~/greenteam/nerd

Tuesday, September 8, 2026

Daily digest

Multiple stories today converge on Microsoft 365 as the primary attack surface — help-desk vishing against executives, a phishing-as-a-service kit that bypassed MFA at 258 organizations, and a critical Magento zero-day already being weaponized. Worth a fresh look at conditional access and help-desk verification procedures this week.

cybersec The Hacker News

Adobe Patches Critical Magento Zero-Day Actively Exploited to Deploy Backdoors

Adobe released emergency patches for CVE-2026-75650 (CVSS 10.0), a maximum-severity flaw in Adobe Commerce and Magento Open Source dubbed 'StyleSmuggler.' Sansec discovered active exploitation starting September 4, with attackers deploying a Rust-based backdoor and PHP web shell on compromised e-commerce sites.

Why it matters: If any org-run or third-party e-commerce storefront touches Magento/Adobe Commerce, patch immediately — active exploitation predates the patch by several days.

cybersec The Hacker News

FreeIPA Flaw Chain Lets Anonymous Clients Create Admin Credentials

Red Hat disclosed a flaw chain in FreeIPA that allows an unauthenticated client to create an arbitrary Kerberos identity and land it in the administrators group, provided a companion flaw in the underlying 389 Directory Server is also present. FreeIPA manages identity and login across Linux domains via LDAP.

Why it matters: Any Linux systems in the environment using FreeIPA/IdM for centralized authentication should be inventoried and patched — full domain admin from an unauthenticated client is a severe 800-171 access-control failure.

cybersec The Hacker News

Fake IT Help Desk Calls Target Executives in Microsoft 365 Extortion Campaign

A threat cluster is targeting directors, VPs, and executives with vishing calls impersonating IT help desks, combined with adversary-in-the-middle token theft and residential-proxy sign-ins to steal Microsoft 365 and other SaaS data for extortion. The campaign specifically singles out high-privilege executive accounts.

Why it matters: In a GCC High tenant, executive accounts often carry the broadest privilege sets — verify help-desk identity-proofing procedures and consider phishing-resistant MFA (FIDO2) for privileged users to close the AitM token-theft path.

cybersec BleepingComputer

BigBear Phishing Service Bypassed MFA at 258 Organizations

A phishing-as-a-service platform called BigBear 2.0 has been used to bypass multi-factor authentication and steal more than 5,000 Microsoft 365 credentials across 258 organizations. The kit uses reverse-proxy techniques to capture live session tokens rather than just credentials.

Why it matters: Standard MFA (push/OTP) is not sufficient against this AitM-style toolkit; token-theft-resistant methods (FIDO2/Windows Hello for Business, Conditional Access sign-in risk policies) are the mitigation to prioritize in GCC High.

cybersec The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE

N-able released a fourth hotfix in five weeks for its N-central RMM platform, addressing an unauthenticated remote code execution flaw affecting all on-premises builds below 2026.3.1.14 — including systems already updated to Hotfix 3. N-able's incident notice states the flaw has been exploited in the wild, though release notes call that unconfirmed.

Why it matters: If N-central is used for endpoint management, apply Hotfix 4 immediately regardless of prior patch level — RMM platforms are high-value targets for lateral movement across managed fleets.

cybersec BleepingComputer

ConnectWise Warns of New Unpatched ScreenConnect Flaw

ConnectWise disclosed a new vulnerability in its ScreenConnect Remote Access product and issued temporary mitigation guidance, with a patch planned later this week. No CVE details or exploitation status were confirmed at time of disclosure.

Why it matters: ScreenConnect is a common RMM tool for MSPs and IT teams; apply the interim mitigations now and watch for the patch — unpatched remote-access tools are a recurring initial-access vector.

cybersec BleepingComputer

Hackers Exploit New MikroTik RouterOS Flaws to Hijack Routers

Attackers are actively exploiting a chain of two recently disclosed vulnerabilities in MikroTik RouterOS to take control of devices with SSH services exposed to the internet. The campaign targets internet-facing routers directly rather than requiring user interaction.

Why it matters: Confirm no MikroTik devices have SSH exposed to the internet; restrict management interfaces to internal networks or VPN per standard 800-171 boundary protection requirements.

cybersec The Hacker News

PEEP Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors

Researchers disclosed a Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension. It requires prior admin or code-execution access, injecting itself directly into Chrome/Edge profiles by forging Secure Preferences to bypass Web Store checks and user prompts.

Why it matters: On an Intune-managed Windows 11 fleet, ensure browser extension allowlisting and Secure Preferences integrity are enforced via policy — this technique specifically evades standard extension vetting controls.

infrastructure BleepingComputer

Microsoft Warns Windows Server 2025 Memory Changes Causing App Crashes

Microsoft confirmed that recent memory management changes in Windows Server 2025 are causing application crashes on some systems. The company acknowledged the issue last week but has not yet detailed a full fix timeline.

Why it matters: If Windows Server 2025 is deployed or planned in the AHV environment, hold on updates and test application compatibility before wider rollout.

infrastructure The Register

Extortion Crews Increasingly Targeting High-Value AI Data, Google Warns

Google's threat intelligence team reports that extortion groups are shifting focus to stealing proprietary AI models, training data, and datasets rather than just encrypting systems, betting that companies will pay to keep their AI intellectual property from being exposed.

Why it matters: Any self-hosted AI stack with proprietary models, fine-tuning data, or CUI-adjacent training data should be treated as a high-value target and segmented/monitored accordingly, not just as a convenience tool.

cmmc FedScoop

Report: Government Needs Vertical AI Rigor at Horizontal Scale

FedScoop commentary argues federal agencies need secure, mission-specific AI systems capable of operating across real-world government operations, rather than remaining stuck in pilot programs, to move federal AI adoption forward.

Why it matters: Signals continued federal push toward mission-specific, secure AI deployment models — relevant context for how self-hosted AI tooling may need to align with future agency compliance expectations.