The 24-hour period from September 7-8, 2026 revealed a highly active threat landscape dominated by multiple critical zero-day vulnerabilities, widespread phishing campaigns, and aggressive ransomware operations. Most concerning are critical-severity flaws in widely-deployed platforms including Adobe Commerce/Magento (CVE-2026-75650, CVSS 10.0), JetBrains Hub (CVE-2026-86480, CVSS 9.8), and the knowns application suite (three critical CVEs). The BigBear 2.0 phishing-as-a-service framework successfully bypassed MFA at 258 organizations, stealing over 5,000 Microsoft 365 credentials. A Magento zero-day dubbed "StyleSmuggler" is being actively exploited to deploy Linux backdoors, while threat actors continue exploiting MikroTik and ConnectWise ScreenConnect vulnerabilities.
Ransomware groups demonstrated sustained activity with 22 new victim listings across multiple operators, including a significant breach at NFM Lending exposing 2.5TB of customer financial data. Data breach disclosures continued with Mathspace (1+ million users), Trezor (81,000 customers total), and multiple regional platforms in South Korea reporting credential exposure. Infrastructure-focused attacks included a $320M Bitcoin theft from the Liquid Network and multiple school district disruptions. The convergence of authentication bypass vulnerabilities, active zero-day exploitation, and credential harvesting campaigns represents an elevated risk to enterprise environments.
Defenders should prioritize emergency patching of Adobe Commerce, JetBrains, and knowns systems, implement enhanced MFA monitoring for bypass attempts, and review network segmentation for internet-exposed management interfaces. The StyleSmuggler Magento zero-day requires immediate attention as no patch is available.
Multiple critical-severity vulnerabilities are under active exploitation, including zero-days in Adobe Commerce/Magento and several authentication bypass flaws in enterprise platforms.
All versions of Magento and Adobe Commerce are vulnerable to active exploitation of the StyleSmuggler zero-day, allowing attackers to deploy Linux backdoors. No patch currently available, requiring immediate mitigation measures.
Critical template engine vulnerability in Adobe Commerce allows arbitrary code execution in the context of the current user. CVSS 10.0, requires no user interaction and no privileges.
Unauthenticated attackers can register a trusted service and gain superuser privileges in JetBrains Hub versions before 2026.2.52442. CVSS 9.8 critical severity.
Three critical CVEs affecting knowns versions before 0.30.0: unauthenticated API access (CVE-2026-86543, CVSS 9.8), path traversal allowing arbitrary file writes (CVE-2026-86542, CVSS 9.1), and authorization bypass enabling privilege escalation (CVE-2026-86544, CVSS 8.1).
N-able released emergency hotfix for maximum-severity (CVSS 10.0) remote code execution vulnerability in N-central RMM platform amid ongoing exploitation attempts.
Improper authentication in YouTrack Helpdesk allows unauthenticated attackers to perform account takeover via self-asserted email addresses. CVSS 9.8 critical severity.
Deserialization of untrusted data vulnerability in Next4Biz CSM allows remote code injection. CVSS 9.8 critical. Vendor did not respond to early disclosure.
Attackers are chaining two recently disclosed MikroTik RouterOS vulnerabilities to take control of devices with SSH services exposed to the internet.
ConnectWise disclosed a new ScreenConnect Remote Access vulnerability without an available patch, providing only temporary mitigation measures. Patch expected later this week.
Sophisticated phishing campaigns leveraging MFA bypass techniques and AI-enhanced social engineering are actively compromising enterprise credentials at scale.
Phishing-as-a-Service framework BigBear 2.0 successfully bypassed multi-factor authentication at 258 organizations, stealing over 5,000 Microsoft 365 credentials. CloudSEK researchers gained admin access to the control panel revealing the scope.
Lock and Code podcast explores how loyalty points fraud has become a significant revenue stream for cybercriminal groups, with organized operations targeting rewards programs.
OpenAI testing new ChatGPT feature that learns writing styles by analyzing examples from users' connected apps, creating potential data exposure risks from integrated personal applications.
Personalized AI-generated replies and voice notes are being used by OnlyFans promoters to appear human, making it increasingly difficult to distinguish between humans, chatbots, and AI agents in social engineering contexts.
Multiple significant data breaches disclosed affecting over 2 million individuals globally, including financial institutions, educational platforms, cryptocurrency services, and regional applications.
National mortgage lender NFM Lending (originating $7.15B annually with 1,000+ employees) suffered data breach exposing over 2.5TB of sensitive customer information including names, Social Security numbers, bank accounts, credit information, and loan details.
Hackers drained approximately $320 million in Bitcoin from Liquid Network's federation wallet. Attackers claimed to be 'good guys' while executing the theft from the Blockstream-developed Bitcoin sidechain used by exchanges and financial institutions.
