InfoSec News Nuggets – 09/08/2026
Adobe Fixes Critical Magento Zero-Day Exploited to Backdoor Servers
Adobe released an emergency out-of-cycle patch for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Magento Open Source and Adobe Commerce, after e-commerce security firm Sansec discovered attackers exploiting it since September 4 to plant backdoors on vulnerable stores. The flaw abuses Magento’s template-processing system to inject and execute malicious PHP code, and Sansec confirmed the technique compromised at least one store that was fully current on every prior security update — meaning normal patching discipline alone wasn’t enough to prevent infection. The backdoor disguises its command-and-control traffic as a standard NTP server but leaves detectable traces such as suspicious “Payment Transaction Failed Reminder” emails; with over 111,000 active Magento stores in operation, merchants who ran unpatched between September 4 and 7 need to actively hunt for compromise rather than assume the patch alone resolves the exposure.
N-able Patches Critical N-central Zero-Day Exploited in the Wild (CVE-2026-86218)
N-able shipped an emergency hotfix for CVE-2026-86218, a maximum-severity pre-authentication remote code execution flaw in its N-central remote monitoring and management platform, marking the third distinct N-central vulnerability disclosure in six weeks. The company’s public release notes stated it had no confirmation of exploitation in production environments, but a separate internal customer notice — contradicting that public stance — described the flaw as being actively exploited in the wild across hosted and on-premises deployments in the Americas, APAC, and Europe. Cybersecurity firm Huntress, which had already been investigating a customer compromise tied to two earlier N-central flaws, said rotated server logs prevented it from confirming which specific vulnerability the attacker actually used — administrators running any N-central version prior to Hotfix 4 should upgrade immediately regardless of which prior patches they’ve already applied.
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
A security researcher known as Chaotic Eclipse published a proof-of-concept exploit called FalconFlank targeting CrowdStrike’s Falcon endpoint security platform, the latest in a rapid string of uncoordinated zero-day disclosures from the same researcher following earlier exploits against Microsoft Defender, Kaspersky, and Avast. The flaw abuses Falcon’s built-in remediation feature for malicious Microsoft Office macros to escalate from limited local access to full SYSTEM privileges, working even on fully patched Windows 11 25H2 and Windows Server 2025 systems. CrowdStrike said customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings and pointed to a technical alert in its support portal, though no CVE has been assigned and the underlying root cause remains undocumented — researchers note the exploit is detectable through standard endpoint telemetry since it keys on the abused mechanism rather than any specific file hash or payload.
OpenAI Says Astra Is Its First Model to Cross ‘Critical’ Cybersecurity Threshold
OpenAI launched GPT-6 Astra, disclosing that it is the first model the company has classified as reaching the “Critical” cybersecurity capability level under its Preparedness Framework, meaning it can independently discover previously unknown vulnerabilities and develop working exploits against well-protected systems without step-by-step human guidance. In pre-release testing, Astra scored a perfect 100% on ExploitBench — up from 78.5% for its predecessor GPT-5.6 Sol — and discovered two genuinely unknown zero-day vulnerabilities when tested against software patched only in the three months before launch, ruling out the possibility it was simply recalling exploits from its training data. OpenAI said the classification triggered significantly strengthened safeguards during both training and deployment, and access to Astra’s advanced cybersecurity capabilities will initially be limited to a small set of vetted organizations through its Daybreak program rather than broadly available at launch.
Trezor Customers Hit With Phishing Calls and Letters After Shipping-Partner Breach
Hardware wallet maker Trezor disclosed that a breach at its shipping and fulfillment partner ShipMonk is far larger than originally reported, after learning that roughly 67,000 additional U.S. customers’ order data — which ShipMonk had repeatedly certified as deleted per its contract — remained in the compromised systems, bringing the total affected count to approximately 80,700 people. The breach traces to a zero-day SQL injection vulnerability in ShipMonk’s Metabase analytics platform, attributed to the ShinyHunters extortion group, which was used to create administrator-level sessions and bulk-download customer data tables including names, emails, phone numbers, and shipping addresses. Trezor’s own wallet security, private keys, and firmware were not affected, but the company is warning customers of heightened phishing, impersonation, and physical security risk, since the combination of home addresses and confirmed hardware-wallet ownership gives attackers a highly specific profile for targeted social engineering or in-person threats.