Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ed Miliband to set out ‘reset’ of UK relations with Israel over Palestine | Foreign policy

    September 7, 2026

    What we expect from the upcoming Apple launch

    September 7, 2026

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ed Miliband to set out ‘reset’ of UK relations with Israel over Palestine | Foreign policy
    • What we expect from the upcoming Apple launch
    • Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
    • Middle East Crypto Activity Triples to $350 Billion Amid Ongoing Conflict, Report Finds
    • Story about ‘K9 Valor’ surviving suicide bomber, saving 47 soldiers isn’t what it seems
    • Alleged killers of Australian surfers and American friend go on trial in Mexico | Mexico
    • Ireland hails EU tax agreement on carbon imports and electronic waste – POLITICO
    • A Reform UK without Nigel Farage used to be unthinkable. Not any more | Gaby Hinsliff
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.

    The first exploitation incident was recorded on September 4 on a target running the latest security updates.

    E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working on a fix but did not provide a timeline for its release.

    Magento is a popular open-source e-commerce platform by Adobe installed on more than 160,000 websites, including 14,000 of the top 1 million sites.

    Linux backdoor

    The exploit Sansec observed in the wild abuses Magento’s template system through PHP code injection to generate a fake “failed-payment” email, which triggers code execution.

    Successful exploitation installs a small Rust-based backdoor as a background process, disguised as [kworker/u:8:0]. Newer versions disguise the process as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.

    According to Sansec researchers, the attacker also adds a cron job configured to repeat every 30 minutes for persistence.

    Although Sansec did not observe any follow-on activity, the malware can communicate with remote infrastructure and receive commands.

    The researchers note that earlier samples of the backdoor used TLS/WebSockets to communicate with the command-and-control (C2) address, while newer versions disguise their traffic as Network Time Protocol (NTP).

    They send UDP packets to port 123 and use hostnames that resemble time-syncing infrastructure, helping to mask malicious traffic as NTP and get through firewalls.

    The malware also determines the server’s public IP using services including ipify, icanhazip, ident.me, and ipinfo.io, and checks Linux’s TracerPid value to detect tracing. If tracing is active, the malware still installs, but does not beacon.

    Sansec says an unexpected surge of Magento “Payment Transaction Failed Reminder” emails may indicate exploitation, and also recommends monitoring for ‘kworker’ or ‘fc-cache’ processes, suspicious cron entries, and temporary files.

    If there is suspicion of compromise, it is recommended to rotate Magento credentials.

    At the time of writing, Adobe has not released fixes for StyleSmuggler, but the firm’s next scheduled security release is tomorrow, September 8.

    Until fixes are made available, Sansec recommends that website administrators disable GraphQL as a mitigation measure.

    BleepingComputer has contacted Adobe to ask if a fix for StyleSmuggler is planned for rollout tomorrow, but the company has not yet responded.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Backdoor Deploy Exploited Linux Magento StyleSmuggler ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    Mathspace discloses data breach affecting over 1 million people

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    Trezor data breach impact now reaches 81,000 customers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ed Miliband to set out ‘reset’ of UK relations with Israel over Palestine | Foreign policy

    September 7, 2026

    What we expect from the upcoming Apple launch

    September 7, 2026

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    Middle East Crypto Activity Triples to $350 Billion Amid Ongoing Conflict, Report Finds

    September 7, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ed Miliband to set out ‘reset’ of UK relations with Israel over Palestine | Foreign policy

    September 7, 2026

    What we expect from the upcoming Apple launch

    September 7, 2026

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.