Threat Analysis: Magento Zero-Day and Liquid Network Heist - What UK SMBs Need to Know

Threats & Attacks

Threat Analysis: Magento Zero-Day and Liquid Network Heist - What UK SMBs Need to Know

This is your Daily Threat Analysis for 7 September 2026.

Unpatched Magento Zero-Day Vulnerability

The Stylesmuggler zero-day vulnerability in all current versions of Magento and Adobe Commerce continues to be exploited actively. This vulnerability enables unauthenticated remote code execution, posing significant risk to e-commerce businesses in the UK and beyond. If leveraging Magento, immediate mitigation strategies should be implemented such as disabling unnecessary services and employing web application firewalls.

The attack, seen since 4th September, operates via injection of PHP code through style properties. Given the widespread use of Magento among UK SMBs for retail operations, this vulnerability could have broad implications. The longer Adobe takes to issue a patch, the greater the risk to affected systems.

Liquid Network $320M Cryptocurrency Heist

A reported $320 million worth of Bitcoin has been drained from Liquid Network, with hackers claiming to return the funds once vulnerabilities are fixed. This dramatic incident underscores the volatility inherent in cryptocurrency markets when security is not prioritized. While the perpetrators claim to be β€˜white hats’, the real story is the persistent vulnerabilities exploitable in blockchain technology.

UK businesses dealing in cryptocurrency must heed this as a stern reminder to implement bitcoin cold storage wallets and strengthen overall cryptocurrency security practices. The threat does not only lie in direct financial loss, but also in reputational damage.

Mathspace Data Breach: Lessons in Data Management

A breach affecting over a million users at Mathspace highlights the critical importance of securing reporting systems like Metabase. While focused primarily on educational platforms, the lessons are universally applicable: secure internal systems diligently, employ strong encryption practices, and ensure third-party vendors comply with robust security standards.

ConnectWise ScreenConnect Vulnerability

ConnectWise reports an unpatched vulnerability in their ScreenConnect tool, used by many UK-based MSPs. Temporary mitigations are available, but the lack of a permanent fix should give pause to any relying on remote management tools in their stack. The NCSC has long advocated for immediate patching and careful vendor selection, a position underscored by this latest incident.

Call to Action

Before the next item: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.

Conclusion

Today’s operational threats, from major software vulnerabilities to cryptocurrency theft, emphasise a critical necessity for vigilance and proactive security measures across all UK businesses, especially SMBs. Stay informed, patch promptly, and always assume you are a target.

Sources

Filed under

  • smb-security
  • cryptocurrency
  • supply-chain-risk
  • uk-business