Welcome to Issue #34 of the CosmicBytez Labs Weekly Digest — your curated rundown of what mattered in cybersecurity this week.
E-commerce infrastructure took the hardest hit. A maximum-severity zero-day in Magento and Adobe Commerce, now nicknamed "StyleSmuggler" (CVE-2026-75650), has been under active exploitation since September 4 — attackers smuggle poisoned templates into failed-payment emails to get unauthenticated RCE and plant Linux backdoors on live stores. Adobe rushed out an emergency patch this week, but Sansec's original find means a growing window of already-compromised storefronts predates the fix.
Edge and CI/CD infrastructure weren't spared either. Sophos uncovered a stealthy Linux rootkit — dubbed "Poisoned Refresh" — hooking PHP directly in memory on breached F5 BIG-IP APM devices to run fileless web shells that never touch disk. Separately, JetBrains confirmed its Cadence cloud service was breached through an unpatched, KEV-listed TeamCity RCE, exposing AWS IAM credentials and a 2024 server backup — another reminder that "already on CISA's list" doesn't mean "already patched everywhere."
Hardware and network gear also had a rough week. Trezor now says the ShipMonk fulfillment breach — traced to a Metabase SQL injection zero-day — affects 81,000 customers, up sharply from the 14,000 first disclosed. And CERT Polska is warning that attackers are hijacking internet-exposed MikroTik RouterOS devices over SSH with no authentication required at all, gaining full admin control outright.
The throughline: this week's damage came less from novel techniques and more from exposed surface — payment templates, management interfaces, fulfillment vendors, and routers left reachable from the open internet.
Top Stories
Adobe Rushes Emergency Fix as Magento "StyleSmuggler" Zero-Day Backdoors Servers
A maximum-severity template injection flaw in Adobe Commerce and Magento (CVE-2026-75650), tracked as "StyleSmuggler," has been actively exploited since September 4 to plant Linux backdoors on live stores via poisoned templates rendered in failed-payment emails — no authentication required. Adobe shipped an emergency patch this week covering Adobe Commerce and Magento 2.4.4–2.4.9, but Sansec's original disclosure means any unpatched store has had days of exposure to unauthenticated RCE.
What to do: Patch immediately, then assume compromise on any instance that was internet-facing before the fix — audit for planted templates, unfamiliar admin accounts, and outbound connections from checkout/payment code paths.
"Poisoned Refresh" Rootkit Injects Fileless PHP Web Shells on Breached F5 BIG-IP Devices
Sophos found a stealthy Linux rootkit hooking PHP on breached F5 BIG-IP APM servers to inject memory-only web shells — leaving disk files untouched and standard file-integrity checks blind to the implant. It's a notable escalation in how attackers are treating network-edge appliances: not just an entry point, but a platform worth investing in persistence tooling for.
What to do: Don't rely on disk-based file-integrity monitoring alone for BIG-IP APM devices — check for anomalous PHP process behavior and memory artifacts, and confirm your instances are fully patched and not internet-exposed unnecessarily.
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains confirmed its Cadence cloud service was breached via an unpatched, KEV-listed TeamCity RCE, exposing AWS IAM credentials and a 2024 server backup. The bug being both known and already on CISA's Known Exploited Vulnerabilities list makes this less a novel-exploit story and more a patch-cadence story — the flaw was public and weaponized well before it hit JetBrains' own infrastructure.
What to do: Cross-check your TeamCity (and broader CI/CD estate) against the KEV catalog specifically, not just your general patch backlog, and rotate any AWS credentials that touched an exposed build server.
Trezor Data Breach Impact Now Reaches 81,000 Customers
Trezor says the fulfillment-partner breach at ShipMonk — traced to a Metabase SQL injection zero-day — now affects 81,000 customers, up from the 14,000 originally disclosed. Hardware wallet customers are a particularly high-value target list, since a shipping-address leak paired with a known Trezor purchase is a ready-made phishing and physical-targeting lead.
What to do: If you're a Trezor customer, treat any unexpected "replacement device" or support outreach as suspicious, and never enter a recovery seed into anything but your physical device.
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska is warning of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices over SSH — with no authentication needed at all. Given how widely MikroTik gear is deployed at the network edge for SMBs and ISPs alike, an unauthenticated path to full admin is about as high-leverage as router bugs get.
