Magento zero-day 'StyleSmuggler' exploited to plant Rust backdoor before Adobe patch
Sansec saw the first attack on September 4 against a fully patched store; The Hacker News reports Adobe has since issued a fix.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
A zero-day vulnerability dubbed StyleSmuggler, affecting all versions of Magento and Adobe Commerce, has been exploited in the wild to install a Linux backdoor, according to e-commerce security company Sansec as reported by BleepingComputer. The first recorded exploitation was on September 4 against a target running the latest security updates. Adobe Enterprise Support confirmed on Monday that it was working on a fix but gave no timeline. The Hacker News reported on Tuesday that Adobe has patched the flaw, which it says was used to deploy a Rust backdoor and a PHP web shell. Magento is installed on more than 160,000 websites, including 14,000 of the top one million sites. The observed exploit abuses Magento's template system through PHP code injection to generate a fake failed-payment email, which triggers code execution. Successful attacks install a small Rust-based backdoor running as a background process disguised as [kworker/u:8:0]. Newer versions pose as fc-cache and copy themselves to ~/.cache/fontconfig/fc-cache. The attacker also adds a cron job that repeats every 30 minutes for persistence. Sansec did not observe follow-on activity, but the malware can contact remote infrastructure and receive commands. Earlier samples used TLS and WebSockets to reach command-and-control servers. Store operators should apply Adobe's update as soon as possible and check for the disguised processes, the fontconfig cache path and unexpected cron entries.