Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (8 September 2026)
Published: Loading…
At a Glance
- ConnectWise ScreenConnect clients were abused in worm-like attacks distributing a four-stage VBScript payload to newly connected hosts.
- The StyleSmuggler zero-day is being actively exploited to deploy backdoors on Magento and Adobe Commerce stores, with no patch yet.
- BigBear 2.0, an Evilginx2-based phishing-as-a-service platform, bypassed MFA at 258 organizations and stole over 5,000 Microsoft 365 credentials.
- Hackers exploited chained MikroTik RouterOS vulnerabilities, dubbed MikroTrick, to hijack devices with internet-exposed SSH.
- Rhysida published Berlin government data after the city refused a €2 million extortion demand.
- N-able released its fourth hotfix in five weeks for N-central, patching CVE-2026-86218, an unauthenticated pre-auth RCE flaw.
Editorial Analysis
N-able's fourth hotfix in five weeks for N-central illustrates a different failure mode from the single-bypass pattern seen with PaperCut on 29 August. Hotfix 3 was itself superseded a day later, meaning some customers patched into a still-vulnerable build before Hotfix 4 arrived, while N-able's own incident notice and release notes disagree on whether CVE-2026-86218 has actually been exploited in the wild. For an RMM platform used to manage client networks at scale, repeated emergency releases within a single month leave MSPs having to deploy successive fixes before they have had much opportunity to verify that each one is complete.
Elsewhere, several unrelated disclosures involved attackers building persistence or propagation into infrastructure rather than relying on a standalone payload. ScreenConnect campaign used backdoored clients to automatically push a VBScript chain to newly connected sessions, turning each compromised host into a distribution point without further attacker involvement. BigBear 2.0 panel achieved a similar effect through a service model, leasing AiTM infrastructure to affiliates who could independently target new Microsoft 365 accounts. A PHP rootkit took a different route, hooking Apache's module loader so the implant persists inside process memory across requests without any file needing to change on disk. In each case, legitimate infrastructure becomes part of how the attacker maintains access or extends the campaign.
Highlights of the Day
N-able Patches Critical Pre-Auth RCE Flaw in N-central
N-able released Hotfix 4 for N-central 2026.3, addressing CVE-2026-86218, a critical vulnerability enabling pre-authenticated remote code execution on the N-central server. A third party disclosed the flaw through N-able's security disclosure programme, and no in-the-wild exploitation has been confirmed. Hosted N-central customers are already protected, while self-hosted deployments require an upgrade to build 2026.3.1.14.
Rogue ScreenConnect Clients Spread Worm-Like Malware Chain
Huntress identified rogue ScreenConnect installations across unrelated organisations, deployed via social engineering and Quick Assist scams, that launched a four-stage VBScript payload chain. The malware profiled hosts, evaded security tools, and used modified ScreenConnect clients to automatically push the same scripts to newly connected sessions, creating worm-like propagation. Payloads included backdoors, privilege escalation tools, a cryptocurrency miner, and tunnelling utilities, while ConnectWise separately disclosed a related file-transfer vulnerability.
Unpatched Magento Flaw Under Active Exploitation Since September
A zero-day dubbed StyleSmuggler enables unauthenticated remote code execution against all current versions of Magento Open Source and Adobe Commerce. Sansec confirmed active exploitation from 4 September, a day before public disclosure, while Adobe has yet to issue a CVE, advisory, or patch. Attackers inject PHP through GraphQL style properties, with the payload executing later during automated email template rendering, and confirmed intrusions have installed a persistent Rust-based backdoor.
Researchers Expose Global Microsoft 365 Phishing-as-a-Service Panel
CloudSEK gained admin access to BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 accounts across over 40 countries. The panel managed 42 VPS nodes and exfiltrated over 5,000 credential records, including 474 sessions with complete MFA bypass and thousands of session cookies, via adversary-in-the-middle proxying and geo-matched residential proxies. Custom JavaScript injections disabled FIDO2/WebAuthn authentication, and the infrastructure was leased to at least five affiliate operators via Telegram bots.
Fileless Linux Rootkit Hides Web Shell Inside PHP Memory
Sophos analysed a Linux implant, linked to BIG-IP APM systems affected by CVE-2025-53521, that injects a web shell directly into memory rather than writing files to disk. The malware hooks Apache and PHP functions to intercept specific script files, prepending malicious code only when they are memory-mapped, leaving on-disk files unchanged. It also opens a hidden UNIX socket backdoor granting interactive shell access without a network listener, and ESET has separately tracked the same malware as "PoisonedRefresh".
Daily Coverage