SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, September 08, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Zero-Day Exploitation of N-able and Adobe | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 27 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by critical zero-day exploits and active campaigns targeting remote management tools and e-commerce platforms. Most notably, N-able has rushed out its fourth hotfix in five weeks to patch an actively exploited unauthenticated RCE in N-central, while Adobe Commerce and Magento face active exploitation of the "StyleSmuggler" zero-day to deploy Linux backdoors. Additionally, a worm-like campaign is abusing modified ConnectWise ScreenConnect clients, and the "Nightmare Eclipse" exploit drop targets CrowdStrike, Nvidia, and Avast with local privilege escalation zero-days. |
|
■ CRITICAL STORIES N-able Issues Emergency Hotfix 4 for Actively Exploited N-central RCE N-able has issued its fourth emergency hotfix in five weeks for a maximum-severity unauthenticated remote code execution (RCE) vulnerability in its N-central RMM platform. Because this flaw is reportedly being exploited in the wild, immediate patching to version 2026.3.1.14 or higher is critical for all on-premises deployments. |
"StyleSmuggler" Zero-Day Exploited to Deploy Magento and Adobe Commerce Backdoors Attackers are actively exploiting a zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce. The exploit allows attackers to bypass security boundaries, execute arbitrary code, and deploy a stealthy Linux backdoor on online storefronts to steal sensitive customer and payment data. |
Nightmare Eclipse Campaign Drops Zero-Day Exploits for CrowdStrike, Nvidia, and Avast A sophisticated threat campaign named "Nightmare Eclipse" has released proof-of-concept exploits targeting previously undisclosed zero-day vulnerabilities in CrowdStrike, Nvidia, and Avast products. The exploits achieve local privilege escalation, spawning command shells with SYSTEM-level privileges on compromised endpoints. |
Modified ScreenConnect Clients Abused in Worm-Like VBScript Campaign Security researchers have observed a worm-like campaign abusing ConnectWise ScreenConnect. Attackers are using backdoored or modified ScreenConnect clients to automatically transfer and execute a four-stage malicious VBScript payload onto newly connected hosts, highlighting the risk of trusted remote access tools being weaponized. |
|
■ CVEs IDENTIFIED [CVE-TBD] N-able N-central — Unauthenticated Remote Code Execution |
[CVE-TBD] Adobe Commerce and Magento — StyleSmuggler Zero-Day Remote Code Execution and Backdoor Deployment |
[CVE-TBD] CrowdStrike, Nvidia, Avast — Nightmare Eclipse Privilege Escalation to SYSTEM |
[CVE-TBD] ConnectWise ScreenConnect — Unpatched Remote Access Vulnerability |
|
■ THREAT ACTORS North Korean Hackers | State-sponsored |
Deploying a stealthy Linux espionage toolkit that embeds a backdoor in HAProxy targeting automotive and media organizations. |
Rhysida | Cybercrime / Ransomware |
Linked to a new data leak publishing stolen login credentials from Berlin's government. |
BigBear | Cybercrime / PhaaS |
Operating the BigBear 2.0 phishing-as-a-service framework to bypass MFA and steal Microsoft 365 credentials. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to exploit Adobe Commerce "StyleSmuggler", N-able N-central, and Telerik UI vulnerabilities. |
| T1068 | | Exploitation for Privilege Escalation | Seen in the "Nightmare Eclipse" zero-day exploits targeting CrowdStrike, Nvidia, and Avast. |
| T1219 | | Remote Access Software | Modified ScreenConnect clients used to drop and execute payloads on newly connected hosts. |
| T1566.002 | | Phishing: Spearphishing Link | BigBear 2.0 MFA-bypass phishing and text-based QR code phishing. |
| T1539 | | Steal Web Session Cookie | JSCeal malware bypassing Google authentication using stolen session cookies. |
| T1176 | | Browser Extensions | PEEP post-compromise toolkit masquerading as a bookmarks extension to execute host commands. |
|
■ PATCH PRIORITY N-able — N-central RCE flaw under active exploitation — THN |
Adobe — Commerce / Magento "StyleSmuggler" zero-day exploited in the wild — BC |
CrowdStrike — "Nightmare Eclipse" privilege escalation zero-day — SW |
Nvidia — "Nightmare Eclipse" privilege escalation zero-day — SW |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply N-able N-central Hotfix 4 immediately to all on-premises servers below version 2026.3.1.14 to mitigate active unauthenticated RCE exploitation ([CVE-TBD]). |
| 2 | [P1] Deploy security patches or server-side mitigations to Adobe Commerce and Magento installations to block the "StyleSmuggler" zero-day exploit ([CVE-TBD]). |
| 3 | [P1] Implement the temporary mitigation measures provided by ConnectWise for the unpatched ScreenConnect Remote Access vulnerability ([CVE-TBD]). |
| 4 | [P2] Restrict external SSH access to MikroTik RouterOS devices to prevent exploitation of the active router hijacking vulnerability chain ([CVE-TBD]). |
| 5 | [P2] Audit enterprise endpoints for unauthorized browser extensions to detect and remove the PEEP post-compromise toolkit. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |