📋 Top Headlines at a Glance
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113
- Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Executive Summary: Today’s intelligence highlights a confluence of active exploitation campaigns, ranging from sophisticated infostealer attacks compromising AI platform login sessions to critical zero-day vulnerabilities impacting major e-commerce and content management systems. A notable trend includes the novel use of blockchain for malware payload delivery, underscoring the evolving tactics of cybercriminals. Organizations face persistent challenges in vulnerability management amidst a high volume of reported security flaws.
🌍 Technical Intelligence Breakdown
📰 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113
This newsletter aggregates recent malware-related intelligence, detailing several active threats:
- Infostealer Activity: Threat actors are utilizing infostealer malware to compromise
Claudelogin sessions, leading to account hijacking. - Advanced Malware Evolution:
Fire Antis observed evolving its capabilities, moving from hypervisor-level attacks to targeting trusted infrastructure.Gryxais identified as an AI-built toolkit, incorporating anti-analysis features to evade detection and removal.ValleyRATis being distributed, masquerading as adware to infect systems.
- Defensive Actions: Implement robust endpoint detection and response (EDR) solutions, enforce multi-factor authentication (MFA) for all critical accounts, and conduct regular user awareness training on phishing and social engineering tactics.
🗓️ Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
Further details confirm that Anthropic has initiated account lockouts for Claude users following widespread compromise of login sessions by infostealer malware. This action aims to mitigate ongoing unauthorized access.
- Impact: Direct compromise of user login sessions for an AI platform.
- Vendor Response:
Anthropicis actively locking affected accounts. - Vulnerability Management Outlook: The
September 2026 Patch Tuesdayforecast indicates a continued “Patch Apocalypse,” with record numbers of patches and reported CVEs. This highlights the ongoing burden on organizations to maintain timely patching cycles. - Mitigation: Users of
Claudeshould reset passwords and enable MFA. Organizations should prioritize patching efforts, especially for publicly exposed systems, and enhance monitoring for infostealer activity on endpoints.
🛒 Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A critical unpatched vulnerability, named StyleSmuggler by Sansec, is actively being exploited in Magento Open Source and Adobe Commerce. This zero-day allows attackers to execute malicious code on online store servers without requiring authentication.
- Affected Platforms:
Magento Open Source,Adobe Commerce. - Vulnerability Type: Unauthenticated remote code execution.
- Attack Path: Unauthenticated User →
StyleSmugglerExploit → Remote Code Execution on Server. - Discovery & Timeline: Discovered by
Sansec, with attacks commencing on September 4, and an advisory published on September 5. - Defensive Actions: Organizations using these platforms must monitor
Sansecadvisories for potential workarounds or patches. Implement strong web application firewalls (WAFs) with virtual patching capabilities and conduct frequent security audits of e-commerce environments.
🌐 Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A large-scale cybercriminal operation is leveraging over 5,400 compromised small-business websites to distribute ClickFix payloads. Uniquely, these payloads are stored within smart contracts on the BNB Smart Chain (BSC), indicating a novel method for malware delivery and command-and-control.
- Scale of Compromise: Over 5,400 small-business websites.
- Malware Payload:
ClickFix. - Novel Delivery Method: Payloads hosted on
BNB Smart Chain (BSC)smart contracts. - Implications: This method complicates traditional network-based detection and takedown efforts, as the C2 infrastructure is decentralized and resilient.
- Defensive Actions: Website owners should regularly scan their sites for compromises, ensure all software is updated, and use strong, unique passwords. Network defenders should enhance monitoring for outbound connections to cryptocurrency-related infrastructure that is not business-justified.
⚙️ Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
A critical vulnerability, CVE-2026-32475 (CVSS score of 9.8), in the Elementor Pro WordPress Plugin is being actively exploited. This arbitrary file upload issue within the form submission function allows attackers to compromise affected WordPress sites.
- Affected Component:
Elementor Pro WordPress Plugin. - Vulnerability ID:
CVE-2026-32475. - CVSS Score: 9.8 (Critical).
- Vulnerability Type: Arbitrary file upload.
- Attack Path: Malicious User → Exploits
Elementor Proform submission → Arbitrary File Upload → Website Compromise. - Defensive Actions: Immediately update
Elementor Pro WordPress Pluginto the latest secure version. Implement robust file integrity monitoring (FIM) for WordPress installations and ensure proper file permissions are enforced.
📉 Threat Landscape & Trends
- Persistent Infostealer Threat: Infostealers remain a primary vector for credential theft, now explicitly targeting AI platform login sessions, highlighting the expanding scope of high-value targets.
- Critical Web Application Exploitation: Active zero-day and N-day exploitation of popular web platforms (
Magento,Adobe Commerce,Elementor Pro) underscores the critical need for rapid patching and robust web application security. - Emerging Malware Delivery Tactics: The use of blockchain-based smart contracts for malware payload delivery represents a significant evolution in adversary infrastructure, posing new challenges for traditional security controls.
- Vulnerability Management Overload: The “Patch Apocalypse” continues, with a high volume of CVEs and patches demanding continuous attention and resource allocation from security teams.
- Advanced Malware Capabilities: Malware like
Fire AntandGryxademonstrate increasing sophistication in evasion, persistence, and targeting.
📌 Strategic Takeaway
Organizations must adopt a multi-layered defense strategy focused on rapid vulnerability remediation for web-facing assets, enhanced endpoint security with strong infostealer detection, and proactive monitoring for novel C2 channels, including those leveraging blockchain. User education on credential hygiene and phishing remains paramount, especially for emerging AI services.
🔗 References
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113
- Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites