|
🔓 Hackers drain $320M from Bitcoin sidechain
LINK
|
- Purported white hat hackers have drained just under 4,000 Bitcoin worth $319 million from Blockstream's Liquid Network sidechain, prompting the team to pause bridge nodes and tell exchanges to halt LBTC deposits and withdrawals while it investigates.
- The funds were withdrawn via the SideSwap Peg-out Authorization Key (PAK), though Liquid says that key was not compromised, nor were any others, leaving open whether 11 of 15 functionaries signed off or the withdrawal whitelist failed to hold.
- The federation wallet's balance fell from 4,200 BTC to 207.275 BTC, and analyst DBCrypto noted the coins are sitting unmixed on Bitcoin, more consistent with a whitehat extraction, while an OP_RETURN message read: "we are whitehats. contact us on chain."
|
💥 Berlin cyberattack leaks sensitive data across the dark web
LINK
|
- The ransomware group Rhysida has published nearly six terabytes of data, 1,439,893 files, stolen from Berlin's state administration on the dark web after the city refused to pay the ransom.
- The hackers had demanded 30 Bitcoin, around two million euros, and set a countdown that expired at about 3.35 pm on Friday; the Berlin Senate said it does not give in to blackmail, and the data was released shortly after.
- Leaked files include a folder on chemical, biological, radiological and nuclear threat planning, LKA investigation documents, national defense plans, plus personal data on state civil servants like birth certificates, phone numbers and home addresses.
|
🛡️ Router flaw grants full control
LINK
|
- Attackers are actively exploiting a flaw in MikroTik RouterOS that hands any remote, unauthenticated attacker a direct shell on the device, opening the door to full network takeover, with MikroTik confirming the bug on September 3, 2026.
- The flaw sits in a core library shared by multiple RouterOS services and is tied to SSH, so any router with SSH reachable from the internet can be taken over without stealing credentials or any user interaction, regardless of password or key-based login.
- Fixes shipped across every channel including 7.24.2, 7.23.4, and 6.49.21; upgraded devices now auto-inspect their config at startup and set a "Flagged" status on signs of tampering, but MikroTik urges auditing every device, rotating passwords, and restricting SSH regardless.
|
🛒 Magento zero-day used to backdoor stores
LINK
|
- A zero-day flaw called StyleSmuggler in Magento Open Source and Adobe Commerce is being used to fully take over online stores, with e-commerce security firm Sansec disclosing it early on September 5, 2026 because sites are being compromised right now.
- The flaw is actively exploited by unauthenticated attackers to run code with no login needed, hitting every current version including 2.4.9 and even a fully patched 2.4.6-p15 store, and Adobe has issued no advisory, CVE, or fix as of September 6.
- Attackers slip malicious PHP into a file Magento writes by abusing "styles" in a GraphQL request, then trigger it via a rendered "Payment Transaction Failed Reminder" email; Sansec advises temporarily disabling GraphQL, and checking both var/report and var/log/system.log.
|
🛠️ N-able patches perfect-10 remote code flaw
LINK
|
- N-able has shipped an emergency hotfix for a maximum-severity (CVSS 10/10) remote code execution flaw, tracked as CVE-2026-86218, in its N-central remote monitoring and management platform used by IT teams and managed service providers.
- The bug lets an attacker with no privileges run malicious code on unpatched N-central instances exposed online in easy-to-pull-off attacks; N-able reports no confirmed exploitation in production, though Huntress has flagged it as a potential zero-day.
- N-able fixed the flaw on Saturday with N-central 2026.3 Hotfix 4 and urges on-premises customers to upgrade immediately, since systems running HF3 stay vulnerable, while Shadowserver tracks nearly 1,500 exposed servers, mostly in the US and Europe.
|
|