Threat Brief — 2026-09-08 — Zero-Day Patches, AI Attack Automation, Identity Flaws
Adobe has shipped an emergency fix for the actively exploited Magento/Adobe Commerce zero-day first reported unpatched on 2026-09-05 — the vulnerability (CVE-2026-75650KEV, max severity) was being used to deploy a Rust backdoor and PHP web shell. Separately, a FreeIPA flaw chain that lets unauthenticated clients create reusable administrator credentials and a WeChat zero-click worm propagating via incoming calls both demand immediate attention. On the strategic side, two independent reports detail threat actors moving from AI-assisted tooling toward autonomous multi-agent attack frameworks.
Top items
- Magento/Adobe Commerce CVE-2026-75650KEV patch released. Adobe has issued emergency patches for this max-severity zero-day, which was actively exploited in the wild to backdoor servers with a Rust backdoor and PHP web shell. This is a genuine development: the flaw was first reported unpatched on 2026-09-05 and is now remediated. Affected products include multiple versions of Magento Open Source and Adobe Commerce. (src: BleepingComputer) · (src: The Hacker News)
- FreeIPA flaw chain lets anonymous clients mint administrator credentials. A vulnerability in FreeIPA allows a client that has never authenticated to create a Kerberos identity of its choosing in the directory and land in the administrators group. Red Hat has disclosed the issue. Any organisation using FreeIPA for identity management across Linux environments should treat this as high priority — the flaw effectively grants unauthenticated root-level directory access. (src: The Hacker News)
- WeChat zero-click worm spreads via incoming calls on iPhone and Android. Researchers at security firm Calif demonstrated a worm that takes over a WeChat account through an incoming call — the recipient does not need to answer or interact with the device. The worm was shown propagating among three test phones. The attack surface is anyone running WeChat with call functionality enabled. (src: The Hacker News)
- Threat actors building multi-agent AI frameworks for automated credential theft. Attackers are shifting from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack, from reconnaissance through credential theft. This represents a move from AI as a tool to AI as an attack orchestrator. (src: BleepingComputer)
- GTIG: adversarial AI evolving from prompting to autonomy. Google Threat Intelligence Group reports that since its May 2026 assessment, forward-leaning adversaries have transitioned from basic prompt-based misuse toward more autonomous AI-driven operations. The trend indicates adversaries are operationalising AI agents rather than merely using chat interfaces for assistance. (src: Mandiant Blog)
- Windows Server 2025 memory management changes causing application crashes. Microsoft has warned that recent memory management changes in Windows Server 2025 may cause application crashes on some systems. Administrators running production workloads on Server 2025 should test for stability impact. (src: BleepingComputer)
- BengalSEO SEO-poisoning campaign delivers MayaBot and tech support scams via Bing. A large-scale SEO poisoning campaign is manipulating Bing search results to redirect victims to malware deployment (MayaBot) and tech-support scam pages. The campaign was discovered by the DFIR Report in March 2026 and has now been publicly detailed. (src: The Hacker News)
- BelGaN industrial espionage: GaN chip secrets may have reached China. Belgian authorities are investigating industrial espionage at chip manufacturer BelGaN, where a senior executive simultaneously held a position at a Chinese company in the same industry. Gallium nitride (GaN) semiconductor technology was the suspected target. (src: SecurityLab)
- Forgotten Google Workspace third-party integrations create persistent breach risk. Third-party applications connected to Google Workspace can retain access long after their original purpose has ended, creating an overlooked attack surface. The risk is compounded by overly permissive OAuth scopes granted to integrations that are never revoked. (src: BleepingComputer)
Themes
AI as attack infrastructure, not just tooling. Two separate reports today — from GTIG and from BleepingComputer — describe the same trajectory: adversaries are moving beyond using LLMs for code generation or phishing drafting toward deploying multi-agent frameworks that autonomously orchestrate full attack chains. This shifts the defender's problem from detecting AI-generated content to detecting AI-driven operational behaviour.
Identity systems under pressure. The FreeIPA flaw and the Google Workspace third-party access problem both highlight the same pattern: identity infrastructure accumulates privileged trust relationships that are rarely audited. Whether it's an anonymous client minting Kerberos admin credentials or a forgotten OAuth integration with domain-wide delegation, the gap between granted access and intended access is where attackers are finding footholds.
