StyleSmuggler compromise count forces Magento incident responseKiteworks restart does not close the Advanced Forms questionCarbonato turns exposed Docker hosts into AI-assisted operator consolesDC health-data exposure puts publication controls under review
Reporting that more than 3,800 online stores were compromised materially raises the response standard for an already exploited Adobe Commerce and Magento flaw: verify the hotfix, hunt every node and rotate credentials where compromise cannot be excluded.
Security.io Intelligence Desk · Tuesday, 29 September 2026
Executive consequence
CVE-2026-75650 was already known and patched, but the material development is reporting that compromise spread to more than 3,800 stores. Security leaders should separate hotfix status from compromise status, preserve evidence and rotate exposed secrets where forensic assurance is incomplete.
Decision today
Inventory every Adobe Commerce and Magento Open Source instance, including dormant storefronts and managed environments.
Kiteworks says its shutdown was preventative and reports no indication of compromise, while reporting identifies a severe vulnerability confined to Advanced Forms.
Do today
Identify all Kiteworks deployments and whether Advanced Forms is enabled.
Carbonato compromises Docker hosts exposed without authentication on port 2375, establishes conventional persistence and installs Hermes Agent under a hostile GH0ST persona.
Do today
Block unauthenticated network access to Docker daemon APIs, especially TCP port 2375.
DHCF says two public reports contained hidden beneficiary information that may have been reachable without permission. The decision is to preserve evidence, test similar publishing workflows and avoid characterising potential exposure as confirmed theft until access or misuse is established.
Do today
Identify public reports, dashboards and files containing embedded or hidden source data.
The jury found more than 43 million state-law violations, but the judge has not set penalties or final injunctive relief. Security and privacy leaders should treat unsupported assurances and incomplete third-party oversight as board-level evidence risks.
Do today
Map material privacy statements to current technical and governance evidence.
Security.io 0–100 editorial scores. Exposure combines deployed footprint and internet reach; Urgency combines active exploitation and remediation time; Business Consequence combines compromise depth, data sensitivity and revenue impact. These are editorial scores, not externally reported measurements. Source: Security.io editorial assessment informed by Adobe, Sansec and independent reporting.
Back page
Daily comic · Circuit Chuckles
A brief pause after the intelligence
Penetration Test
Rusty declares a penetration test complete after attacking a locked cabinet with a pen, then reports the bent pen as a valuable finding.