Weekly review

ThreatNoir Afternoon Brief — September 7

2026-09-07Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 7, 2026

The threat landscape continues to shift rapidly as attackers exploit newly disclosed vulnerabilities across multiple critical infrastructure and business platforms. Today's security briefing covers active exploitation campaigns targeting e-commerce systems, network infrastructure, remote management tools, and remote access software, each presenting significant risk to organizations worldwide.

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

A critical zero-day vulnerability in Adobe Commerce and Magento platforms is being actively exploited in the wild to deploy persistent backdoors on online retail stores. The vulnerability, tracked as StyleSmuggler, allows attackers to execute arbitrary code and establish stealthy backdoor access on compromised systems. The malware indicators associated with this campaign include process names such as [kworker/u:8:0] and fc-cache, which are designed to blend into legitimate system activity. Source: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Organizations operating Adobe Commerce or Magento installations should immediately assess their systems for signs of compromise and implement enhanced monitoring for the identified malware signatures. This threat represents a significant supply-chain risk, as successful compromises could lead to customer data theft, payment card fraud, and long-term unauthorized access to sensitive business systems.

Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers

A chain of recently disclosed vulnerabilities in MikroTik RouterOS is being actively exploited by threat actors to gain complete control of exposed router devices. The attack chain leverages CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060 to target routers with SSH services exposed to the internet, enabling full system takeover. Malicious traffic has been observed originating from IP addresses 103.102.31.18 and 82.192.72.4 as part of coordinated exploitation efforts. Source: Hackers exploit new MikroTik RouterOS flaws to hijack routers

Network administrators managing MikroTik infrastructure should prioritize patching these vulnerabilities and restrict SSH access to trusted networks only. Compromised routers can serve as persistent entry points for lateral movement into organizational networks and may be repurposed for botnet participation or traffic interception.

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able has released its fourth critical security hotfix in five weeks for the N-central remote monitoring and management platform, addressing an unauthenticated remote code execution vulnerability. The vulnerability chain involves CVE-2026-18556, CVE-2026-18577, and CVE-2026-86218, with evidence suggesting active exploitation in the wild, though N-able's official release notes indicate this remains unconfirmed. All on-premises N-central builds below version 2026.3.1.14, including systems updated to the previous Hotfix 3, require immediate deployment of Hotfix 4. Source: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The rapid succession of critical patches suggests either a systematic vulnerability discovery process or active exploitation attempts targeting this widely deployed RMM platform. Organizations using N-central should treat this update as critical priority, as successful exploitation could grant attackers direct access to managed customer environments.

Modified ScreenConnect Clients Used in Worm-Like Campaign

A sophisticated attack campaign is leveraging backdoored ScreenConnect remote access clients to propagate malware in a worm-like fashion across networks. The attacks utilize compromised ScreenConnect instances to transfer and execute payloads, including UltraViewer and VBScript-based malware, to newly connected clients. The campaign employs MITRE ATT&CK techniques T1059.003 (command-line interface scripting) and T1547.001 (registry run keys for persistence), enabling self-propagating infection chains. Source: Modified ScreenConnect Clients Used in Worm-Like Campaign

This campaign demonstrates how compromised remote access tools can become force multipliers for attackers, enabling rapid lateral movement and persistent access across multiple systems. Organizations should audit their ScreenConnect deployments for unauthorized modifications, implement strict access controls, and monitor for suspicious payload transfers between connected clients.

The combination of these threats—from e-commerce backdoors to infrastructure hijacking to supply-chain compromises in management tools—underscores the importance of rapid vulnerability assessment, timely patching, and enhanced detection capabilities across all critical systems and services.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Malware3
  • fc-cache
    Second variant of StyleSmuggler backdoor disguise, emerged September 6
  • StyleSmuggler
    Zero-day RCE vulnerability in Adobe Commerce/Magento used to deploy backdoors
  • [kworker/u:8:0]
    First variant of StyleSmuggler backdoor disguise, deployed from September 4