Daily Digest

Zero-Days Exploit RMM, E-commerce; Wall Street Targeted by AI Vishing

September 7, 2026
7 articles (6 new, 1 updated)
21 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw: N-able is urging on-premises customers to immediately apply an emergency hotfix for its N-central RMM platform due to a critical, actively exploited zero-day vulnerability (CVE-2026-86218). This pre-authentication RCE allows unauthenticated attackers to gain full control of N-central servers, posing a significant supply chain risk.
  • Unpatched 'StyleSmuggler' RCE Flaw Hits Magento & Adobe Commerce: An unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being actively exploited to compromise e-commerce sites running Magento Open Source and Adobe Commerce. The attack leverages the GraphQL endpoint and template system to inject a backdoor, affecting all current versions.
  • MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit: Attackers are actively exploiting an unauthenticated exploit chain called 'MikroTrick' to gain full administrative control of MikroTik routers with exposed SSH. This attack combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060).

New Threats and Advisories:

  • [UPDATE] Wall Street Giants Targeted in Coordinated AI Vishing Campaign: The vishing campaign, now tracked as PREY-0058, has evolved to include data exfiltration from Microsoft 365 services like SharePoint and OneDrive. Attackers are using residential proxies to evade detection and are using exfiltrated data for extortion.
  • [NEW] Researcher 'Nightmare Eclipse' Drops Three LPE Zero-Day Exploits: A security researcher known as 'Nightmare Eclipse' has publicly released proof-of-concept exploits for three unpatched local privilege escalation (LPE) zero-day vulnerabilities affecting CrowdStrike Falcon Sensor, Avast Antivirus, and Nvidia components.
  • [NEW] North Korea's Lazarus Group Operations Decomposed into Six Clusters: New research reveals that North Korea's state-sponsored cyber operations, attributed to the Lazarus Group, are organized into six distinct clusters. These specialized units focus on missions including espionage, financial theft, and sanctions evasion.

Policy & Industry Notes:

  • CISA Retires Six Free Cybersecurity Assessment Services: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is retiring six of its free, hands-on cybersecurity assessment services for critical infrastructure operators, shifting organizations towards self-service tools.

Filter by Category

New Articles (6)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.