SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, September 09, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Microsoft Patches Record 974 Flaws, Two Zero-Days | CRITICAL |
|
5 C2 IPs | 83 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR Today's intelligence landscape is dominated by Microsoft's record-breaking September 2026 Patch Tuesday addressing over 970 vulnerabilities, including two actively exploited privilege-escalation zero-days. Concurrently, Adobe has patched a maximum-severity CVSS 10.0 zero-day (CVE-2026-75650) in Adobe Commerce and Magento that is actively exploited to deploy Rust backdoors. Additionally, critical infrastructure and networking devices face severe threats, with active exploitation of F5 BIG-IP APM devices to deploy fileless memory-resident Linux rootkits and a critical "MikroTrick" vulnerability chain allowing passwordless takeover of MikroTik routers. |
|
■ CRITICAL STORIES Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor Tracked as CVE-2026-75650, this maximum-severity CVSS 10.0 vulnerability allows unauthenticated attackers to execute arbitrary code and is actively being exploited in the wild to drop Rust-based backdoors and PHP web shells on e-commerce sites. |
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Threat actors are compromising F5 BIG-IP APM environments to deploy a sophisticated Linux rootkit that intercepts PHP file loading and injects a fileless web shell directly into memory, evading traditional disk-based security controls. |
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited Microsoft released its largest security update ever, patching 973+ vulnerabilities including 113 critical bugs and two actively exploited privilege-escalation zero-days, placing an unprecedented patch-management burden on enterprise IT teams. |
MikroTik Patches Critical Flaws Chained to Hack Routers Dubbed 'MikroTrick', these vulnerabilities allow unauthenticated attackers to bypass authentication, overwrite configuration files, and take full control of RouterOS devices with SSH exposed to the internet. |
|
■ CVEs IDENTIFIED CVE-2026-75650 Adobe Commerce and Magento Open Source — Unauthenticated arbitrary code execution exploited in the wild to deploy backdoors and web shells. |
[CVE-TBD] Microsoft Windows — Two actively exploited privilege-escalation zero-day vulnerabilities patched in September 2026. |
[CVE-TBD] F5 BIG-IP APM — Vulnerability allowing unauthenticated attackers to breach devices and deploy a memory-resident Linux rootkit. |
[CVE-TBD] SAP Kernel — Extended Passport Processing vulnerability allowing unauthenticated remote command execution and secret recovery. |
|
■ THREAT ACTORS Slim Spider | Financially Motivated Threat Actor |
Targeting Brazilian financial institutions since March 2026 to steal cryptocurrency custody secrets. |
DoppelCart | Cybercrime Group |
Operating a massive fraud network of over 119,000 fake e-shops to harvest and steal credit card details. |
ShinyHunters | Extortion Gang |
Claimed a breach of the Florida DMV "DAVID" database, allegedly exfiltrating over 200,000 driver records. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of Adobe Commerce (CVE-2026-75650), F5 BIG-IP APM, and SAP Kernel vulnerabilities. |
| T1068 | | Exploitation for Privilege Escalation | Exploitation of two Windows zero-days and the FreeIPA anonymous admin credential flaw chain. |
| T1014 | | Rootkit | Linux rootkit deployed on compromised F5 BIG-IP APM devices. |
| T1027.002 | | Software Packing | Injection of fileless web shells directly into memory to avoid disk-based detection. |
| T1566 | | Phishing | Use of credential harvesting frameworks and fake e-shop domains by DoppelCart to steal sensitive data. |
| T1203 | | Exploitation for Client Execution | WeChat zero-click incoming call exploit triggering remote code execution on mobile devices. |
|
■ PATCH PRIORITY CRITICAL | Adobe Commerce and Magento Open Source — CVE-2026-75650 CVSS 10.0 zero-day is actively exploited to deploy Rust backdoors — SecurityWeek |
CRITICAL | Microsoft Windows 10 & 11 — Two actively exploited privilege-escalation zero-days patched in record-breaking release — Recorded Future |
CRITICAL | F5 BIG-IP APM — Active exploitation deploying fileless web shells and memory-resident Linux rootkits — BleepingComputer |
CRITICAL | MikroTik RouterOS — "MikroTrick" vulnerability chain allows full device takeover without a password via exposed SSH — SecurityWeek |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch CVE-2026-75650 on all Adobe Commerce and Magento Open Source installations to prevent unauthenticated remote code execution and Rust backdoor deployment. |
| 2 | [P1] Deploy Microsoft September 2026 Patch Tuesday cumulative updates (KB5122878 for Windows 10; KB5124008 and KB5122880 for Windows 11) to mitigate two actively exploited privilege-escalation zero-days. |
| 3 | [P1] Audit and apply security updates to all F5 BIG-IP APM devices to defend against active memory-resident Linux rootkit and web shell injections. |
| 4 | [P1] Apply MikroTik RouterOS patches to resolve the "MikroTrick" vulnerability chain, and immediately restrict or disable SSH access exposed to the public internet. |
| 5 | [P2] Apply SAP Kernel security patches to mitigate the critical Extended Passport Processing vulnerability. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |