Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Unpatched Magento Zero-Day 'StyleSmuggler' Backdoors Online Stores (20260906)

Sansec warns attackers are exploiting StyleSmuggler, an unpatched unauthenticated Magento Open Source / Adobe Commerce zero-day that backdoors store servers even when fully patched; JetBrains admits attackers used TeamCity CVE-2026-63077 to breach its own Cadence cloud and steal AWS credentials; CERT Polska flags unauthenticated MikroTik RouterOS SSH hijacks; Broadcom patches VMware Workstation/Fusion CVE-2026-59346 and CVE-2026-59347; Trezor says ShipMonk's Metabase CVE-2026-72898 breach exposed 67,000 more U.S. customers; Elastic documents four REVSTEALER-linked persistence modules including a miner that disables Windows Update and Defender.

StyleSmuggler Magento Adobe-Commerce Zero-Day Sansec JetBrains TeamCity CVE-2026-63077 MikroTik RouterOS VMware CVE-2026-59346 CVE-2026-59347 Trezor ShipMonk CVE-2026-72898 REVSTEALER Elastic

Unpatched Magento Zero-Day ‘StyleSmuggler’ Backdoors Online Stores

Dutch e-commerce security firm Sansec published an advisory on September 5 for a new unauthenticated vulnerability in Magento Open Source and Adobe Commerce that lets attackers run code on a store’s server and install a persistent backdoor — naming it StyleSmuggler and warning that exploitation began September 4. “Sansec is publishing early because stores are being compromised right now.” As of September 6, Adobe has published no advisory, CVE identifier, patch, or workaround; its security bulletin index lists nothing after the August 11 update.

Sansec says all current versions are affected, including 2.4.9, and reproduced the full unauthenticated chain on clean installs of 2.4.7, 2.4.8, and 2.4.9. The first observed victim ran 2.4.6-p15 with Adobe’s July and August 2026 updates applied — the latest patch level Adobe offers for that release line — so patch status did not matter. Hosting firm Disrex Group, which responded to two compromised stores, confirmed a Sansec Shield customer (Store A, Magento 2.4.8) was breached at 23:10 UTC on September 4 with Shield active — hours before Sansec’s first blocking rules existed — and a second store (2.4.7-p2, eight patch levels behind) hit at 00:55 UTC September 5. The implant runs as a background process disguised under the legitimate kernel-thread name [kworker/u:8:0], installs a ~1.9 MB stripped static Rust binary (x86-64 and arm64) at ~/.local/share/.gvfsd/gvfsd-user, and re-arms itself every five minutes through a cron entry written directly to the spool file — on one store the line appeared 1,728 times and was re-added within a second of removal. On another store the implant made no outbound connections at all but held 28 connections to the local Redis instance, reading Magento’s session storage. Sansec’s interim advice is to temporarily disable GraphQL; Disrex notes headless and PWA storefronts require it. Adobe’s next scheduled security release is September 8 — unknown whether it covers this flaw.

Why This Reshapes E-Commerce Platform Risk

The episode collapses the assumption that a patched, protected store is safe: the first victim was at the newest patch level and one breached store ran an active, licensed security module. It also exposes a response-time asymmetry — attackers moved within hours of discovery while Adobe’s fix cadence is a scheduled monthly release — and a persistence design aimed at operational blind spots: kernel-thread-name disguise, binaries outside the web root, spool-file cron writes that bypass crontab logging, and Redis session reads that could feed customer-account or payment-session abuse in later stages. For enterprises running Magento or Adobe Commerce, the interim mitigation (disabling GraphQL) collides with headless commerce architectures, making this a business decision as much as a security one.

🔗 Reference: The Hacker News


Active Threats This Week

📌 JetBrains breached through its own unpatched TeamCity — Cadence credentials and AWS keys exposed JetBrains disclosed that unidentified attackers exploited CVE-2026-63077 (CVSS 9.8, TeamCity deserialization flaw; KEV-listed August 5 and covered in our August digests) between August 8 and 24 to break into Cadence, its hosted cloud-computing service for running ML workloads on cloud GPUs from PyCharm. Confirmed access includes personal data (names, emails, last-login timestamps, last IPs), a full 2024 Cadence server backup containing credentials, AWS IAM users and secrets including those of JetBrains employees, files in JetBrains AWS S3 buckets, and potentially source code PyCharm users synchronized to the server. The compromised server (api.cadence.jetbrains.com) is offline; JetBrains conceded it “should have been patched” as part of its own vulnerability response. All Cadence users should revoke and rotate credentials and treat prior executions as untrusted. Observed IOC IPs: 150.109.230.104, 43.153.227.206, 62.210.127.48, 210.247.242.190, 15.235.225.205, 152.233.30.18. 🔗 Reference: The Hacker News

