • Sansec's interim workaround: disable GraphQL (breaks headless and PWA storefronts)
  • Researcher-reported vulnerability name: StyleSmuggler

Sources: The Hacker News RSS, BleepingComputer RSS Update to: Adobe Commerce zero-day vulnerability exploited to backdoor online stores

8.5 Microsoft September 2026 Patch Tuesday addresses record 966 vulnerabilities including two zero-days

Microsoft released a record-breaking security patch fixing 974 vulnerabilities, including two actively exploited zero-days.

Sources: BleepingComputer RSS, SecurityWeek RSS

8 Vietnam-linked APIS database exposes 220 million passenger records

A publicly exposed Advance Passenger Information System database containing 220 million passenger and crew records spanning 2017โ€“2026 was discovered on an unsecured cloud platform.

Sources: BleepingComputer RSS

8 AI-powered credential harvesting attacks compromise thousands in hours

Threat actors deployed autonomous AI agents to harvest thousands of credentials in a large-scale attack completed in under six hours.

Sources: The Hacker News RSS, BleepingComputer RSS

8 N-able Patches Critical Zero-Day in N-central Management Platform

N-able released a patch for a critical zero-day vulnerability in its N-central management platform affecting administrator access.

Sources: SecurityWeek RSS

7.5 Mathspace breach exposes data of over 1 million students and parents

Educational platform Mathspace disclosed a data breach affecting 1.08 million students, parents, and staff members.

Sources: Help Net Security RSS, teiss RSS, SecurityWeek RSS, Hackread RSS Update to: Mathspace data breach affects 1.07 million users

7.5 OpenAI's GPT-6 Astra Reaches Critical Cybersecurity Capability Level

OpenAI discloses that GPT-6 Astra has the capability to find zero-day vulnerabilities but is difficult to monitor for safety.

Sources: BleepingComputer RSS, bleepingcomputer.com RSS Update to: OpenAI's Astra model crosses critical cybersecurity threshold

7.5 ChatGPT Flaw Allowed Planted Prompt to Exfiltrate User Gmail Data

Check Point Research discovered that a concealed instruction in a ChatGPT conversation could silently extract a user's Gmail data and send it to an attacker's account.

Sources: The Hacker News RSS

7.5 WeChat zero-click worm spreads via incoming calls on iPhone and Android

Security researchers demonstrated a worm that takes over WeChat accounts through incoming calls without user interaction, potentially spreading across multiple devices.

Sources: The Hacker News RSS

7.5 FreeIPA vulnerability chain allows anonymous clients to create admin credentials

A security flaw in FreeIPA allows unauthenticated clients to create arbitrary Kerberos identities and gain administrator group membership.

Sources: The Hacker News RSS