Close Menu
AIToday7

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 2026

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 2026

    Magento StyleSmuggler zero

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]
    • 5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB
    • Magento StyleSmuggler zero
    • Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly
    • Your Car’s New AI Assistant Is Very Friendly, Mostly Because It Wants Your Money
    • The Dark Ages’ Limited-Edition Atlan Statue: What You Need to Know
    • Grupo Financiero Inbursa Adopts Harvey Across Its Legal Organization
    • Matt Clifford Steps Down as ARIA Chair After Anthropic Move
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AIToday7
    • Home
    • AI News
    • Tech News
    • AI Guides
    • Chatbots
    • Cybersecurity
    • Gadgets
    • More
      • Generative AI
      • Startups
    AIToday7
    Home»Cybersecurity»Magento StyleSmuggler zero
    Cybersecurity

    Magento StyleSmuggler zero

    aitoday7By aitoday7September 7, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Magento StyleSmuggler zero
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    Bill Toulas

    • September 7, 2026
    • 12:50 PM

    A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.

    The first exploitation incident was recorded on September 4 on a target running the latest security updates.

    E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release.

    Magento is a popular open-websites, including 14,000 of the top 1 million sites

    Linux backdoor

    The exploit Sansec observed in the wild abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email, which triggers code execution.

    Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.

    According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence.

    Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands.

    The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP).

    They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls.

    The malware also determines the server’s public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux’s TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon.

    Sansec says an unexpected surge of Magento “Payment Transaction Failed Reminder” emails may indicate exploitation, and also recommends monitoring for ‘kworker’ or ‘fc-cache’ processes, suspicious cron entries, and temporary files.

    If there is suspicion of compromise, it is recommended to rotate Magento credentials.

    At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm’s next scheduled security release is tomorrow, September 8.

    Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure.

    BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded.

    article image

    Once attackers have valid credentials, only 37% of their actions are blocked

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Post Views: 3

    Magento Security StyleSmuggler zero
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWorking with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly
    Next Article 5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB
    aitoday7
    • Website

    Related Posts

    Cybersecurity

    Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly

    September 7, 2026
    Cybersecurity

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026
    Cybersecurity

    FBI looking into driver’s license data breach possibly linked to New Orleans ID

    September 6, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 20260 Views

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 20260 Views

    Magento StyleSmuggler zero

    September 7, 20260 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Uncategorized

    Architecting memory and storage in the AI era

    aitoday7September 4, 2026
    Uncategorized

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    aitoday7September 4, 2026
    Uncategorized

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    aitoday7September 4, 2026

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 20260 Views

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 20260 Views

    Magento StyleSmuggler zero

    September 7, 20260 Views
    Our Picks

    Architecting memory and storage in the AI era

    September 4, 2026

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    September 4, 2026

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 AIToday7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.