Search/North Korean WaterPlum hackers infected 30,000 devices worldwide
Story

North Korean WaterPlum hackers infected 30,000 devices worldwide

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds. The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency…

CVEs
0
Highest CVSS
In KEV
0
Sources
3
Connections
12 relationships
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds. The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets. The primary targets of the campaign are web designers, engineers and cryptocurrency specialists. Friday’s advisory said the WaterPlum scheme is specifically victimizing IT professionals in Japan and other countries. Job seekers are contacted through social media platforms, gig work websites and freelance portals. Applicants are instructed to download files during the interview process, allowing the hackers to infect devices and steal cryptocurrency wallet credentials alongside other information. Japanese police found variants of the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware strains on victim devices. WaterPlum actors typically installed infostealers and remote management tools to maintain their access to victim devices. Other North Korean hackers were seen using identity documents stolen from victims to obtain employment elsewhere. In April, incident responders uncovered a similar campaign involving the same strains of malware where hackers stole up to $12 million in cryptocurrency through malware attacks on personal devices. Those incidents were also targeted at blockchain developers who were contacted by fake recruiters through LinkedIn. In addition to stealing a person’s cryptocurrency, the hackers maintained their access to victim devices in the hopes that the person got hired at other tech firms, allowing North Korean hackers to piggyback into corporate systems. At least one blockchain company previously confirmed that a version of this tactic was responsible for a damaging cryptocurrency theft incident. The law enforcement agencies tied WaterPlum to other North Korean efforts to infect the devices of job applicants. Dating back to 2020, cybersecurity firms have identified similar North Korean campaigns targeting job seekers in the defense industry, and Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted with malicious emails from fake recruiters claiming to be from Disney, Google and Oracle. Ties to IT worker schemes According to the report, the WaterPlum campaign is deeply intertwined with the IT worker scheme — where North Koreans steal or purchase identities to get hired in lucrative roles at technology firms in the U.S. or Europe. Japanese officials noted that for the first time, they disrupted a laptop farm operated by a Japanese national and found evidence that several hundred million Japanese yen was sent to addresses outside of the country. The FBI has uncovered dozens of laptop farms across the U.S. that are used by North Koreans to make it look like they are working locally. The report notes that WaterPlum actors and North Korean IT workers used the same IP addresses when accessing laptop farms or applying for positions at Japanese cryptocurrency companies. The laptop farm disruption allowed Japanese officials to get an inside look at a variety of North Korean schemes. North Korean IT workers who interviewed for roles were seen using AI face-swapping software, text-to-speech software that gave them Japanese pronunciations and other AI translation tools. The report said the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department — which is within the Central Committee of the Workers Party of Korea. Experts previously told Recorded Future News that multiple government departments within North Korea essentially run squads of their own cyber workers who participate in a variety of revenue-generating schemes, including legitimate IT work, cryptocurrency thefts and data extortion. “While North Korean IT workers primarily focus on revenue generation, there have been cases of additional malicious cyber activity. In one case, a North Korean IT worker extorted a company over payment and published its proprietary source code online,” the advisory said. “In another case, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.” Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaSep 18, 2026extracted
Related Stories
4
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now carrying out remediation and recovery work and says all of its Secure Email Cloud devices have been upgraded to AsyncOS 16.5.0-780. Admins running their own appliances have a little more work to do. Cisco recommends checking logs for signs of suspicious activity, but warns that finding nothing doesn't necessarily mean the system is clean. Once attackers have root access, Cisco says they could tamper with the logs and cover their tracks. Admins are also being told to check network and firewall logs for anything unusual, rather than relying on the gateway itself for answers. For virtual appliances suspected of being compromised, Cisco's recovery advice is fairly drastic: preserve the forensic evidence, deploy a fresh VM running fixed software, rebuild the configuration, and rotate credentials and cryptographic material. Cisco has fixed the bug in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, with customers strongly encouraged to move to the latter. There's still a decent-sized target pool out there. The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday The flaw has also landed in CISA's Known Exploited Vulnerabilities catalog, with US federal civilian agencies ordered to remediate it by September 17. CVE-2026-76461 comes less than a year after attackers exploited another critical AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms. That bug eventually scored a perfect 10. For anyone still running an affected gateway, the message is fairly simple: the box designed to inspect hostile email can itself be pwned by one; attackers are already doing it, and there is no workaround to hide behind. ®
5 shared
Sep 18, 2026
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls Amazon threat intelligence has identified an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device, which was disclosed by Cisco on March 4, 2026. After Cisco’s disclosure, Amazon threat intelligence began research into this vulnerability using Amazon MadPot’s global sensor network—a system of honeypot servers that attract and monitor cybercriminal activity. While looking for any current or past exploits of this vulnerability, our research found that Interlock was exploiting this vulnerability 36 days before its public disclosure, beginning January 26, 2026. This wasn’t just another vulnerability exploit, Interlock had a zero-day in their hands, giving them a week’s head start to compromise organizations before defenders even knew to look. Upon making this discovery, we shared our findings with Cisco to help support their investigation and protect customers. A misconfigured infrastructure server—essentially, a poorly secured staging area used by the attackers—exposed Interlock’s complete operational toolkit. This rare mistake provided Amazon’s security teams with visibility into the ransomware group’s multi-stage attack chain, custom remote access trojans (backdoor programs that give attackers control of compromised systems), reconnaissance scripts (automated tools for mapping victim networks), and evasion techniques. AWS infrastructure and customer workloads on AWS were not observed to be involved in this campaign. This advisory shares comprehensive technical analysis and indicators of compromise to help organizations identify potential compromise and defend against Interlock’s operations. Organizations running Cisco Secure Firewall Management Center should immediately apply Cisco’s security patches and review the indicators provided below. Discovery and investigation timeline Amazon threat intelligence identified threat activity potentially related to CVE-2026-20131 beginning January 26, 2026, predating the public disclosure. Observed activity involved HTTP requests to a specific path in the affected software. Request bodies contained Java code execution attempts and two embedded URLs: one used to deliver configuration data supporting the exploit, and another designed to confirm successful exploitation by causing a vulnerable target to perform an HTTP PUT request and upload a generated file. Multiple variations of these URLs were observed across different exploit attempts. To advance the investigation and obtain additional threat intelligence, we performed the expected HTTP PUT request with the anticipated file content—essentially, we pretended to be a successfully compromised system. This successfully prompted Interlock to proceed to the next stage, issuing commands to fetch and execute a malicious ELF binary (a Linux executable file) from a remote server. When analysts retrieved the binary, they discovered the same host (attacker-controlled server) is used for distributing Interlock’s entire operational toolkit. The exposed infrastructure organized artifacts into separate paths corresponding to individual targets, with the same paths used for both downloading tools to compromised hosts and uploading operational artifacts back to the staging server. Attribution to Interlock ransomware The ELF binary and associated artifacts are attributable to the Interlock ransomware family based on convergent technical and operational indicators. The embedded ransom note and TOR negotiation portal are consistent with Interlock’s established branding and infrastructure. The ransom note’s invocation of multiple data protection regulations reflects Interlock’s documented practice of citing regulatory exposure to pressure victims, essentially threatening organizations not just with data encryption, but with regulatory fines and compliance violations. The campaign-specific organization identifier embedded in the note aligns with Interlock’s per-victim tracking model. Interlock has historically targeted specific sectors where operational disruption creates maximum pressure for payment. Education represents the largest share of their activity, followed by engineering, architecture, and construction firms, manufacturing and industrial organizations, healthcare providers, and government and public sector entities. Temporal analysis performed on timestamps from observed threat activities, artifacts stored on the misconfigured infrastructure server, and metadata embedded within recovered threat artifacts indicates the actor most likely operates in UTC+3 with 75–80% confidence. Systematic analysis across all UTC offsets showed UTC+3 produced the best fit: first activity around 08:30, peak activity between 12:00 and 18:00, and a probable sleep window of 00:30–08:30. Technical analysis: Interlock’s operational toolkit Post-compromise reconnaissance script Once Interlock gains initial access, they use a variety of priority tools to complete their attack. Amazon threat intelligence teams recovered a PowerShell script designed for systematic Windows environment enumeration (automated information gathering about the victim’s network). The script collects operating system and hardware details, running services, installed software, storage configuration, Hyper-V virtual machine inventory, user file listings across Desktop, Documents, and Downloads directories, browser artifacts from Chrome, Edge, Firefox, Internet Explorer, and 360 browser (including history, bookmarks, stored credentials, and extensions), active network connections correlated with responsible processes, ARP tables, iSCSI session data, and RDP authentication events from Windows event logs. The script stages results to a centralized network share (\JK-DC2\Temp) using each system’s fully qualified hostname to create dedicated directories—essentially creating a folder for each compromised computer. Following collection, it compresses data into ZIP archives named after each hostname and removes original raw data. This structured per-host output format indicates the script operates across multiple machines within a network—a hallmark of ransomware intrusion chains that prepare for organization-wide encryption. Custom remote access trojans Remote access trojans (RATs) are malicious programs that give attackers persistent control over compromised systems, functioning like unauthorized remote desktop software. JavaScript implant: Amazon threat intelligence recovered an obfuscated JavaScript remote access trojan that suppresses debugging output by overriding browser console methods (hiding its activity from basic detection tools). On execution, it profiles the infected host using PowerShell and Windows Management Instrumentation (WMI), collecting system identity, domain membership, username, OS version, and privilege context before transmitting this data during an encrypted initialization handshake. Command-and-control communication occurs over persistent WebSocket connections with RC4-encrypted messages using per-message 16-byte random keys embedded in packet headers—essentially, each message uses a different encryption key, making interception more difficult. The implant cycles through multiple operator-controlled hostnames and IP addresses in randomized order with exponential backoff between reconnection attempts. The implant provides interactive shell access, arbitrary command execution, bidirectional file transfer, and SOCKS5 proxy capability for tunneling TCP traffic (routing malicious traffic through other systems to hide its origin). Self-update and self-delete capabilities allow operators to replace or remove the implant without reinfection, supporting operational cleanup to hinder forensic investigation. Java implant: A functionally equivalent client implemented in Java provides identical command-and-control capabilities. Built on GlassFish ecosystem libraries, it uses Grizzly for non-blocking I/O transport and Tyrus for WebSocket protocol communication. In simpler terms, Interlock built the same backdoor in two different programming languages, ensuring they maintain access even if defenders detect one version. Infrastructure laundering script Sophisticated threat actors don’t attack from their own infrastructure, they build disposable relay networks to hide their tracks. Amazon threat intelligence teams identified a Bash script that configures Linux servers as HTTP reverse proxies (intermediary servers that forward traffic to hide the attacker’s true location). The script performs system updates, installs fail2ban with SSH brute-force protection, and compiles HAProxy 3.1.2 from source. The HAProxy instance listens on port 80 and forwards all inbound HTTP traffic to a hardcoded target IP, with systemd ensuring persistence across reboots. A notable component is a log erasure routine running as a cron job every five minutes. The routine truncates all *.log files under /var/log and suppresses shell history by unsetting the HISTFILE variable. This aggressive evidence destruction, wiping logs every five minutes, combined with the purpose-built HTTP forwarding proxy, indicates the script establishes disposable traffic-laundering relay nodes. These nodes obscure exploit traffic origin, relay command-and-control communications, or proxy data exfiltration, making it nearly impossible to trace attacks back to their source. Memory-resident webshell Amazon threat intelligence teams observed a Java class file delivered as an alternative to the ELF binary drop. When loaded by the Java Virtual Machine (JVM), its static initializer registers a ServletRequestListener with the server’s StandardContext, essentially installing a persistent memory-resident backdoor that intercepts HTTP requests without writing files to disk. This “fileless” approach evades traditional antivirus scanning that looks for malicious files. The listener inspects incoming requests for specially crafted parameters containing encrypted command payloads. Payloads are decrypted using AES-128 with a key derived from the MD5 hash of the hardcoded seed “geckoformboundary99fec155ea301140cbe26faf55ed2f40″ (using the first 16 characters: 09b1a8422e8faed0). Decrypted payloads are treated as compiled Java bytecode, dynamically loaded into the JVM, and executed—a technique designed to evade file-based detection by running malicious code entirely in memory. Connectivity verification tool Amazon threat intelligence teams recovered Java class files implementing a basic TCP server listening on port 45588 (encoded as Unicode character 넔 to obscure the port number from static analysis). The server accepts connections, logs connecting IP addresses, sends a greeting message, and immediately closes connections. This operational profile is consistent with a lightweight network beacon—essentially a “phone home” tool used to verify successful code execution or confirm network port reachability following initial exploitation. Legitimate tool abuse Interlock deployed ConnectWise ScreenConnect, a legitimate commercial remote desktop tool, alongside custom implants. When ransomware operators deploy legitimate remote access tools alongside their custom malware, they’re buying insurance—if defenders find and remove one backdoor, they still have another way in. This indicates multiple redundant remote access mechanisms—a pattern consistent with ransomware operators seeking to maintain access even if individual footholds are removed. The tool’s legitimate network footprint helps blend with authorized remote administration traffic, making detection more challenging. Amazon threat intelligence teams also recovered Volatility, an open-source memory forensics framework typically used by incident responders (the same tool defenders use to investigate attacks). While no artifacts indicated automated use, its presence alongside custom implants and reconnaissance scripts is consistent with advanced threat operations. Both ransomware groups and nation-state actors have been observed deploying Volatility during intrusions. The tool’s focus on parsing memory dumps provides access to sensitive data such as credentials stored in RAM, which can enable lateral movement (spreading through the network) and deeper environment compromise in support of ransom operations or espionage objectives. Interlock also used Certify, an open source offensive security tool designed to exploit misconfigurations in Active Directory Certificate Services (AD CS). For ransomware operators, Certify provides a pathway to identify vulnerable certificate templates and enrollment permissions that allow requesting authentication-capable certificates. These certificates can be used to impersonate users, escalate privileges, or maintain persistent access. These capabilities directly support both initial compromise and long-term persistence objectives in ransomware operations. Indicators of compromise (IoCs) The following indicators support defensive measures by organizations that may be affected. Due to Interlock’s use of content variation techniques, most file hashes are not included as reliable indicators. The threat actor modified most artifacts like scripts and binaries downloaded to different targets. This resulted in different file hashes for functionally identical tools. The customization allowed each attack to evade signature-based detection that looks for exact file matches. Defensive recommendations Organizations should take the following actions to protect against Interlock ransomware operations. Immediate actions: Apply Cisco’s security patches for Cisco Secure Firewall Management Center Review logs for the indicators of compromise listed above Conduct security assessments to identify potential compromise Review ScreenConnect deployments for unauthorized installations Detection opportunities: Monitor for PowerShell scripts staging data to network shares with hostname-based directory structures Detect Java ServletRequestListener registrations in web application contexts (unusual modifications to Java web applications) Identify HAProxy installations with aggressive log deletion cron jobs (proxy servers that erase their own logs every five minutes) Watch for TCP connections to unusual high-numbered ports (e.g., 45588) Long-term measures: Implement defense-in-depth strategies with multiple layers of security controls Maintain continuous threat monitoring and hunting capabilities Ensure comprehensive logging with secure, centralized log storage (stored separately from systems that could be compromised) Regularly test incident response procedures for ransomware scenarios Educate security teams on Interlock’s tactics, techniques, and procedures The real story here isn’t just about one vulnerability or one ransomware group—it’s about the fundamental challenge zero-day exploits pose to every security model. When attackers exploit vulnerabilities before patches exist, even the most diligent patching programs can’t protect you in that critical window. This is precisely why defense in depth is essential—layered security controls provide protection when any single control fails or hasn’t yet been deployed. Rapid patching remains foundational in vulnerability management, but defense in depth helps organizations not to be defenseless during the window between exploit and patch. Amazon Threat Intelligence teams continue to monitor Interlock ransomware operations and will provide updates as additional information becomes available. The intelligence gathered from this campaign is being integrated into AWS security services to protect customers proactively. If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post, contact AWS Support.
4 shared
Mar 23, 2026
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are the same ones F5 pointed customers to in March, when it said changes to them alone do not show a break-in. A web shell is usually a small script an attacker drops into a web server's folders to run commands through ordinary web requests. Because it sits on disk, defenders look for it by scanning files and comparing them against known-good copies. That approach does not work here. As the researchers put it, the web shell "does not need to exist in its final form on disk." The three scripts are apm_css.php3, full_wt.php3 and webtop_popup_css.php3, part of the BIG-IP APM webtop. F5 named all three in March in a published list of indicators of compromise for the malware it tracks as c05d5254, and said at the time that their presence alone does not point to a security problem. F5 also said it had seen cases where a web shell was written to disk, but that the web shells "have been observed to work in memory only," which means the files it listed might not be modified. The Sophos analysis explains how both statements can be true at once. Sophos examined a single sample. Its analysis names no victim and does not say how the sample was obtained. F5 has linked the c05d5254 activity to appliances affected by CVE-2025-53521, Sophos said. F5 first published that flaw on October 15, 2025, as a denial-of-service problem. On March 27, 2026, F5 said new information had led it to reclassify the flaw as remote code execution, and that it had been exploited. An attacker needs no login to use it, and F5 rates it 9.8 on CVSS 3.1 and 9.3 on CVSS 4.0. CISA added it to its Known Exploited Vulnerabilities catalog the same day, giving U.S. federal civilian agencies until March 30 to act. The flaw applies where a BIG-IP APM access policy is set on a virtual server. The UK's National Cyber Security Center calls BIG-IP APM a common component, especially in large organizations. F5's advisory lists the affected and fixed releases. The patch that fixes this is nearly a year old. Ireland's National Cyber Security Center said in a March 31 advisory that the patch released in October is still valid and will protect against exploitation. The web shell is the last step in a longer chain, and the earlier steps do touch the disk. Sophos said a separate installer, found in a sample named umount, infects the Apache web server program at /usr/sbin/httpd by adding malicious code to the front of the real file. The size of that added code matches the payload carried inside the installer, which Sophos said strongly suggests the installer puts it there. ESET, which analyzed related samples in April and named the malware PoisonedRefresh, said the installer is meant to be run as root and turns off SELinux. It also infects umount, httpd and rc.local inside BIG-IP install images, which ESET said was presumably done to spread the malware to other systems through the installation media. Because the malware sits inside the Apache program, it runs before Apache's own code starts. Sophos said it hooks an Apache Portable Runtime function, apr_dso_load, and does nothing until Apache loads the PHP module, libphp. Once PHP is loaded, the malware reads /proc/self/maps to find the module in memory, briefly makes those memory pages writable, rewrites the calls the module uses to open, size, and map files, then puts the original permissions back. From that point, it controls what PHP sees when it opens one of the three scripts. When the file is mapped into memory, the malware places the web shell in front of the original content. The web shell reads the raw body of a request, checks it for a short marker, decrypts the rest, and runs it. It replies with HTTP status 201 and a CSS content type, so the exchange looks like a request for a stylesheet. The malware also opens a local socket at /run/bigtlog.pipe. After checking for a fixed token, it connects that socket to /bin/bash, giving an interactive shell without opening a network port. Sophos said it could not find any code in the sample for connecting to that socket, and no other use of the token, so the two ways in look like separate features. It has no evidence either way on whether the attacker reaches the socket through the web shell. What Defenders Can Check Sophos said its behavioral signals are leads to investigate, not proof on their own, and should be read alongside file, process, and memory evidence. The list below combines them with the indicators F5 published in March. File: /run/bigtlog.pipe or /run/bigstart.ltm present Binary: hash, size or timestamp mismatch on /usr/bin/umount or /usr/sbin/httpd against a known good copy. F5 notes that sizes and timestamps differ between releases and engineering hotfixes Tool: sys-eicheck failing because one of those two files has changed Log: an entry in /var/log/restjavad-audit showing a local user reaching the iControl REST API from localhost Log: an entry in /var/log/auditd showing SELinux being switched off by the same route Log: an entry in /var/log/audit showing a bash command run through iControl REST. F5 says these lines show base64 data written into a file and /run/bigstart.ltm being run Traffic: HTTP 201 responses carrying a CSS content type from the appliance Host behavior: an Apache worker reading /proc/self/maps, changing memory permissions around libphp, binding a socket under /run, or starting /bin/bash SHA-256: 26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9 File, weak on its own: changes to the three .php3 scripts. F5 says their presence alone does not show a problem, and the Sophos analysis explains why: the file does not have to change at all F5's list also includes items the Sophos analysis does not cover, among them /run/bigstart.ltm and the changes affecting sys-eicheck. Neither account describes the whole intrusion. If You Have Already Patched Patching does not settle whether an appliance was compromised before the patch went on. Ireland's NCSC said no timeline for exploitation is available, and that it expects some exploitation was or could have been happening before the flaw and its fix were first published in October 2025. The UK's NCSC advises investigating for compromise "regardless of when the system was updated." Run F5's built-in sys-eicheck integrity check. F5's own indicators say the changes to /usr/bin/umount and /usr/sbin/httpd make this tool fail, so a failure is itself the signal. Collect a qkview report, send it to F5 and raise a case. Ireland's NCSC said F5 can check that report for signs of compromise, and that raising an associated case brings a quicker and fuller response. Compare the contents of modules in memory against the copies on disk, which Sophos recommends adding to incident response playbooks for critical web servers. Where a full investigation is not possible, the UK NCSC advises isolating the appliance and rebuilding it as new, and says this may cause an outage. Three things are still unknown. F5 has not said when exploitation began. None of the published advisories or analyses say whether upgrading an appliance to a fixed release removes malware already installed on it, and both Sophos and ESET describe a component designed to survive upgrade images. And no one has named an attacker: Sophos said it does not have enough evidence to name a group, and ESET said in April that it had not settled the question either.
4 shared
Sep 9, 2026
Microsoft Plugs Nearly 1,000 Security Holes
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical vulnerability that could result in arbitrary code execution," Adobe said, adding it's "aware that CVE-2026-75650 has been exploited in the wild targeting Adobe Commerce merchants." At its core, the flaw abuses Magento's template system through PHP code injection to generate a "Payment Transaction Failed Reminder" email, triggering code execution in the process. The shortcoming affects the following versions - Adobe Commerce - 2.4.9-2026-aug and earlier - 2.4.8-2026-aug and earlier - 2.4.7-2026-aug and earlier - 2.4.6-2026-aug and earlier - 2.4.5-2026-aug and earlier - 2.4.4-2026-aug and earlier Adobe Commerce B2B - 1.5.3-2026-aug and earlier - 1.5.2-2026-aug and earlier - 1.4.2-2026-aug and earlier - 1.3.4-2026-aug and earlier - 1.3.3-2026-aug and earlier Magento Open Source - 2.4.9-2026-aug and earlier - 2.4.8-2026-aug and earlier - 2.4.7-2026-aug and earlier - 2.4.6-2026-aug and earlier Patches have been released as part of a hotfix's available for download from the following link: repo.magento[.]com/patch/VULN-39341-composer-patches.zip "To help resolve the vulnerability for the affected products and versions, you must apply the VULN-39341 patch (depending on your version) and rotate your encryption keys," Adobe said. The development comes days after the Dutch e-commerce security company revealed that threat actors are exploiting CVE-2026-75650 to deploy a Rust-based Linux backdoor that connects to an external server and awaits further instructions. Separately, the issue has been abused to deliver a PHP dropper on susceptible sites that writes a web shell capable of executing arbitrary PHP code. According to Netherlands-based Disrex, a Magento server managed by the e-commerce development platform is said to have been compromised 50 minutes after the first confirmed StyleSmuggler exploitation was reported on September 4, 2026, at 10:20 p.m. UTC. "StyleSmuggler turns Magento's own template-processing and dependency-injection code into an unauthenticated remote-code-execution chain," Disrex said. Telemetry data from Previdian shows that 12 exploitation attempts have been recorded against its honeypots since September 7, 2026, from two unique IP addresses from China and Romania. That said, the efforts have been unsuccessful, Founder and CEO Ryan Dewhurst said. Update The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 8, 2026, added CVE-2026-75650 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. In tandem, Adobe has also released patches for more than 170 vulnerabilities across its products, including CVE-2026-82004 (CVSS score: 10.0), an operating system command injection flaw in Campaign Classic leading to arbitrary code execution. Also patched by Adobe are two critical vulnerabilities in ColdFusion CVE-2026-48273, CVSS score: 9.9, and CVE-2026-75746, CVSS score: 9.1) that could result in arbitrary code execution. The web design software maker said it's not aware of any exploits in the wild for any of these issues.
4 shared
Sep 9, 2026