📌 CERT Polska: unauthenticated hijacks of internet-exposed MikroTik RouterOS SSH CERT Polska’s September 5 attack warning says attackers are taking full administrative control of MikroTik routers without authentication through SSH services reachable from the internet; successful attacks date to at least September 2. No victim count or actor identity has been published. Fixed releases: RouterOS 6.49.21, 7.23.4 (with 7.23.5 recommended on the long-term channel — it also fixes an IPv6 DHCP regression introduced in 7.23.4), 7.24.2, and development-channel 7.25beta3. Default firewall rules on home devices block public management access; organizations with managed or ISP-deployed MikroTik equipment should audit exposure and check for unauthorized configuration changes. 🔗 Reference: The Hacker News

📌 VMware Workstation and Fusion: CVE-2026-59346 (CVSS 9.3) and CVE-2026-59347 (CVSS 8.1) Broadcom patched two guest-to-host flaws in VMware Workstation and Fusion 25H2 and 26H1. CVE-2026-59346 is an integer-overflow flaw where a local attacker with elevated privileges on a VM using a VMXNET3 virtual network adapter can execute code on the host; CVE-2026-59347 is a stack-based buffer overflow in HGFS allowing code execution as the host’s VMX process (reported by Tencent Xuanwu Lab). Both require local administrative privileges inside the guest — reachable via separate phishing or misconfiguration compromises. Fixes ship in Workstation 26H1u1 and Fusion 26H1u1; no workarounds exist and no in-the-wild exploitation is confirmed yet, but VMware flaws remain an attack magnet after last month’s vCenter CVE-2026-59309/CVE-2026-59310 campaign across 47 countries. 🔗 Reference: The Hacker News

📌 Trezor: ShipMonk breach exposed 67,000 more U.S. customers — data it had certified as deleted Trezor disclosed on September 5 that another 67,000 U.S. customers are impacted by the breach at shipping provider ShipMonk — names, email addresses, phone numbers, shipping addresses, and order numbers for orders between November 2019 and August 2021 — on top of the 13,689 customers disclosed in August. Trezor said it repeatedly received written assurance that ShipMonk had deleted the data per contract; it had not. ShipMonk notified Trezor on August 10; the intrusion stemmed from exploitation of the Metabase SQL-injection zero-day CVE-2026-72898 (CVSS 10.0), attributed by Holborn to the ShinyHunters extortion gang. Hardware wallets are unaffected, but Trezor warns the leaked data enables phishing, impersonation scams, and physical-security risks. 🔗 Reference: The Hacker News

📌 REVSTEALER: four persistence modules, including a miner that disables Windows Update and Defender Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, a commercial Windows infostealer sold since at least February 2026 that deletes itself after exfiltration: ProManager (wallet-overlay phishing and password logging), WinUpdate (clipboard cryptocurrency-address swapping and recovery-phrase harvesting), SoftManager (turns the machine into a reverse proxy), and LockAppHost, which abuses the CMSTP tool to gain administrator rights, adds Defender exclusions, disables 5 Windows Update services, 11 scheduled update tasks, and 2 malware-removal tasks, then hides a miner inside legitimate Windows processes — with the defensive weakening persisting after the miner is found. REVSTEALER reaches victims through game-cheat lures pushed by at least 17 hijacked YouTube channels, pirated software, and a fake “Claude Opus 5 Free Desktop” application that copied Anthropic branding (Anthropic itself was not compromised). Elastic notes sandbox evasion, indirect system calls, and Polygon smart-contract-based backup C2. 🔗 Reference: The Hacker News


How Can OPSWAT Help

Today’s active threats are largely file-borne. StyleSmuggler implants arrive as binaries planted on store servers, REVSTEALER spreads through fake installers, pirated software, and game-cheat archives, and both abuse trusted upload and download channels. MetaDefender multi-scan layers 30+ anti-malware engines over binaries, archives, and installers so trojanized or backdoored files are caught before they reach servers or endpoints, while MetaDefender Deep CDR (Content Disarm & Reconstruction) strips active content from documents, scripts, and archives crossing email and web upload — reducing the blast radius of file-upload and supply-chain vectors like these.