Online mathematics learning platform Mathspace disclosed breach affecting 1,079,819 people in Australia and New Zealand. Attackers accessed internal Metabase reporting system and downloaded user information on September 3, 2026.
Cryptocurrency hardware wallet maker Trezor reports August data breach at shipping provider ShipMonk now affects additional 67,000 U.S. customers, bringing total impact to 81,000 individuals.
Another trove of data from Berlin's government appeared online including stolen login credentials. Germany's information security agency separately issued warning about Rhysida ransomware group operations.
Jinny Beauty Supply, one of the largest Korean-American wholesale beauty distributors serving 7,400+ stores and 2,800+ international distributors, had corporate data exposed including distribution center information across 9 US locations.
HYBE-affiliated Weverse platform confirmed security incident affecting 422,584 K-pop fan accounts. Exposed information consists mainly of internal identifiers that cannot be used outside the platform.
South Korean beauty medical platform Gangnam Unni (operated by Healing Paper) disclosed personal information leak affecting approximately 220,000 domestic and international users following abnormal access detected on September 4, 2026.
Ransomware groups disclosed 22 new victims across multiple sectors including manufacturing, healthcare, logistics, construction, and retail. Notable campaigns from MetaEncryptor, Aurora, Direwolf, and established groups.
Singapore Technologies Engineering, multinational technology and defense conglomerate with aerospace, smart city, defense and public security segments, listed as victim by MetaEncryptor ransomware group.
Pittsburgh-based Benshaw Inc. and affiliated UTG entities (Unico, Benshaw Canada, AuCom, Excel, Noble Victoria) breached. Data includes 100+ corporate credit cards with full PAN+SSN+DOB, 637 former employees' full SSN/DOB/address, and 88 active employee records.
Leading Canadian construction and infrastructure services company (founded 1951) targeted by MetaEncryptor ransomware. EllisDon provides construction management, engineering, and facilities management across healthcare, transportation, and commercial sectors.
US-based medical technology company specializing in women's health, diagnostic imaging, and surgical products targeted by MetaEncryptor. Hologic develops breast health, gynecology, diagnostics, and osteoporosis assessment systems.
Leading US destination for rugs, furniture, and home decor breached by Rhysida. Stolen data includes database of 50,193 customers with full names, addresses, emails, phone numbers, purchase amounts (CSV), and ~10,800 signed delivery note scans.
Human resources software provider Lightcast (lightcast.io) targeted by Direwolf ransomware group.
International education technology platform connecting students with 1,500+ campuses and 50,000+ programs across Canada, USA, UK, Australia, and Germany targeted by Kazu ransomware.
ShinyHunters group issued final warning with deadline of September 8, 2026, threatening to leak Medela.com data along with 'several annoying digital problems' if ransom not paid.
Abuse.ch tracking shows active distribution of Mirai variants, Mozi botnet, RemcosRAT, MassLogger, PureLogsStealer, and ConnectWise ScreenConnect abuse.
Active Mirai botnet C2 at 94.154.43.221 distributing multiple architecture variants (armv4l, armv5l, armv6l, armv7l, i486, mips, mipsrouter) via telnet.sh and iran.* payloads. Over 20 distinct download URLs identified.
32-bit ELF MIPS Mozi botnet samples distributed from 42.230.42.141:49057 via bin.sh and /i endpoints targeting IoT devices.
Multiple RemcosRAT payloads distributed via steganographic PNG images hosted on od.lk (OpenDrive) and opendrive.com API. Files include MSI_PRO.png and img_052027.png containing embedded RAT payloads.
Multiple IP addresses (45.61.176.53, 45.61.170.60) distributing ConnectWise ScreenConnect client executables (support.client.exe, ScreenConnect.ClientSetup.exe) for unauthorized remote access.
PureLogsStealer distributed through Cloudflare Workers (pablosoftwareplus.workers.dev) and compromised dinamikakargo.com site using steganographic image files to hide malicious payloads.
MassLogger credential stealer distributed through catbox.moe file sharing service in ZIP archive format.
Security research reveals concerning vulnerabilities in consumer IoT devices including smart TVs that enable surveillance and privacy violations.
Security testing found LG smart TVs can track viewing habits, scan home networks, and contain flaws allowing attackers to record conversations even when TV is in standby mode. Privacy and security concerns for home network environments.
National governments strengthening healthcare sector cybersecurity requirements following surge in attacks against medical institutions.
Massachusetts Springfield Public Schools closed Tuesday following cyber incident that disrupted systems necessary for essential school operations. District continuing response efforts.
Japan's Health, Labor and Welfare Ministry included ¥13.7 billion in fiscal 2027 budget request to strengthen cybersecurity measures at hospitals countering surging number of cyberattacks on medical institutions. Represents significant national healthcare security investment.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.