Isometric cyan data pipelines exposing multiple zero-day cyber threats.

Daily Cybersecurity News – September 9, 2026

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-87491

High

What happened

Google released Chrome 153.0.8010.36 (and .37 on Windows/macOS) fixing CVE-2026-87491, an out-of-bounds write in the V8 JavaScript and WebAssembly engine.

Google stated it is aware that an exploit for the flaw exists in the wild. The bug allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. It was reported on August 6, 2026, and is the seventh actively exploited Chrome zero-day patched in 2026.

Chromium rated it Medium severity while the CVSS score is 8.8. Details remain restricted while the fix rolls out.

Who is affected

Users of Google Chrome prior to 153.0.8010.36 on Windows, macOS, and Linux.

This covers the vast majority of desktop Chrome installations worldwide until auto-updates complete.

Why it matters

In-the-wild browser exploits enable drive-by attacks that require only a visit to a malicious or compromised page.

Even sandbox-limited code execution is a common first stage for further chain exploits, and Chrome's massive installed base makes every V8 zero-day high-value for attackers.

How it could have been prevented

Update Chrome immediately to 153.0.8010.36 or later on all platforms and verify the version under chrome://settings/help.

Keep automatic updates enabled and avoid high-risk browsing until the patch reaches the majority of users.

Relevant professional terms

Zero-day
A security flaw that attackers exploit before the vendor has released a fix.
Out-of-bounds write
A memory-safety error in which a program writes data past the end of an allocated buffer, frequently leading to code execution.

Adobe Magento Zero-Day Deploys Rust Backdoor

Critical

Affected product lines

  • Adobe Commerce 2.4.4-2026-aug through 2.4.9-2026-aug and earlier
  • Adobe Commerce B2B 1.3.3-2026-aug through 1.5.3-2026-aug and earlier
  • Magento Open Source 2.4.6-2026-aug through 2.4.9-2026-aug and earlier

What happened

Adobe released hotfixes for CVE-2026-75650 (CVSS 10.0), a maximum-severity improper neutralization flaw in the Magento template engine that enables unauthenticated remote code execution.

Codename StyleSmuggler by Sansec, exploitation began around September 4, 2026. Attackers abuse template processing and dependency injection to generate a crafted "Payment Transaction Failed Reminder" email that triggers code execution.

Observed payloads include a Rust-based Linux backdoor that phones home for instructions and a PHP dropper that installs a web shell. CISA added the CVE to its KEV catalog on September 8, 2026, with a federal remediation deadline of September 11.

Who is affected

Adobe Commerce 2.4.4 through 2.4.9 (2026-aug and earlier), corresponding B2B editions, and Magento Open Source 2.4.6 through 2.4.9 (2026-aug and earlier).

Any internet-facing Magento or Adobe Commerce store that has not applied the VULN-39341 hotfix is exposed. Honeypot telemetry already recorded exploitation attempts from Chinese and Romanian IPs.

Why it matters

A CVSS 10 unauthenticated RCE on a widely used e-commerce platform gives attackers immediate control of payment and customer data stores.

The rapid deployment of both a stealthy Rust backdoor and classic PHP webshells shows opportunistic and targeted actors are already weaponizing the bug, turning online stores into persistent footholds.

How it could have been prevented

Download and apply the VULN-39341 composer patch from repo.magento.com immediately, then rotate all encryption keys as directed by Adobe.

Confirm the patch is active, review server logs and file integrity for webshells or unexpected binaries, and restrict admin and template-related endpoints where possible.

Relevant professional terms

Remote code execution (RCE)
A vulnerability that lets an attacker run their own commands on a target system from across the network.
Template injection
An attack that smuggles malicious code into a server-side template engine so the engine evaluates and executes it during rendering.

WeChat Zero-Click Worm Hijacks Accounts via Calls

High

What happened

Security firm Calif demonstrated a zero-click worm that fully hijacks a WeChat account when an incoming voice call arrives from an existing contact. The target does not need to answer or interact; simply receiving the call is enough.

Once inside, the attacker can read and send messages, place calls, and operate the account as the owner. The researchers showed the worm spreading across three test devices (Android to iOS to Android). Calif reported the issue to Tencent in July 2026.

Tencent mitigated the exploit server-side for all users and shipped client updates (Android 8.0.77, iOS 8.0.76) on 21 August. No real-world attacks using the flaw have been reported.

