Cybersecurity News — 2026-09-08
Generated: 2026-09-08 | Sources: BleepingComputer, The Hacker News, Help Net Security, SecurityWeek, Rapid7, Sansec, SOC Prime, IT Security Guru, Huntress, Cybernews, Infosecurity Magazine
1. A Widely Used Remote-Access Gateway Is Being Broken Into by Attackers Who Skip the Login Screen Entirely
Citrix NetScaler — an appliance many businesses put at the edge of their network so staff can work remotely or connect via VPN — has a critical flaw (CVE-2026-19490) that lets an attacker walk straight past the login screen with no account or password at all, on devices set up as a remote-access gateway. Citrix published a fix back on 19 August, but this week brought reports that criminals are now actively scanning for and breaking into unpatched devices after working attack code was published, prompting Belgium's national cyber centre to issue a public warning urging administrators to patch immediately.
Why it matters for your business: if your business or IT provider uses a Citrix NetScaler Gateway for remote access or VPN, confirm today that it's on version 14.1-73.32, 13.1-63.21, or later. This is precisely the kind of device attackers can reach without any credentials, which makes it worth checking ahead of software that merely needs a password guessed.
2. Every Online Store Built on Magento or Adobe Commerce Is Exposed to an Attack With No Official Fix Yet
Researchers this week disclosed a flaw nicknamed "StyleSmuggler" affecting every current version of Magento and Adobe Commerce — the software behind a large share of small and mid-size online shops — and say it's already being used to plant a hidden backdoor on live stores. It works by hiding malicious code inside the store's own template styling settings, then triggering that code to run via an ordinary failed-payment email, so no password, login, or plugin bug is needed. As of this week Adobe has not issued an official patch or CVE advisory, though the firm that discovered the flaw, Sansec, has published a hotfix.
Why it matters for your business: if your online shop runs Magento or Adobe Commerce, don't wait for Adobe's own fix — ask whoever manages your site to apply Sansec's hotfix now and check for unfamiliar admin accounts or files, because "no login required" means an attacker needs nothing from you or your customers to get in.
3. Google Rushed Out a Chrome Fix After Attackers Found a Way to Run Code From a Web Page Alone
Google issued an emergency Chrome update this week after confirming a flaw in V8 — the engine that runs the JavaScript behind most websites — was already being exploited: simply loading a booby-trapped page could let an attacker run their own code on a visitor's computer. It's the sixth time this year Google has had to patch a Chrome bug already under active attack, and the fix shipped within days of the flaw being found.
Why it matters for your business: Chrome usually updates itself quietly in the background, but the fix only takes effect once the browser restarts — so close and reopen Chrome (or restart the computer) rather than assuming a silent update is already protecting you, and do the same for Edge and any other Chromium-based browser your business uses.
4. A New Phishing Kit Steals the Login Session Itself, So Multi-Factor Authentication Never Gets a Chance to Stop It
Researchers uncovered a phishing-as-a-service kit called "Knight Office" being used to break into Microsoft 365 and Google Workspace accounts by stealing an already-logged-in session rather than a password. A victim gets a DocuSign-style email, clicks through a chain of redirects — some via well-known services like Monday.com or a hacked website — signs in and completes multi-factor authentication exactly as normal, and the kit quietly captures the resulting session token: a live, already-verified login the attacker can reuse without ever needing a password or MFA code of their own. It's been running since at least April, with over 700 matching phishing emails reported so far.
Why it matters for your business: multi-factor authentication is still essential, but this is why it isn't the whole answer — train staff to be wary of "document ready to sign" emails they weren't expecting, especially ones that bounce through several unfamiliar links before asking for a login, and if your Microsoft 365 or Google Workspace plan supports it, turn on sign-in alerts so an unexpected session is caught quickly.
5. Berlin Refused to Pay a Ransom Demand — and the Stolen Data Was Published Anyway
The ransomware group Rhysida followed through on its threat to publish stolen data after Germany's Berlin state government refused to pay a roughly €2m ransom by the gang's own deadline. Rhysida says it took 5.8 terabytes — around 1.4 million files, including contracts, staff records, and infrastructure security assessments — from Berlin's administrative network after a break-in first discovered in mid-August, and has since put the data up for sale and leaked samples publicly. Berlin says election systems were unaffected and that it never intended to pay.
Why it matters for your business: this is "double extortion" in practice — refusing to pay doesn't undo the theft, it only decides whether you also fund the criminals. The lesson holds either way: keep offline backups the attacker can't reach or encrypt, and decide separately, in advance, who makes the pay-or-not call and who runs recovery, rather than waiting on one decision to start the other.
Sources
- BleepingComputer — Critical Citrix NetScaler auth bypass now leveraged in attacks
- Help Net Security — Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
- The Hacker News — Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
- Rapid7 — CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- BleepingComputer — Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
- The Hacker News — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Sansec — StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
- SecurityWeek — Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- BleepingComputer — Google warns of new Chrome zero-day flaw exploited in attacks
- The Hacker News — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- SOC Prime — CVE-2026-85046: Actively Exploited Chrome V8 Zero-Day Enables Code Execution
- IT Security Guru — New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
- Huntress — Inside Knight Office, a New M365 AiTM Phishing Kit
- Cybernews — Berlin cyberattack: Rhysida threatens auction of stolen data
- BleepingComputer — Berlin confirms data theft after Rhysida ransomware attack claims
- Infosecurity Magazine — Rhysida Publishes Berlin Government Data After €2m Extortion Demand