Weekly review

ThreatNoir Morning Brief — September 7

2026-09-07Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 7, 2026

September 7, 2026 brings critical security developments across multiple fronts, from sophisticated phishing evasion techniques to zero-day exploits targeting widely-used enterprise platforms. Organizations face mounting pressure to patch vulnerabilities and strengthen email defenses as threat actors continue to innovate their attack methodologies.

Attackers Conceal Phishing Lures Using Invisible Unicode Characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, leveraging invisible Unicode characters to evade email security filters. This method allows attackers to embed malicious content that remains hidden from automated detection systems while remaining visible to end users, creating a significant challenge for traditional email security solutions. The technique represents an evolution in phishing sophistication and underscores the need for enhanced user awareness and advanced email filtering capabilities. Source: Bleeping Computer

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

A critical unpatched vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to install backdoors on e-commerce platforms without requiring authentication. Discovered by Dutch e-commerce security company Sansec and designated as StyleSmuggler, the vulnerability enables threat actors to execute arbitrary code on compromised servers. Attacks began on September 4, 2026, immediately following public disclosure, indicating rapid weaponization of this zero-day flaw. Online retailers running these platforms face immediate risk and should implement available mitigations while awaiting official patches. Source: The Hacker News

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains disclosed a security incident affecting its Cadence platform resulting from exploitation of a critical vulnerability in TeamCity that remained unpatched in their environment. Unidentified threat actors leveraged the vulnerability to gain unauthorized access and extract sensitive AWS credentials used for Cadence executions. JetBrains has advised all Cadence users to immediately revoke and rotate credentials and secrets that may have been compromised during the breach. This incident highlights the risks of delayed patching even within organizations responsible for development tools and infrastructure. Source: The Hacker News

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates addressing critical vulnerabilities in VMware Workstation and Fusion, including an integer-overflow flaw tracked as CVE-2026-59346 with a CVSS score of 9.3. A local attacker with elevated privileges can exploit this vulnerability to execute arbitrary code on the host system, effectively escaping the virtual machine isolation boundary. This vulnerability poses significant risk to organizations relying on virtualization for security isolation and workload containment. Immediate patching is strongly recommended for affected deployments. Source: The Hacker News

The security landscape continues to evolve with attackers demonstrating sophistication across multiple attack vectors, from email-based social engineering to supply chain exploitation and virtualization escape techniques. Organizations must prioritize patch management, credential rotation, and employee security awareness as fundamental defensive measures.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).