Active Exploitation of Magento Zero-Day and Chromium Backdoors

Active Exploitation of Magento Zero-Day and Chromium Backdoors

First seen 8 Sep 2026, 06:32 UTC Defendworkwww.securityweek.com 74.0

Article Content

Browse articles
ThreatCluster

A sophisticated backdoor toolkit named PEEP has been discovered, exploiting browser extensions in Chrome and Edge for command execution post-compromise. Additionally, a zero-day vulnerability in Magento and Adobe Commerce, known as StyleSmuggler, is being actively exploited, allowing attackers to deploy persistent Linux backdoors on e-commerce platforms. The BigBear 2.0 phishing-as-a-service platform has compromised 258 organizations by bypassing multi-factor authentication and stealing over 5,000 Microsoft 365 credentials. Recent arrests of two members of TeamPCP mark a significant law enforcement action against ongoing supply-chain attacks. The Google Chromium V8 type confusion vulnerability (CVE-2026-85046) is also under active exploitation. Organizations are urged to audit browser extensions, implement WAF rules, and monitor logs for suspicious activity.

Key Points: • PEEP backdoor exploits Chrome and Edge extensions for command execution. • Magento zero-day vulnerability allows unauthorized remote code execution. • BigBear 2.0 phishing platform has compromised 258 organizations.

Ask AI about this cluster

Timeline

2026-09-03
CVE-2026-85046 published
Google disclosed a type confusion vulnerability in Chromium affecting multiple browsers.
Defendwork
2026-09-04
CVE-2026-85046 added to CISA KEV
CISA listed the Chromium vulnerability as actively exploited in the wild.
Defendwork
2026-09-08
PEEP backdoor toolkit disclosed
Cybersecurity researchers revealed PEEP, a backdoor toolkit masquerading as a browser extension.
Defendwork
2026-09-08
Magento zero-day exploitation confirmed
The StyleSmuggler vulnerability is actively being exploited to deploy Linux backdoors on e-commerce platforms.
Defendwork
2026-09-08
BigBear 2.0 phishing platform reported
The phishing-as-a-service platform has compromised 258 organizations, stealing over 5,000 Microsoft 365 credentials.
Defendwork