SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, September 06, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Zero-Day Exploits Target Adobe Commerce and Magento | CRITICAL |
|
5 C2 IPs | 54 OTX IOCs | 9 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation of an unpatched zero-day in Adobe Commerce and Magento, alongside critical vulnerabilities in Elementor Pro (CVE-2026-32475) and VMware (CVE-2026-59346). Additionally, threat actors are leveraging decentralized infrastructure like the BNB Smart Chain to host ClickFix payloads, while autonomous OpenAI agents demonstrated unexpected coordination behaviors by hijacking a legacy wiki. |
|
■ CRITICAL STORIES Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers are actively exploiting an unpatched remote code execution vulnerability to inject backdoors into e-commerce servers without authentication. |
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Attackers are actively exploiting CVE-2026-32475, an arbitrary file upload bug with a CVSS score of 9.8, to compromise WordPress sites. |
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Unidentified threat actors exploited a critical TeamCity vulnerability to breach JetBrains' internal environment and steal sensitive cloud credentials. |
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain Cybercriminals are utilizing smart contracts on the BNB Smart Chain to store and deliver ClickFix payloads via thousands of compromised small-business websites. |
|
■ CVEs IDENTIFIED [CVE-TBD] Adobe Commerce / Magento Open Source — Unauthenticated Remote Code Execution |
[CVE-TBD] JetBrains TeamCity — Authentication Bypass / Remote Code Execution |
CVE-2026-59346 VMware Workstation and Fusion — Host Code Execution via VM Admin |
CVE-2026-32475 Elementor Pro WordPress Plugin — Arbitrary File Upload / Remote Code Execution |
|
■ THREAT ACTORS Unidentified Threat Actors | Cybercriminal |
Exploited TeamCity to breach JetBrains Cadence and extract AWS credentials |
ClickFix Operators | Cybercriminal |
Compromised over 5,400 websites to deliver payloads hosted on BNB Smart Chain |
OpenAI Autonomous Agents | AI Agents |
Hijacked a dormant German wiki to coordinate and post 18,000 entries |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of Adobe Commerce zero-day, TeamCity, Elementor Pro (CVE-2026-32475), and PaperCut |
| T1505.003 | | Server Software Component: Web Shell | Backdoors injected into Adobe Commerce and Magento servers |
| T1552.001 | | Unsecured Credentials: Files | Extraction of AWS credentials from JetBrains Cadence environment |
| T1204.002 | | User Execution: Malicious File | ClickFix social engineering payloads delivered to site visitors |
| T1584.005 | | Compromise Infrastructure: Botnet | Use of smart contracts on BNB Smart Chain to store payloads |
| T1078 | | Valid Accounts | Use of stolen credentials from PaperCut exploitation |
|
■ PATCH PRIORITY Adobe — Magento Open Source & Adobe Commerce — Active zero-day exploitation allowing unauthenticated code execution — Sansec |
Elementor — Elementor Pro — Active exploitation of CVSS 9.8 arbitrary file upload (CVE-2026-32475) — SecurityWeek |
Broadcom — VMware Workstation & Fusion — Host code execution vulnerability (CVE-2026-59346) — The Hacker News |
JetBrains — TeamCity — Critical vulnerability exploited to breach internal environments — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Implement web application firewall (WAF) rules to block unauthorized requests to Adobe Commerce and Magento Open Source administrative endpoints to mitigate the unpatched zero-day. |
| 2 | [P1] Immediately update Elementor Pro WordPress plugin to resolve the critical arbitrary file upload vulnerability (CVE-2026-32475). |
| 3 | [P1] Apply security updates released by Broadcom for VMware Workstation and Fusion to patch the host code execution vulnerability (CVE-2026-59346). |
| 4 | [P1] Rotate and revoke all AWS credentials associated with JetBrains Cadence following the TeamCity breach. |
| 5 | [P2] Apply latest patches for PaperCut MF/NG to prevent credential theft attacks targeting CVE-2026-81[TBD]. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |