Attacks commenced on September 4, 2026, when a previously unknown Magento and Adobe Commerce zero-day—dubbed StyleSmuggler—began injecting backdoors into online storefronts, according to Sansec.
Google: CVE-2026-85046 — a Chrome V8 zero-day in active use
Google issued security updates addressing 12 vulnerabilities in Chrome, including a high-severity, actively exploited zero-day tracked as CVE-2026-85046 (CVSS 8.8). The flaw is described as a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine: "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," the CVE record says. Researcher Salvatore Gulizia (aka Serotav) reported the bug on August 4, 2026. Google confirmed that "an exploit for CVE-2026-85046 exists in the wild" and has now patched it; this marks the sixth actively exploited Chrome zero-day addressed so far this year.
MikroTik RouterOS and the MikroTrick exploit chain
CERT Polska warned of active exploitation of multiple RouterOS flaws that together form an exploit chain dubbed MikroTrick. The chain relies on CVE-2026-67276 and CVE-2026-86060 (both with CVSS scores of 9.2), and can enable authentication bypass and privilege elevation on devices that allow SSH remote access. The vendor released fixes in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). CERT Polska said successful attacks observed so far—"including the creation of the 'ops' account"—originated from IP address 82.192.72.4 and date back to at least September 2; IP 103.102.31.18 was used in exploitation attempts as well.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMagento and Adobe Commerce: StyleSmuggler backdoors and execution via failed payment emails
Sansec reported that StyleSmuggler allows unauthenticated remote code execution in Magento and Adobe Commerce by abusing the template system’s styles properties to inject PHP. The attack works in two stages: first an injection or "poison" of PHP code—often by generating a failure report—and then letting Magento execute that poisoned code via a failed payment email. The injected backdoor is a Rust program that connects to the command-and-control server at 99.84.67[.]186 and waits for further instructions; two variants have been named fc-cache and chronyd. Sansec also identified a separate cluster that exploits the same weakness to drop a PHP web shell into the product image cache. The attacks began on September 4, 2026, and—per the reporting—there are currently no indications the backdoor has been weaponized beyond installation.
SNMPv3 pre-authentication leakage: an ironic blind spot
New research validated across roughly 470,000 internet-exposed endpoints shows SNMPv3—the protocol commonly marketed as the secure successor for network management—leaks pre-authentication signals that help an unauthenticated actor discover vendor fingerprinting, valid usernames, and likely encryption settings. Kobi Ben‑Naim, Co‑Founder and CEO of Malanta, summarized the problem: "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary. But that answer is incomplete." The practical result: standards-compliant SNMPv3 responses can collapse what should be a multi-dimensional brute-force problem into a far more focused password-guessing exercise when endpoints are internet-exposed.
Supply-chain and social-engineering incidents: Coder, RevStealer, Exodus, Knight Office, and QR phishing
Several incidents this week emphasized attackers’ continued appetite for supply-chain and social-engineering vectors. Coder said an unidentified actor compromised its Cloudflare infrastructure and added unauthorized IPs to its module registry pool, delivering malicious Terraform modules that stole environment variables, API keys, CI/CD credentials, tokens, SSH keys, and Coder database passwords; exfiltration went to the lookalike domain coder-infra[.]com. Coder advised users to check for connections to that domain and upgrade to patched releases (2.37.0, 2.36.4, 2.35.7, and 2.34.9).
Elastic and Morphisec detailed RevStealer (REF2859), a Windows information stealer distributed via game-cheat lures and rogue GitHub repositories for an unauthorized Claude desktop project; the malware uses a Polygon blockchain-based dead drop technique called EtherHiding and targets gaming platforms for monetization. Huntress described a tampered Exodus installer that delivers a modular RAT: a nearly legitimate Exodus wallet where three files differ, one of which stops the wallet UI from drawing a window while another turns a source file into a PE loader that maps a 10 MB payload into memory; the RAT beacons to Azure Table Storage and exposes hidden VNC and SOCKS proxy access. Meanwhile, Huntress and others warned of Knight Office, a new AiTM phishing kit capturing session tokens via multi-redirect Docusign-themed lures, and Kaspersky flagged a QR-phishing technique that renders a scannable QR code built out of text and markup that displays even when inboxes have images turned off.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: prioritize patches for CVE-2026-85046 (Chrome), the MikroTik RouterOS fixes, and the Magento/Adobe Commerce mitigations; retain and review logs because "fully patched" does not prove an environment was not breached.
- Procurement and platform owners: scrutinize upstream registry and CDN configurations after the Coder compromise; verify module sources and monitor for unexpected domain connections such as coder-infra[.]com.
- End users and administrators: beware social-engineering lures that evade typical defenses—text-built QR codes, AiTM pages, and bootleg software installers—and treat unusual device behavior or unexpected service accounts (e.g., an "ops" account on routers) as signs for immediate investigation.
This week's incidents share a theme: trusted channels and upgraded standards still leave practical blind spots. Patching remains essential, but so does collecting the logs and telemetry necessary to detect and investigate attacks that can succeed even when fixes are in place.




