Loki Intelligence — Security Briefs · Published

Daily Security Brief: Magento Zero-Day, APIS Leak, MFA Phishing

Active exploitation of Adobe Commerce and Magento is the top operational priority, with reports of backdoors and web shells following a critical zero-day. Teams should also review exposure management for sensitive databases, Microsoft 365 identity controls, cloud misconfigurations, and recently patched application components.

Signal 01 · The Hacker News

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe released emergency fixes for a critical Adobe Commerce and Magento Open Source flaw reportedly exploited in live attacks. The activity has been linked to deployment of persistent server-side malware.

Why it matters: Commerce teams should prioritize patch validation, review recent server changes, inspect for unauthorized files or processes, and confirm incident response coverage for storefront infrastructure.

Source: The Hacker News

Signal 02 · BleepingComputer

220 million traveler records exposed in Vietnam-linked APIS leak

A cloud-exposed APIS database reportedly contained hundreds of millions of passenger and crew records, including identity and travel details spanning several years. The incident highlights the sensitivity of border, airline, and travel ecosystem data.

Why it matters: Organizations handling regulated personal data should audit cloud storage paths, enforce access controls, monitor public exposure, and verify retention limits for high-risk identity records.

Source: BleepingComputer

Signal 03 · BleepingComputer

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Additional reporting says the Magento zero-day known as StyleSmuggler is being used to install a Linux backdoor on affected systems. All versions are described as impacted pending vendor remediation.

Why it matters: Security teams should treat vulnerable Magento hosts as potentially compromised until patched and reviewed, with emphasis on integrity checks, log analysis, credential rotation, and egress monitoring.

Source: BleepingComputer

Signal 04 · BleepingComputer

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service platform called BigBear 2.0 reportedly bypassed MFA protections across hundreds of organizations and captured thousands of Microsoft 365 credentials. The campaign underscores continued risk from adversary-in-the-middle phishing.

Why it matters: Identity teams should strengthen phishing-resistant MFA, monitor risky session activity, apply conditional access, and train users to report unexpected Microsoft 365 sign-in prompts.

Source: BleepingComputer

Signal 05 · The Hacker News

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The weekly roundup covers several notable threats, including a Chrome zero-day, router hijacking, supply chain issues, and phishing tricks that evade common email display controls. The breadth shows how attackers mix endpoint, network, and social engineering tactics.

Why it matters: Defenders should avoid relying on single controls, keep browsers and network devices current, and test email protections against non-image-based phishing content.

Source: The Hacker News

Signal 06 · The Hacker News

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

Analysis of multi-cloud environments found that cloud risk varies by provider and is often shaped by configuration drift rather than a single universal checklist. The findings argue for provider-specific controls and continuous validation.

Why it matters: Cloud teams should map controls to AWS, Azure, and Google Cloud differences, automate misconfiguration detection, and track ownership for remediation instead of relying only on static checklists.

Source: The Hacker News

Signal 07 · The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A public proof of concept shows how a Telerik UI for ASP.NET AJAX weakness can be chained to remote code execution in certain non-default deployments. Progress addressed the issue in July, and there are no confirmed active attacks in the report.

Why it matters: Engineering teams using Telerik components should confirm patched versions, inventory exposed ASP.NET applications, and remove unsupported or risky configurations from production.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki service: Orvyn — AI agent security private preview.