Cyber Threat Brief
Avsnitt

2026-09-02: SonicWall disclosed two SMA1000 zero-days (CVSS 10 and 7.8) exploited in the wild, patch immediately

Dela

Show Notes - 2026-09-02

Stories Covered: - Today: - SonicWall SMA1000 Dual Zero-Day Exploitation (CVE-2026-83548, CVE-2026-83549) (https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/) - Langflow RCE Under Sustained Exploitation (CVE-2026-0768, CVE-2026-0769, CVE-2026-5027) (https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/) - JFrog Artifactory Authentication Bypass Exploited (CVE-2026-82329) (https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure) - Sangoma Switchvox Unauthenticated SQLi to RCE (CVE-2026-9586) (https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html) - The Gentlemen Claim Nutex Health Breach (https://www.securityweek.com/ransomware-gang-claims-nutex-health-data-breach/) - Insider Recruitment Accelerating for Ransomware Groups (https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within) - BGP Hijack Delivers Malicious Virtualizor Updates (https://news.risky.biz/risky-bulletin-bgp-hijack-targets-virtualizor-to-deliver-malicious-updates/) - GeoNetwork Unauthenticated RCE Chain (CVE-2026-63219 + CVE-2026-58400) (https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html) - FBI Warns of OAuth Consent Phishing Campaign (https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/) - Silver Fox Counterfeit Installer Campaign Targeting Chinese Operations (https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/) - 153M+ Driver's Licenses for Sale on Dark Web (https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/) - Rockwell Automation ICS Advisory Batch (https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04) - Sality Botnet Disrupted by International Law Enforcement (https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html) - Iranian Nimbus Manticore Deploying Cross-Platform RATs via Fake Coding Tests (https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html) - METR Discloses Two Security Incidents (https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing) - Chrome 152 and Firefox 155 Security Updates (https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/) - Malicious Packagist Packages Targeting iOS Devices (https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html)

CVEs Referenced: CVE-2021-42260, CVE-2025-12768, CVE-2025-31277, CVE-2025-3248, CVE-2025-43529, CVE-2026-0768, CVE-2026-0769, CVE-2026-12661, CVE-2026-16675, CVE-2026-5027, CVE-2026-58400, CVE-2026-63219, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549, CVE-2026-84352, CVE-2026-84353, CVE-2026-9586, CVE-2026-9621, CVE-2026-9633

Indicators of Compromise: Domains: 148[.]184., gehie246[.]com, yimxg25tiy[.]com, cc8ttkv35b[.]com, n7b8t85zsg[.]com, azurewebsites[.]net, azurewebsites[.]net., cloudfareintcdn[.]com. IPs: 8.4.0.2

Full brief: https://carolinacleartech.com/brief/2026-09-02/

Podden och tillhörande omslagsbild på den här sidan tillhör Carolina Clear Tech, LLC. Innehållet i podden är skapat av Carolina Clear Tech, LLC och inte av, eller tillsammans med, Poddtoppen.