Who is affected

WeChat and Weixin users on vulnerable client versions (tested against Android 8.0.76 and iOS 8.0.75 and earlier) across iOS and Android.

Tencent reports roughly 1.439 billion monthly active users. Because the caller must already be a contact, the worm relies on an initial compromised account to propagate.

Why it matters

WeChat is far more than chat for many users: it handles payments, official accounts, and mini-programs. Full account takeover therefore exposes financial and identity data without any user action.

A working zero-click worm that chains through the contact graph demonstrates how quickly trust relationships inside a super-app can be turned against its users.

How it could have been prevented

Update WeChat to the latest available version (8.0.77+ on Android, 8.0.76+ on iOS) and keep automatic updates on.

Tencent’s server-side block already stops the demonstrated exploit for everyone, but running a current client remains the safer baseline. Treat unexpected calls from contacts with caution and review recent login or device activity inside the app.

Relevant professional terms

Zero-click attack
An exploit that succeeds without any action or interaction from the victim.
Worm
Self-propagating malware that automatically spreads from one infected system or account to others.

Linux Rootkit Hides Web Shell in F5 BIG-IP APM Memory

High

What happened

Sophos analyzed malware used in compromises of F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell directly into memory rather than writing it to disk.

When Apache loads any of three legitimate APM webtop scripts (apm_css.php3, full_wt.php3, webtop_popup_css.php3), the malware appends the shell to the in-memory copy so disk scans remain clean. An installer binary (observed as umount) first patches /usr/sbin/httpd itself.

The activity is linked to CVE-2025-53521, an unauthenticated RCE (CVSS 9.8) in BIG-IP APM that F5 reclassified in March 2026 and that CISA placed in KEV the same day. F5 tracks the broader malware set as c05d5254.

Who is affected

Organizations running vulnerable BIG-IP APM versions with an access policy on a virtual server: 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10 and earlier unpatched releases.

BIG-IP APM is common in large enterprises for remote access and application delivery, so exposure is concentrated among high-value network infrastructure.

Why it matters

Memory-only web shells defeat standard file-integrity and disk-scanning defenses that most teams still rely on.

Because the initial vector is a critical unauthenticated RCE already known to be exploited, unpatched APM instances remain easy entry points that can yield persistent, hard-to-detect control of authentication gateways.

How it could have been prevented

Apply the F5 patches released in October 2025 (fixed releases 17.5.1.3, 17.1.3, 16.1.6.1, 15.1.10.8 and later) immediately if not already done.

Monitor the three named PHP scripts and httpd for unexpected behavior, inspect process memory and network callbacks, and treat any APM instance that was internet-exposed before patching as potentially compromised.

Relevant professional terms

Web shell
A small malicious script placed on a web server that lets an attacker run commands through ordinary HTTP requests.
Fileless malware
Malicious code that resides primarily in memory or legitimate processes rather than as a persistent file on disk, evading many traditional scanners.

AI Coding Tools Become Prime Target Google Warns

Medium

What to watch

  • Unexpected package publishes or version bumps in AI-related PyPI, npm, and container repositories
  • Suspicious files appearing in hidden AI-assistant workspace directories
  • Token or credential theft from GitHub Actions runners and AI tool process memory
  • Extortion demands that specifically mention proprietary models, prompts, or research data
  • Rapid growth of new MCP servers and agent skills with weak vetting

What happened

Google Threat Intelligence Group (GTIG) reported that the rapid adoption of AI-assisted coding tools has become a primary target for threat actors and has already contributed to large-scale software supply-chain compromises in 2025 and early 2026.

Increased use of LLMs and MCP servers expands the open-source attack surface, while faster development cycles reduce scrutiny of third-party packages. Financially motivated cluster UNC6780 has compromised PyPI, npm, and Docker Hub packages, using its Dustmaker stealer to extract GitHub Actions tokens and drop malicious files into AI assistant workspaces.

GTIG also observed state-sponsored and extortion actors stealing proprietary AI models, prompts, and research from academic, medical, military, and commercial organizations.

Who is affected

Organizations and developers that rely on AI coding assistants, MCP servers, AI-related open-source packages, and CI/CD pipelines that automatically trust those packages.

Targets have included technology, healthcare, pharmaceutical, government, and media sectors in North America and Europe.

