- fc-cacheSecond variant of StyleSmuggler backdoor disguise, emerged September 6
- StyleSmugglerZero-day RCE vulnerability in Adobe Commerce/Magento used to deploy backdoors
- [kworker/u:8:0]First variant of StyleSmuggler backdoor disguise, deployed from September 4
ThreatNoir Afternoon Brief — September 7
Afternoon Review in IT Security — September 7, 2026
The threat landscape continues to shift rapidly as attackers exploit newly disclosed vulnerabilities across multiple critical infrastructure and business platforms. Today's security briefing covers active exploitation campaigns targeting e-commerce systems, network infrastructure, remote management tools, and remote access software, each presenting significant risk to organizations worldwide.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A critical zero-day vulnerability in Adobe Commerce and Magento platforms is being actively exploited in the wild to deploy persistent backdoors on online retail stores. The vulnerability, tracked as StyleSmuggler, allows attackers to execute arbitrary code and establish stealthy backdoor access on compromised systems. The malware indicators associated with this campaign include process names such as [kworker/u:8:0] and fc-cache, which are designed to blend into legitimate system activity. Source: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Organizations operating Adobe Commerce or Magento installations should immediately assess their systems for signs of compromise and implement enhanced monitoring for the identified malware signatures. This threat represents a significant supply-chain risk, as successful compromises could lead to customer data theft, payment card fraud, and long-term unauthorized access to sensitive business systems.
Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers
A chain of recently disclosed vulnerabilities in MikroTik RouterOS is being actively exploited by threat actors to gain complete control of exposed router devices. The attack chain leverages CVE-2026-67276, CVE-2026-67277, and CVE-2026-86060 to target routers with SSH services exposed to the internet, enabling full system takeover. Malicious traffic has been observed originating from IP addresses 103.102.31.18 and 82.192.72.4 as part of coordinated exploitation efforts. Source: Hackers exploit new MikroTik RouterOS flaws to hijack routers
Network administrators managing MikroTik infrastructure should prioritize patching these vulnerabilities and restrict SSH access to trusted networks only. Compromised routers can serve as persistent entry points for lateral movement into organizational networks and may be repurposed for botnet participation or traffic interception.
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able has released its fourth critical security hotfix in five weeks for the N-central remote monitoring and management platform, addressing an unauthenticated remote code execution vulnerability. The vulnerability chain involves CVE-2026-18556, CVE-2026-18577, and CVE-2026-86218, with evidence suggesting active exploitation in the wild, though N-able's official release notes indicate this remains unconfirmed. All on-premises N-central builds below version 2026.3.1.14, including systems updated to the previous Hotfix 3, require immediate deployment of Hotfix 4. Source: N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
The rapid succession of critical patches suggests either a systematic vulnerability discovery process or active exploitation attempts targeting this widely deployed RMM platform. Organizations using N-central should treat this update as critical priority, as successful exploitation could grant attackers direct access to managed customer environments.
Modified ScreenConnect Clients Used in Worm-Like Campaign
A sophisticated attack campaign is leveraging backdoored ScreenConnect remote access clients to propagate malware in a worm-like fashion across networks. The attacks utilize compromised ScreenConnect instances to transfer and execute payloads, including UltraViewer and VBScript-based malware, to newly connected clients. The campaign employs MITRE ATT&CK techniques T1059.003 (command-line interface scripting) and T1547.001 (registry run keys for persistence), enabling self-propagating infection chains. Source: Modified ScreenConnect Clients Used in Worm-Like Campaign
This campaign demonstrates how compromised remote access tools can become force multipliers for attackers, enabling rapid lateral movement and persistent access across multiple systems. Organizations should audit their ScreenConnect deployments for unauthorized modifications, implement strict access controls, and monitor for suspicious payload transfers between connected clients.
The combination of these threats—from e-commerce backdoors to infrastructure hijacking to supply-chain compromises in management tools—underscores the importance of rapid vulnerability assessment, timely patching, and enhanced detection capabilities across all critical systems and services.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- SSH authentication bypass flaw in MikroTik RouterOS
- SSH privilege escalation flaw in MikroTik RouterOS
- Bandwidth-test service flaw allowing memory leak or router restart
103.102.31.18IP observed attempting to exploit MikroTrick82.192.72.4IP linked to confirmed successful attacks
- Critical unauthenticated RCE vulnerability in N-central.
- Previously addressed vulnerability related to CVE-2026-18577.
- Previously addressed vulnerability allowing authentication bypass and account takeover.