ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardDaily Briefing › 6 Sept 2026
Daily Briefing

Sunday, 6 September 2026

Unpatched Magento and Adobe Commerce zero-day is being used to backdoor stores; Chrome flaw added to CISA's exploited list

Recent reporting centres on two flaws already under attack — an unpatched remote-code-execution bug in Magento and Adobe Commerce, and a Google Chrome vulnerability CISA now lists as exploited — alongside MikroTik router takeovers, new browser fixes, and a stealer that disables Windows defences.

Sansec said in an advisory published on September 5 that attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, and are using it to backdoor stores. The Hacker News reported that Sansec discovered the flaw. No fixed version has been named. Match your estate against these products; if you run Magento Open Source or Adobe Commerce, follow Sansec's advisory and inspect store servers for unauthorised code and backdoors.

The Hacker News reported that, according to CERT Polska's attack warning published on September 5, attackers are exploiting MikroTik routers whose SSH remote-access service is reachable from the internet to gain full administrative control without authentication, and that successful attacks date to at least September 2. Review whether any MikroTik SSH service is exposed to the internet, per CERT Polska's warning.

On browsers: CISA lists CVE-2026-85046, a Google Chrome vulnerability, as known to be exploited. Google's advisory covers Chrome up to the fix in 152.0.7977.82; the flaw carries a CVSS 3.1 base score of 8.8. Google's advisory also addresses CVE-2026-84354 (CVSS 9.6), CVE-2026-84325 (CVSS 9.8) and CVE-2026-84324 (CVSS 9.0), fixed in Chrome 152.0.7977.75. Mozilla's advisories address CVE-2026-84143 (CVSS 9.8), fixed in Firefox 140.15.0, and CVE-2026-84142 (CVSS 9.8), fixed in Firefox 155.0.0. Update Chrome to 152.0.7977.82 and Firefox to the fixed releases Mozilla names.

The Hacker News reported that Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself; one switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

Help Net Security reported that Anthropic has started locking users out of their Claude accounts after their login sessions were compromised through infostealer malware.

BleepingComputer reported that threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. Fold this into your phishing detection and user awareness, and prioritise the exploited items above first.

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →