
SANS Internet Storm Center StormCast: Critical Vulnerabilities in MicroTik Routers, Magento, and N Central
This SANS Internet Storm Center StormCast from September 8th, 2026 covers multiple cybersecurity developments. Perplexity released Numbat, an open-source Go executable tool for macOS, Windows, and Linux that monitors AI agents running on systems, logs their activities, and includes a customizable rule language for alerts and restrictions. A critical vulnerability in MicroTik routers was actively exploited over the weekend, affecting the custom SSH daemon in Router OS that fails to properly verify SSH keys, allowing attackers to spoof keys and gain access to any user account. MicroTik released a patch that includes detection capabilities using a flagged mechanism that checks for compromise on boot, with early attacks adding a user account named ops as an indicator of compromise. A vulnerability called Style Smuggler affecting Magento and Adobe Commerce has been exploited since Friday with no patch available yet, only workarounds and filters. N Central released its fourth hotfix in recent weeks addressing a critical vulnerability that has not yet been exploited.