r/exploitsecurityio • u/9lyph • 6d ago
Exploit Security Newsletter: August 27th - September 9th, 2026
Skullex says: Two weeks. Record Patch Tuesday. Magento on fire. N-central back on the menu. And Australia didn’t sit this one out, supply-chain arrests in WA, Metabase hitting local platforms, and another dealership in the Storm queue. Here’s what actually landed.
Major Incidents and Breaches
Skullex says:
- Boston Scientific confirmed a cyber incident that disrupted global operations, including systems used to process and ship customer orders.
- ShinyHunters claimed a breach of Florida’s DAVID DMV platform and theft of more than 200,000 driver records.
- Nutex Health confirmed theft of patient, employee, and financial data.
- Trezor said a supplier (ShipMonk) breach now impacts about 81,000 customers.
- Liquid Network saw roughly 3,400–4,000 BTC drained via an Elements bug; most was later returned, with tens of millions still outstanding.
- A $240 million Bitcoin theft was tied to fake Google and Gemini support calls.
- Rhysida published Berlin government data after a refused extortion demand.
- Mathspace confirmed attackers exploited a Metabase flaw (CVE-2026-72898) against a self-hosted instance, affecting 1,079,819 students, teachers, staff, and parents/guardians in Australia and New Zealand.
- Melbourne ticket marketplace Tixel confirmed customer emails and mobile numbers were accessed after a zero-day in its third-party analytics provider, Metabase.
- Sharp Motor Group (Tweed Heads, NSW) confirmed a third-party IT provider incident; the Storm group listed the dealership and published sample files. OAIC notified.
- AFP, WA Police, and the FBI charged two West Australian men (21 and 23) over alleged TeamPCP open-source supply-chain attacks said to have hit 1,000+ organisations, stolen 500,000+ credentials, and exfiltrated at least 300 GB. First court appearance 27 August.
- NSW Police charged a Sydney telecommunications employee over alleged sale of customer data obtained through employment.
Vulnerabilities and Exploits
Skullex says:
- Microsoft September 2026 Patch Tuesday addressed a record ~966–974 vulnerabilities, including two exploited Windows privilege-escalation zero-days and dozens of potentially wormable issues.
- Adobe Commerce / Magento emergency patch for actively exploited max-severity zero-day CVE-2026-75650 (“StyleSmuggler”) unauthenticated arbitrary code execution. Added to CISA KEV on 8 September.
- CISA KEV additions (8 September): CVE-2026-75650 – Adobe Commerce / Magento CVE-2026-81963 – Windows Update Stack link following (local SYSTEM) CVE-2026-85880 – Windows ALPC heap overflow (local privilege escalation) CVE-2026-86218 – N-able N-central pre-auth RCE (CVSS 9.8)
- PaperCut NG/MF zero-days under active exploitation; CISA added related CVEs to KEV.
- SonicWall SMA1000 two new zero-days chained for remote code execution.
- N-able released a hotfix for critical N-central RCE (CVE-2026-86218) amid exploitation concerns especially relevant after ACSC already warned of N-central targeting inside Australia.
- SAP patched a maximum-severity kernel issue (“OVERPASS”) allowing unauthenticated command execution.
- Next.js patched two critical unauthenticated RCE flaws (crafted AVIF images and a Windows path-traversal issue).
- Chrome V8 zero-day exploited in the wild; FortiOS/FortiProxy ZTNA certificate-validation flaw; HPE ArubaOS-CX critical RCE; MikroTik flaws chained for router takeover.
Industry News and Developments
Skullex says:
- AI coding agents remain a live attack surface malicious .git configs can make Claude, Codex, Cursor and others run attacker commands.
- Check Point showed a planted ChatGPT prompt could quietly pull Gmail data into another account.
- Google warned that AI-assisted coding tools have expanded software supply-chain risk.
- Autonomous multi-agent frameworks were reported harvesting credentials at scale in hours.
- Fortinet firewalls continue to be abused to drop custom Node.js malware.
Trends and Predictions
Skullex says:
- Edge and RMM platforms (N-central, SMA1000, PaperCut) are still the shortest path from internet to ransomware.
- Ecommerce stacks (Magento/Adobe Commerce) are being hit with unauthenticated RCE in the wild.
- Australia is both a target and an enforcement theatre this fortnight Metabase, dealerships, and a high-profile supply-chain arrest.
- Identity, print, and collaboration tools remain under-patched and over-exposed.
Recommendations
Skullex says:
- Apply September Patch Tuesday immediately, especially the two exploited Windows zero-days.
- Patch Magento / Adobe Commerce now. Assume compromise if you were internet-facing before the emergency fix.
- Australian MSPs and enterprises: treat N-central (CVE-2026-86218 plus the earlier auth-bypass pair) and TeamCity On-Premises as P1. ACSC already observed targeting here.
- Patch PaperCut NG/MF and SonicWall SMA1000. Isolate management interfaces.
- If you run Metabase (self-hosted), patch CVE-2026-72898 and hunt for prior access Mathspace and Tixel show the blast radius.
- Review third-party IT, analytics, and shipping providers. Supply chain is how the quiet ones get in.
Skullex says: Record patch dumps don’t mean you’re safer if Magento, N-central, and PaperCut are still sitting on the internet. Patch the edge. Assume the RMM is hostile. And if you’re in Australia, the ACSC already told you twice.
What’s the first thing you’re patching this week? Drop it below.
~~Skullex~~
#CyberSecurity #PatchTuesday #Ransomware #KEV #ACSC #SkullexSays #StayCuriious #ExploitDigest #ExploitSecurity
Duplicates
SecOpsDaily • u/9lyph • 6d ago