Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026

    Trezor data breach impact now reaches 81,000 customers

    September 7, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
    News

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    adminBy adminSeptember 7, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.

    The first exploitation incident was recorded on September 4 on a target running the latest security updates.

    E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release.

    Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites.

    Linux backdoor

    The exploit Sansec observed in the wild abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email, which triggers code execution.

    Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.

    According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence.

    Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands.

    The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP).

    They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls.

    The malware also determines the server’s public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux’s TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon.

    Sansec says an unexpected surge of Magento “Payment Transaction Failed Reminder” emails may indicate exploitation, and also recommends monitoring for ‘kworker’ or ‘fc-cache’ processes, suspicious cron entries, and temporary files.

    If there is suspicion of compromise, it is recommended to rotate Magento credentials.

    At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm’s next scheduled security release is tomorrow, September 8.

    Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure.

    BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWe Are Going to Be Okay: A Three Year Anniversary Events Recap
    admin
    • Website

    Related Posts

    News

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026
    News

    Trezor data breach impact now reaches 81,000 customers

    September 7, 2026
    News

    Mathspace discloses data breach affecting over 1 million people

    September 7, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026

    Trezor data breach impact now reaches 81,000 customers

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.