FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Critical Unauthenticated RCE "StyleSmuggler" in Adobe Commerce and Magento

Sansec has identified "StyleSmuggler," a critical zero-day vulnerability enabling unauthenticated remote code execution (RCE) within Adobe Commerce and Magento Open Source. Exploitation, detected in the wild on September 4, 2026, utilizes injection via CSS and style-related parameters to bypass existing security filters. Attackers leverage this vector to deploy sophisticated web shells and persistent backdoors capable of surviving subsequent security patches. This flaw grants complete server-level control, facilitating the theft of customer PII and payment data. Organizations must prioritize immediate file integrity monitoring and credential rotation to mitigate the risk of deep-seated persistence.

ClickFix Malware Campaign: Decentralized Payload Hosting via WordPress Exploitation

A widespread cyberattack campaign has compromised over 5,400 WordPress websites to distribute multi-stage malware using the "ClickFix" social engineering technique. Attackers leverage critical RCE vulnerabilities in plugins—including CVE-2026-14894 (Super Forms) and CVE-2026-32475 (Elementor Pro)—to inject scripts that display deceptive Cloudflare CAPTCHAs or browser error prompts. These lures trick users into manually executing malicious PowerShell or Terminal commands. To ensure resilience, the campaign utilizes "EtherHiding," hosting payloads and C2 resolution on the Polygon and BNB Smart Chain blockchains. Impacted systems are infected with diverse payloads, including DeepLoad, KongTuke (ModeloRAT), and ACR Stealer, targeting both Windows and macOS environments for enterprise credential theft and network intrusion.

Silent Breach: Lessons from Hosting-Layer Compromises

Attackers exploited CMS vulnerabilities and server-level misconfigurations within web hosting environments to bypass perimeter defenses, leading to extended attacker dwell times. The breach utilized hosting-layer defense bypass techniques and web shells to establish persistence and create entry points into broader enterprise networks. Research from Patchstack highlights a systemic failure, noting that 87% of vulnerability exploits successfully bypassed standard hosting defenses, including common security plugins and firewalls. This incident underscores the risks of the shared responsibility model, where perceived provider-side security leads to insufficient enterprise-level monitoring and increased supply chain exposure.


LINK COPIED TO CLIPBOARD