September 8, 2026 by sig9

Hacker Wars - September 08, 2026

bulletin-feature-image

Your daily dose of infosec chaos


E-commerce admins get to deal with an actively exploited Magento zero-day, because patching under fire builds character. Meanwhile 220 million traveler records are sitting in a misconfigured database, someone turned Chrome into a backdoor, and MFA once again failed to save anyone. And Grindr learned that sharing users’ HIV status with advertisers is, in fact, a £26 million mistake.

StyleSmuggler Zero-Day Backdoors Magento Stores

A zero-day dubbed StyleSmuggler affects every version of Magento and Adobe Commerce and is being actively exploited to plant Linux backdoors on storefronts. Attackers abuse the platforms’ CSS handling to smuggle malicious payloads past inspection, turning your product catalog into a delivery mechanism.

What to do: If you run Magento or Adobe Commerce, treat patching as a fire drill today, and audit for unexpected admin accounts and cron jobs.


220 Million Traveler Records Exposed In Aviation Database Leak

An exposed Advance Passenger Information System database linked to Vietnam leaked 220 million passenger and crew records, including names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Border control data is a goldmine for tracking journalists, dissidents, and anyone else who thought their movements were private.

What to do: Assume your travel history is on the open market, and brief anyone at risk on physical surveillance indicators.


PEEP Toolkit Turns Chrome And Edge Into Persistent Backdoors

Researchers detailed PEEP, a Chromium-based post-exploitation toolkit that disguises itself as a bookmarks extension and gets injected directly into Chrome and Edge profiles. Once embedded, it executes host commands and survives most cleanup attempts, since who suspects the browser itself of being the implant.

What to do: Inventory browser extensions and profile directories, and alert on extensions that appear outside your deployment pipeline.


BigBear Phishing Service Bypassed MFA At 258 Organizations

A phishing-as-a-service framework called BigBear 2.0 was used to defeat multi-factor authentication at 258 organizations and harvest more than 5,000 Microsoft 365 credentials. Renting enterprise-grade credential theft is now a subscription business, and your perimeter is their product roadmap.

What to do: Move to phishing-resistant MFA like FIDO2 keys and enforce device compliance checks on mail access.


Grindr To Pay £26 Million Over HIV Status Data Sharing

Grindr agreed to pay £26 million to settle U.K. claims that it shared sensitive personal data, including users’ HIV status and medication details, with third-party advertisers. A timely reminder that “we share data with trusted partners” can quietly become the most expensive sentence in your privacy policy.

What to do: Map exactly what sensitive attributes leave your systems and to whom, because regulators and class actions certainly will.


That’s the chaos for today. Stay sharp out there.


Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown

This bulletin is provided for informational purposes. Contact us for tailored security analysis.