What to do: Pull SSH management off the public internet immediately (VPN or allowlist only), and check for unfamiliar admin users, firewall rule changes, or scheduler scripts on any exposed device.
Security Corner
Notable advisories published this week:
-
CVE-2026-75650 — Critical. Adobe Commerce & Magento "StyleSmuggler" template injection — unauthenticated RCE, directly tied to this week's top story above.
-
CVE-2026-18922 — Critical. 389 Directory Server SASL auth flaw — a stale identity from a failed bind can be inherited by a later successful bind, letting attackers seize Directory Manager rights on Red Hat Directory Server 11.
-
CVE-2026-79697 — Critical (CVSS 9.9). Advantech WISE-6610 industrial gateways — unauthenticated command injection with a public exploit, across the full WISE-6610/EL/P firmware line.
-
CVE-2026-81963 — High. Windows Update Stack link-following flaw added to CISA's KEV catalog as actively exploited; federal agencies have until September 22 to patch.
-
SourceCodester's SQLi backlog keeps growing — five more unauthenticated SQL injection flaws landed this week across its Online Voting System and Class/Exam Timetabling System: CVE-2026-86159 and CVE-2026-86290 (voting), plus CVE-2026-86208, CVE-2026-86209, and CVE-2026-86224 (timetabling) — all pre-auth, several with public exploit code. If you're running SourceCodester products, assume more are coming.
Browse the full Security Advisories archive for all active CVEs.
Quick Takes
-
Scammer behind $245M crypto heist pleads guilty — Malone Lam, ringleader of a social-engineering theft ring, pleaded guilty to racketeering conspiracy over the Bitcoin heist (read more).
-
JSCeal malware hijacks Google sessions — A heavily obfuscated V8 JavaScript malware steals browser session cookies to replay Google logins and drain crypto accounts (read more).
-
N-able patches max-severity N-central RCE amid live attacks — CVE-2026-86218, a 10.0 pre-auth RCE, got a rushed Hotfix 4 after Huntress flagged signs of related exploitation (read more).
-
Telerik UI padding-oracle chained to unauthenticated RCE — Researchers turned an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into a public unauthenticated RCE exploit chain (read more).
-
Elementor Pro file-upload bug under heavy fire — CVE-2026-32475 is being actively exploited against WordPress sites, with over 190,000 attack attempts already blocked (read more).
-
VMware Workstation and Fusion VM-escape flaw patched — A critical VMXNET3 integer-overflow bug (CVSS 9.3) let a VM's local admin break out to run code on the host (read more).
-
ClickFix payloads now hide on the blockchain — Over 5,400 hacked WordPress and PrestaShop sites are serving ClickFix stagers stashed in BNB Smart Chain contracts for takedown-resistant C2 (read more).
-
220 million traveler records exposed in Vietnam-linked leak — An exposed Advance Passenger Information System database held passport and flight records spanning 2017–2026 (read more).
-
Grindr to pay £26M over HIV data sharing — A UK High Court settlement covers 12,000 users whose HIV status and PrEP data was allegedly shared with advertisers pre-2020 (read more).
-
Chainguard doubles rebuild output to 1 billion manifests — A new agentic pipeline pushed the container-image factory from 500 million to over 1 billion build manifests in six months (read more).
Catch up on everything else in this week's full recap.
Upcoming
Next issue (Issue #35): Watch for Adobe's patch adoption numbers on StyleSmuggler and whether the pre-fix compromise window produces a wave of follow-on Magento breach disclosures. We're also tracking whether the F5 BIG-IP "Poisoned Refresh" rootkit shows up on other appliance families now that memory-only persistence has a documented playbook.
On the Labs: Fresh advisories are landing daily in the Security archive, and the howto library continues to grow with practical hardening guides — this week's headlines make a strong case for auditing every internet-facing management interface (SSH, admin panels, CI/CD) on your network.
Stay sharp. When a fileless rootkit and a stale-identity auth bypass both surface in the same week, the common defense isn't a single patch — it's knowing what's actually reachable from the internet before an attacker's scan finds it first.
Issue #34 — September 8, 2026. Published weekly by CosmicBytez Labs. To receive this digest by email, subscribe here.