Show Notes - 2026-09-02
Stories Covered:
- Today:
- SonicWall SMA1000 Dual Zero-Day Exploitation (CVE-2026-83548, CVE-2026-83549) (https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/)
- Langflow RCE Under Sustained Exploitation (CVE-2026-0768, CVE-2026-0769, CVE-2026-5027) (https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/)
- JFrog Artifactory Authentication Bypass Exploited (CVE-2026-82329) (https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure)
- Sangoma Switchvox Unauthenticated SQLi to RCE (CVE-2026-9586) (https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html)
- The Gentlemen Claim Nutex Health Breach (https://www.securityweek.com/ransomware-gang-claims-nutex-health-data-breach/)
- Insider Recruitment Accelerating for Ransomware Groups (https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within)
- BGP Hijack Delivers Malicious Virtualizor Updates (https://news.risky.biz/risky-bulletin-bgp-hijack-targets-virtualizor-to-deliver-malicious-updates/)
- GeoNetwork Unauthenticated RCE Chain (CVE-2026-63219 + CVE-2026-58400) (https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html)
- FBI Warns of OAuth Consent Phishing Campaign (https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/)
- Silver Fox Counterfeit Installer Campaign Targeting Chinese Operations (https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/)
- 153M+ Driver's Licenses for Sale on Dark Web (https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/)
- Rockwell Automation ICS Advisory Batch (https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04)
- Sality Botnet Disrupted by International Law Enforcement (https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html)
- Iranian Nimbus Manticore Deploying Cross-Platform RATs via Fake Coding Tests (https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html)
- METR Discloses Two Security Incidents (https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing)
- Chrome 152 and Firefox 155 Security Updates (https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/)
- Malicious Packagist Packages Targeting iOS Devices (https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html)
CVEs Referenced:
CVE-2021-42260, CVE-2025-12768, CVE-2025-31277, CVE-2025-3248, CVE-2025-43529, CVE-2026-0768, CVE-2026-0769, CVE-2026-12661, CVE-2026-16675, CVE-2026-5027, CVE-2026-58400, CVE-2026-63219, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549, CVE-2026-84352, CVE-2026-84353, CVE-2026-9586, CVE-2026-9621, CVE-2026-9633
Indicators of Compromise:
Domains: 148[.]184., gehie246[.]com, yimxg25tiy[.]com, cc8ttkv35b[.]com, n7b8t85zsg[.]com, azurewebsites[.]net, azurewebsites[.]net., cloudfareintcdn[.]com.
IPs: 8.4.0.2
Full brief: https://carolinacleartech.com/brief/2026-09-02/