This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: SonicWall confirmed that threat actors are chaining two previously undisclosed vulnerabilities in its SMA1000 series secure remote access appliances for remote code execution. CVE-2026-83548 is a pre-authentication SSRF (CVSS 10.0) in the Appliance Work Place interface; CVE-2026-83549 is a post-authentication OS command injection (CVSS 7.8) in the Appliance Management Console. The flaws affect models 6210, 7210, and 8200v on specific 12.4.3 and 12.5.0 platform-hotfix builds. SonicWall stated it has investigated a case of active exploitation and released hotfixes 12.4.3-03526 and 12.5.0-02952.

Key takeaway / Actionable note: Immediately upgrade all internet-facing or internal SMA1000 appliances to the latest hotfixes, then re-image, rotate credentials, and reset TOTP tokens if compromise is suspected.

Summary: CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2–3. The list includes the two new SonicWall SMA1000 flaws, an unauthenticated SQL injection leading to RCE in Sangoma Switchvox (CVE-2026-9586), an authentication bypass in JFrog Artifactory that yields admin tokens under default configuration (CVE-2026-82329), and flaws in Kludex Starlette, Kestra OSS, and Berri LiteLLM. Attackers have been observed deploying reverse shells, minting admin tokens, and dropping crypto miners.

Key takeaway / Actionable note: Prioritize patching per BOD 26-04 timelines (most by September 5) and hunt for anomalous admin tokens, reverse shells, and miner activity on exposed Artifactory, Switchvox, and AI infrastructure.

Summary: A coordinated operation by U.S. authorities, CrowdStrike, the Shadowserver Foundation, Europol, and partners in Bulgaria, Hungary, and Romania dismantled the Sality peer-to-peer botnet on August 31–September 1. The Russia-based infrastructure had operated for more than two decades and been linked to more than 11 million infected IP addresses. CrowdStrike manipulated peer lists to isolate bots from the operator while domains hosting payloads were seized.

Key takeaway / Actionable note: Organizations should work with ISPs or Shadowserver notifications to identify and remediate any remaining Sality-infected endpoints.

Summary: The group behind the late-August breach of Manchester Airports Group (operating Manchester, London Stansted, and East Midlands airports) has published the full dataset of approximately 8.7 million customer records after MAG refused to pay a ransom. The data includes email addresses, phone numbers, postcodes, vehicle registrations, and booking information primarily from Wi-Fi sign-ups and car-park/lounge/fast-track services. No payment card details were involved, and airport operations were unaffected.

Key takeaway / Actionable note: Affected individuals and organizations should monitor for secondary phishing and identity-fraud attempts leveraging the newly public travel-related PII.

Summary: Citizen Lab, working with the SHARE Foundation, confirmed that the iPhone of a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware via a zero-click iMessage exploit between December 2025 and January 2026. The infection was identified after an Apple Threat Notification. SHARE Foundation reported at least 14 people in civil society targeted in what it described as the largest documented wave of such surveillance in Serbia.

Key takeaway / Actionable note: Ensure iOS devices are updated to versions that include the relevant iMessage patches and treat Apple Threat Notifications as high-priority indicators requiring forensic review.

Summary: An RMM (remote monitoring and management) phishing campaign that initially appeared focused on Canadian targets via CRA tax-form lures has expanded to 46 countries, with the United States now the top target. The campaign rotates infrastructure daily and delivers malicious RMM tools to gain persistent remote access.

Key takeaway / Actionable note: Block unauthorized RMM tool installations, enforce strict application allow-listing for remote-access software, and train users on tax- and government-themed lures.

Summary: Microsoft reported a malware campaign that uses counterfeit software installers to disable Windows Update services and weaken Microsoft Defender protections, facilitating follow-on payload delivery. The campaign has been observed delivering remote-access trojans.

Key takeaway / Actionable note: Verify installer authenticity through official channels only and monitor for unexpected changes to Windows Update or Defender configuration.

Summary: A high-severity SQL injection vulnerability (CVE-2026-19949) in a popular WordPress migration plugin can be leveraged by unauthenticated attackers to achieve remote code execution and full site takeover. More than three million sites are estimated to be affected.

Key takeaway / Actionable note: Update the affected migration plugin immediately or remove it if unused; audit sites for signs of compromise.

Summary: A dark-web identity-theft service is offering digital scans of more than 153 million U.S. and Canadian driver’s licenses. KrebsOnSecurity linked the material to data collected by a Louisiana-based identity-verification company; the FBI’s New Orleans field office has opened an inquiry.

Key takeaway / Actionable note: Organizations that rely on ID-scan verification should review vendor data-handling practices and monitor for related fraud indicators.

Also Noted:

Bottom line: The past 24 hours underscored the continued high value of edge remote-access appliances and the speed at which newly disclosed flaws move into active exploitation and KEV listings. Organizations should treat the SonicWall SMA1000 hotfixes and the broader CISA KEV additions as emergency priorities, while the Sality disruption and MAG data dump serve as reminders that long-running infrastructure and secondary data abuse remain constant risks.

Reply

Avatar

or to participate