Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 2, 2026

SonicWall confirmed active exploitation of a zero-day chain—CVE-2026-83548, an SSRF-to-command-injection flaw in the WorkPlace interface, and CVE-2026-83549, a command injection in the Management Console—against SMA1000 6210, 7210, and 8200v appliances; the vendor shipped a hotfix and advises re-imaging, credential rotation, and TOTP reset where IOCs are detected, though it has not yet published those IOCs. In parallel, Horizon3.ai and SRA Labs observed in-the-wild exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox 8.3 yielding PostgreSQL superuser code execution; the patch shipped July 14, six weeks before the first observed attacks on August 30, and roughly 4,000 instances remain internet-exposed.

Compiled by the Slugnet Editorial System. Published Sep 2, 2026, 7:27 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    BleepingComputer

    SonicWall warns of actively exploited SMA1000 zero-day flaws

    What happened

    SonicWall disclosed that threat actors are actively chaining two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, to execute remote code on SMA1000 appliances. The attack exploits a server-side request forgery flaw in the WorkPlace interface and a command injection vulnerability in the Management Console to gain unauthorized control over the devices.

    Why it ranks #1

    SonicWall disclosed that threat actors are actively chaining two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, to execute remote code on SMA1000 appliances by exploiting a server-side request forgery flaw in the WorkPlace interface and a command injection vulnerability in the Management Console.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise are detected.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

    What happened

    Threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3, to execute arbitrary code as the PostgreSQL superuser. The flaw, which allows attackers to bypass authentication and deploy reverse shells, was patched in Switchvox 8.4.0.2 on July 14, 2026, with in-the-wild exploitation attempts observed beginning August 30.

    Why it ranks #2

    Threat actors actively exploit CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox, to execute arbitrary code and deploy reverse shells without credentials.

    Who should care

    CISOs and security leaders

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Hackers abuse Faronics Deploy admin tool to install ScreenConnect

    What happened

    Huntress identified a campaign where threat actors abused the legitimate Faronics Deploy platform to enroll victim endpoints in attacker-controlled deployments, subsequently using PowerShell to install ConnectWise ScreenConnect for persistent remote access. The activity, which targeted over 457 endpoints between July 21 and August 20, relied on phishing lures disguised as business documents to trick users into executing the signed Faronics installer. Faronics confirmed the abuse and implemented anti-abuse measures that caused the malicious activity to drop significantly starting August 21.

    Why it ranks #3

    Huntress identified a campaign in which threat actors abused the legitimate Faronics Deploy platform to enroll over 457 victim endpoints in attacker-controlled deployments between July 21 and August 20, subsequently using PowerShell to install ConnectWise ScreenConnect for persistent remote access.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Inspect ScreenConnect installations in atypical locations to identify unauthorized deployments.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Krebs on Security

    FBI Probes Service Selling 153M+ Drivers Licenses

    What happened

    The FBI's New Orleans field office opened an official investigation into an apparent breach at idscan.net, a Louisiana-based identity verification provider. A dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian driver's licenses, which the FBI is linking to the idscan.net incident.

    Why it ranks #4

    The FBI's New Orleans field office opened an official investigation into an apparent breach at idscan.net after linking the incident to a dark web service selling digital scans of over 153 million U.S. and Canadian driver's licenses.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    National Life Group CISO expects more vulnerabilities in six months than in thirty years

    What happened

    National Life Group CISO Becky Palmer stated that the introduction of Frontier AI will likely uncover more vulnerabilities in the next six months than in the previous thirty years. She explained that AI accelerates the discovery and weaponization of flaws, reducing attack timelines from weeks to hours and outpacing traditional human-speed patching processes.

    Why it ranks #5

    National Life Group CISO Becky Palmer stated that Frontier AI will likely uncover more vulnerabilities in six months than in the previous thirty years, accelerating flaw discovery and weaponization.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    low
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

    What happened

    Forescout researchers used Anthropic's Claude to port a pre-authentication remote code execution exploit from one WAGO PLC model to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server, which Siemens has stated has no planned remediation for Nucleus NET.

    Why it ranks #6

    Forescout researchers used Anthropic's Claude to port a pre-authentication remote code execution exploit targeting CVE-2021-31886 from one WAGO PLC model to another, successfully executing attacker-supplied ARM shellcode on live hardware.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line

    What happened

    Vali Cyber released ZeroLock 5, a hypervisor security update that extends multi-factor authentication to the command line to govern file access, program execution, and network operations on ESX and Linux hosts. The vendor stated the release addresses the risk of stolen credentials and insider threats, citing the ShinyHunters group's development of a ransomware platform that exploits compromised SSH keys to encrypt VMware environments.

    Why it ranks #7

    Vali Cyber released ZeroLock 5, a hypervisor security update that extends multi-factor authentication to the command line to govern file access, program execution, and network operations on ESX and Linux hosts, addressing the risk of stolen credentials and insider threats.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    What happened

    Google Threat Intelligence Group and Mandiant identified Breeze Comet, a financially motivated threat actor active since 2024, for executing hundreds of fraudulent transactions through Brazilian payment systems including Pix, STR, and Boleto. The group gains initial access via password spraying, social engineering, or vulnerable JBoss servers, then deploys custom malware like COBALTSPIN to establish persistent access and clear forensic logs.

    Why it ranks #8

    Google Threat Intelligence Group and Mandiant identified Breeze Comet, a financially motivated threat actor active since 2024, for executing hundreds of fraudulent transactions through Brazilian payment systems including Pix, STR, and Boleto.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

    What happened

    GeoNetwork released version 4.4.12 and 4.2.17 to fix an unauthenticated remote code execution chain involving a missing authorization check on the formatter upload endpoint and an unsafe Saxon XSLT processor configuration. The vulnerability allows attackers to upload malicious stylesheets that execute operating system commands when triggered by a standard GET request to a public record.

    Why it ranks #9

    GeoNetwork patched an unauthenticated remote code execution chain in versions 4.4.12 and 4.2.17, allowing attackers to upload malicious stylesheets that execute operating system commands via standard GET requests.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    Keepnet launches free SMS/Call Reporter for iOS

    What happened

    Keepnet released a free iOS application that allows users to report suspicious SMS messages and phone calls directly to security teams. The tool integrates these mobile-channel reports into the same incident pipeline used for email phishing, addressing a visibility gap where voice and text-based social engineering attempts previously lacked a standardized corporate reporting workflow.

    Why it ranks #10

    Keepnet released a free iOS app enabling users to report suspicious SMS and calls directly into corporate incident pipelines, standardizing mobile social engineering reporting.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email