This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: SonicWall confirmed that threat actors are chaining two new zero-day vulnerabilities in its SMA1000 series secure remote access appliances for remote code execution. CVE-2026-83548 is a pre-authentication SSRF in the Appliance WorkPlace interface (CVSS 10.0), while CVE-2026-83549 is a command-injection flaw in the Appliance Management Console that can be reached after the first. The flaws affect SMA1000 6210, 7210, and 8200v models; SonicWall has released hotfixes and strongly urges immediate upgrades, password resets, and TOTP token resets if compromise is suspected. Shadowserver tracks more than 400 internet-exposed SMA1000 appliances.

Key takeaway / Actionable note: Treat all internet-facing SMA1000 appliances as high priority—apply the hotfix release immediately and assume potential compromise if the devices were exposed.

Summary: Aesto Health (Aesto LLC), a healthcare data-migration and archiving provider, reported to HHS that a December 2025 intrusion into a limited portion of its AWS infrastructure affected 9,540,683 individuals. The company confirmed unauthorized access between December 2–18, 2025; exposed data included names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance details, taxpayer IDs, other government IDs, and Social Security numbers for a subset of individuals. Notifications to covered-entity clients began in June 2026; individuals are now being notified and offered identity-protection services.

Key takeaway / Actionable note: Healthcare organizations relying on third-party data-migration or archiving vendors should verify incident-response status and review contractual notification and audit rights.

Summary: Threat actors are actively exploiting the unauthenticated remote-code-execution vulnerability CVE-2026-0768 (CVSS 9.8) in the open-source Langflow AI application framework. Attackers are querying environment variables to harvest LANGFLOW_SUPERUSER credentials, OpenAI API keys, AWS access/secret keys, the secret_key file, and SSH access. VulnCheck observed hundreds of exploitation attempts, primarily originating from Russia and hitting UK canaries. The flaw was disclosed earlier in 2026 and affects versions up to 1.4.2; patched releases are available.

Key takeaway / Actionable note: Immediately patch or isolate any internet-exposed Langflow instances and rotate all API keys and cloud credentials that may have been present in the environment.

Summary: Two zero-day vulnerabilities in PaperCut NG and MF (CVE-2026-81578 improper access control and CVE-2026-82078 unsafe dynamic class loading) that were patched last week are now being abused for data theft. Attackers chain the flaws for unauthenticated authentication bypass and remote code execution, then dump database tables. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog. PaperCut has issued a third emergency patch set that supersedes the prior two and adds further hardening.

Key takeaway / Actionable note: Apply the latest PaperCut emergency release (Release 3) to all Application Servers, especially internet-facing ones, and monitor for unauthorized database queries or remote-access tool installation.

Summary: Threat actors are exploiting CVE-2026-9586, a critical unauthenticated SQL-injection vulnerability (CVSS 9.3) in Sangoma Switchvox SMB Edition 8.3 that allows remote code execution as the PostgreSQL superuser. The flaw resides in the unauthenticated /pa endpoint that processes PolycomIPPhone XML and concatenates the PhoneIP value into SQL without sanitization. Horizon3 and others have observed active exploitation attempts deploying reverse shells; approximately 4,000 instances remain exposed. Sangoma patched the issue in Switchvox 8.4.0.2 in July 2026.

Key takeaway / Actionable note: Upgrade Switchvox SMB Edition to 8.4.0.2 or later immediately and restrict the /pa endpoint from untrusted networks.

Summary: A new dark-web identity-theft service called Nexus is offering digital scans of more than 153 million U.S. and Canadian drivers licenses plus millions of additional ID documents. Krebs on Security traced the images—many containing infrared and ultraviolet scans with timestamps—to identity-verification technology used by customers of Louisiana-based idscan.net (clients include Hertz, Target, FedEx, and marijuana dispensaries). The FBI’s New Orleans field office opened an official investigation after the service was advertised on the Exploit forum; the Nexus site later went offline.

Key takeaway / Actionable note: Organizations that collect or scan drivers licenses should review third-party verification vendors’ security practices and retention policies; individuals should monitor for identity-fraud indicators.

Summary: U.S., Bulgarian, Hungarian, and Romanian authorities, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet. The operation used peer-list sinkholing to isolate infected machines from the operator’s control channel and seized payload domains. Sality had been active for more than two decades and recently primarily distributed the EggJagger clipjacking malware used to steal cryptocurrency.

Key takeaway / Actionable note: Organizations should check for residual Sality infections (file infectors on executables and removable media) and ensure endpoint detection covers legacy P2P botnet indicators.

Summary: A California federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev for a 2016–2017 phishing campaign that used 255 fake accounts on a freelance platform to send malicious Excel macros to approximately 80,000 users. The macros installed TVRAT and DarkVNC, giving remote control via TeamViewer and VNC. Aktulaev was extradited from Cyprus and is in U.S. custody.

Key takeaway / Actionable note: Reinforce macro-blocking and application allow-listing policies for email attachments, particularly in environments that frequently handle freelance or contractor communications.

Summary: Nutex Health disclosed in an SEC filing that an unauthorized party accessed and exfiltrated patient, employee, credentialed-provider, business, and financial information from its servers and threatened to publish it. The Gentlemen ransomware group listed the company on its leak site. Nutex operates micro-hospitals and outpatient facilities across multiple states and is notifying affected individuals while continuing its investigation.

Key takeaway / Actionable note: Healthcare operators should accelerate monitoring for extortion-group leak-site postings and ensure rapid patient-notification workflows are tested.

Also Noted:

Bottom line: The past 24 hours were dominated by actively exploited edge and application flaws—SonicWall SMA1000, PaperCut, Langflow, and Switchvox—underscoring the urgency of rapid patching for internet-facing systems. Parallel large-scale data exposures in healthcare and identity-verification infrastructure continue to expand the attack surface for identity fraud and secondary extortion. Prioritize internet-facing VPN/remote-access appliances, print-management servers, and AI gateways today.

Reply

Avatar

or to participate