Why it matters

AI tooling sits at the center of modern software production. Compromising it gives attackers a force-multiplier that can poison downstream applications used by millions.

Credential theft from AI environments and the sale of those credentials lower the barrier for follow-on attacks, while stolen models and prompts represent both IP loss and potential training-data poisoning risks.

Relevant professional terms

Software supply chain
The collection of third-party code, packages, tools, and services that go into building and running an application.
MCP server
A Model Context Protocol endpoint that exposes tools, data, or skills to AI agents, creating a new class of high-privilege integration point.

Trezor Supply Chain Breach Hits 81,000 Customers

High

What happened

Trezor disclosed that a breach at shipping partner ShipMonk exposed order data for approximately 81,000 customers, a 479 percent increase over the original estimate.

Initial notification covered only May 10 to August 8 2026. The updated scope includes records from November 2019 through August 2021. Stolen fields include names, email addresses, phone numbers, shipping addresses, and order numbers.

Trezor states it had repeatedly received written assurances that older data had been deleted per contract and data-minimization policy, but the data remained in ShipMonk systems.

Who is affected

Roughly 81,000 Trezor hardware-wallet customers whose orders were fulfilled through ShipMonk across the two time windows.

Anyone who purchased a device in those periods and supplied personal shipping details is in the exposed set.

Why it matters

Crypto-wallet owners are already frequent phishing targets. Detailed order and address data enables highly convincing scam emails, phone calls, and even physical letters or visits.

The incident also illustrates classic supply-chain data-retention failure: a vendor kept far more personal information than the customer had authorized or expected.

How it could have been prevented

Treat any unsolicited contact that references a Trezor order, shipping details, or wallet security as suspicious. Never provide seed phrases or recovery information.

Consider using a PO box, parcel locker, or pickup point for future orders to minimize residential address exposure. Monitor accounts for phishing and enable all available device security features.

Relevant professional terms

Supply-chain breach
A security incident that occurs at a vendor or partner and exposes the data or systems of the primary organization and its customers.
Data minimization
The practice of collecting and retaining only the personal data strictly necessary for a stated purpose, then deleting it when no longer needed.

AI-Infra-Guard Open-Source Scanner Targets AI Systems

Low

How it works

  • Fingerprints AI services (Ollama, vLLM, ComfyUI, etc.) and matches versions to 1,600+ CVEs
  • Static and LLM-assisted inspection of MCP servers and agent skills across 14 risk categories
  • Jailbreak testing of target models
  • SkillTrustBench scoring to measure judge-model false-positive rates
  • Hardened prompt isolation in 4.1.9 to treat scanned content as data, not commands

What happened

Tencent’s Zhuque Lab released AI-Infra-Guard, an open-source security scanner purpose-built for AI infrastructure.

It fingerprints running services such as Ollama, vLLM, and ComfyUI and matches them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 risk categories, and performs jailbreak evaluations against target models. Skill analysis asks an LLM whether a skill appears malicious and scores the judgment on the public SkillTrustBench dataset of 5,520 labeled samples.

Release 4.1.9 added structural prompt separation to reduce indirect prompt injection against the scanner’s own agents. The tool is already used by banks, telecoms, and manufacturers including ICBC, China Telecom, Lenovo, and others.

Who is affected

Security and platform teams that operate or evaluate local LLMs, inference servers, MCP servers, and AI agent skills.

The open-source build is intended as a single-operator tool; anyone who deploys it gains a new capability for assessing AI attack surface.

Why it matters

AI systems introduce novel services, protocols, and trust boundaries that traditional vulnerability scanners do not cover well.

A purpose-built open-source checker that combines CVE fingerprinting, skill risk scoring, and jailbreak testing gives defenders a practical starting point before attackers scale the same reconnaissance.

How it could have been prevented

Do not expose the scanner directly to the internet. Place it behind a reverse proxy with authentication (for example nginx basic auth or an IP allowlist) and standard firewall rules, because the open-source build has no built-in login or RBAC and may hold API keys for the models it evaluates.

Relevant professional terms

Jailbreak evaluation
Testing whether a model can be tricked into ignoring its safety instructions and producing disallowed output.
Indirect prompt injection
An attack that hides malicious instructions inside data the model later reads, so the model treats those instructions as authoritative commands.