CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra, and LiteLLM. Researchers found attackers weaponizing the flaws to deploy reverse shells, mint forged admin tokens, and install cryptocurrency miners, with one campaign against a workflow automation tool tied to a broader wave of attacks against AI infrastructure such as LiteLLM gateways and RAGFlow instances used to steal API keys and model provider credentials. Federal agencies have been ordered to patch most of the flaws by September 5, with two additional weeks granted for the Starlette and LiteLLM issues.
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun exploiting a critical authentication bypass flaw in Citrix NetScaler ADC and Gateway appliances after a credible proof-of-concept exploit circulated publicly. A vulnerability intelligence researcher detected requests matching the exploit from sensors in Australia, the United States, and Germany, and Belgium’s national cybersecurity center separately warned of exploitation attempts and urged organizations to patch immediately. More than 22,000 NetScaler ADC appliances and nearly 1,700 Gateway instances remain exposed online, with no clear picture of how many have already been secured.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A zero-day dubbed StyleSmuggler is being used to inject PHP code into Magento’s template system and deploy a stealthy Rust-based backdoor on Adobe Commerce and Magento stores. The two-stage attack triggers a failure report to plant malicious code, then executes it when the platform resends a failed payment notification email, requiring no user interaction. The backdoor disguises its command-and-control traffic as NTP server replies and has already surfaced in two distinct variants since exploitation began, with Adobe’s fix for the flaw still pending as of this week’s Patch Tuesday release.
Health data of more than 9.5 million people leaked from Aesto record system
Healthcare data migration company Aesto disclosed to federal regulators that more than 9.5 million people had sensitive information exposed in a cyberattack traced back to a breach of its Amazon Web Services infrastructure last December. The stolen data includes names, Social Security numbers, medical information, driver’s license numbers, financial account numbers, and health insurance details tied to patients of roughly 30 healthcare organizations that use the company’s record migration and archiving services. No hacking group has claimed responsibility, and the company has not commented beyond its regulatory filings.
Trezor says ShipMonk breach affected another 67,000 customers
Hardware wallet maker Trezor significantly expanded the scope of a data breach at its shipping provider ShipMonk, disclosing that roughly 67,000 additional U.S. customers had names, emails, phone numbers, shipping addresses, and order numbers exposed from orders placed between 2019 and 2021. The company said it had received repeated written assurances from ShipMonk that the older order data had been deleted in line with its retention policy, but the records remained on ShipMonk’s systems. Trezor emphasized that its own systems and hardware wallets were not compromised, while warning affected customers to watch for phishing attempts and physical scam attempts targeting their shipping addresses.