The 48-hour period from September 2-3, 2026 saw intense adversarial activity across multiple attack vectors. Critical zero-day vulnerabilities in SonicWall SMA1000 appliances (CVE-2026-83549, CVE-2026-83548) are under active exploitation for unauthenticated remote code execution, while attackers also exploited flaws in Sangoma Switchvox (CVE-2026-9586) and JFrog Artifactory (CVE-2026-82329) to compromise enterprise infrastructure. The Sality botnet, one of the longest-running malware operations, was successfully disrupted through international law enforcement coordination.
Social engineering attacks have evolved significantly, with the "Spring Ring" campaign leveraging Microsoft Teams external collaboration features to impersonate IT support personnel, gain remote access, and deploy Node.js-based implants for lateral movement. AI-assisted attacks are accelerating threat actor capabilities, with Unit 42 documenting autonomous AI agents breaching enterprise networks in hours rather than days. Meanwhile, 25 ransomware victims were added to leak sites, including critical infrastructure targets like Manchester Airports Group (8.7M customer records exposed) and healthcare provider Policlinico Triestino. A total of 7 Known Exploited Vulnerabilities were added to CISA's catalog, demanding immediate patching across enterprise environments.
The threat landscape shows adversaries successfully weaponizing legitimate collaboration tools, exploiting authentication bypass flaws, and leveraging AI to compress attack timelines. Organizations must prioritize patching critical edge device vulnerabilities, implement external collaboration controls for Teams, and prepare incident response capabilities for AI-accelerated intrusion scenarios.
Multiple critical vulnerabilities in edge devices and enterprise platforms are being actively exploited in the wild, enabling unauthenticated remote code execution and authentication bypass.
SonicWall warned of threat actors chaining two zero-day vulnerabilities in SMA1000 appliances: an OS command injection (CVE-2026-83549) allowing authenticated administrators to execute arbitrary commands, and an SSRF flaw (CVE-2026-83548) enabling unauthenticated attackers to gain unauthorized access to sensitive functionality. Combined exploitation enables full remote code execution on unpatched appliances.
Attackers are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP platform. Single crafted requests enable arbitrary SQL execution against the PostgreSQL backend, including database operations and remote code execution without credentials.
Critical authentication bypass vulnerability in JFrog Artifactory under default configuration allows unauthenticated attackers with network access to forge administrative tokens and obtain full privileged access. Active exploitation observed in attacks targeting enterprise software supply chains.
SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take full control of affected websites. Millions of WordPress installations potentially at risk.
OS command injection vulnerability in Kestra OSS workflow orchestration platform allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials, potentially compromising entire automation pipelines.
International law enforcement successfully dismantled the Sality botnet infrastructure, one of the longest-running malware operations, using the malware's own peer-to-peer architecture against itself.
U.S. and European authorities disrupted the long-running Sality botnet by turning its peer-to-peer architecture against itself, cutting thousands of infected computers off from operators. This represents the takedown of one of the oldest continuously operating botnets, active for over two decades.
Searzhudin Tamirlanovich Aktulaev faces up to 20 years after being extradited from Cyprus to the U.S. for orchestrating a phishing campaign that infected approximately 80,000 freelancers with TVRAT and DarkVNC malware, enabling remote access and credential theft.
New hacktivist group VantaCore has targeted at least seven Russian companies with custom ransomware as part of pro-Ukraine operations. Russian cybersecurity firm F6 reports the group represents an escalation in cyber warfare tactics targeting Russian commercial infrastructure.
Threat actors are leveraging legitimate collaboration platforms and AI capabilities to accelerate attack timelines and bypass traditional security controls through sophisticated social engineering.
Unit 42 investigation reveals attackers using autonomous AI agents to breach an enterprise network in hours rather than days. The attack demonstrates how AI capabilities are compressing reconnaissance, exploitation, and lateral movement timelines, providing threat actors with significant time advantages over defenders.
Microsoft Threat Intelligence documented the 'Spring Ring' operation abusing Microsoft Teams external collaboration to impersonate IT support personnel. Attackers gain initial access via social engineering, obtain remote session access, deploy Node.js-based implants, and move laterally through enterprise networks using legitimate administrative tools.
Tech support scams have evolved significantly beyond traditional fake virus pop-ups. Malwarebytes research reveals scammers are now targeting users across multiple platforms with tailored approaches, including social media, messaging apps, and collaboration tools, making detection more challenging.
Major data breaches affecting millions of individuals across healthcare, transportation, and e-commerce sectors, with significant credential and PII exposure.
Manchester Airports Group disclosed a breach impacting 8.7 million customers of Manchester, Stansted, and East Midlands airports. FulcrumSec hacking group claimed responsibility and published email addresses, phone numbers, browser user agents, IP addresses, names, geographic locations, purchase history, and vehicle registration plates spanning customer data from all three airports.
Healthcare data company Aesto informed federal regulators that sensitive health information for more than 9.5 million people was leaked during a cyberattack in December 2025. The breach represents one of the largest healthcare data exposures of the year.
FBI investigating a potential breach of idscan.net linked to 153 million driver's license scans and millions of additional identification documents now available for purchase on a new dark web marketplace. Represents massive identity theft and fraud risk.
Dropbox warning users that unauthorized parties accessed accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. The authentication bypass enabled account takeovers without legitimate credentials.
Aurora ransomware group published 13 years (2013-2026) of Chip 1 Exchange corporate data including 40+ passport photographs, I-9 forms with SSNs, and extensive employee PII from the global electronics distributor.
PayoutsKing ransomware group added Proliance Surgeons, a large physician-owned surgical group operating across Washington State with hundreds of independent surgeons. Healthcare data breach likely includes extensive patient and provider information.
Global IT services company Seasia Infotech (25+ years in business, 50,000+ projects across 36 countries) compromised by TheGentlemen ransomware group. Breach potentially exposes client data from 500+ enterprise customers.
Hackers gained access to payment accounts used by two Russian fundraising projects (Davayte) supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. Unknown threat actor targeted humanitarian fundraising infrastructure.
Continued Mirai botnet infrastructure activity with multiple command-and-control servers distributing variants targeting IoT devices across multiple architectures.
URLhaus identified extensive Mirai malware distribution infrastructure across IPs 176.65.139.218, 94.154.43.118, 176.65.139.206, 176.65.139.247, 94.154.43.107, and 94.154.43.120. Servers hosting multi-architecture ELF binaries (ARM, MIPS, x86, PPC, SH4, ARC, MPSL) and shell scripts for automated infection of IoT devices.
Botnet domain brightroseax.blog and subdomain mail.brightroseax.blog actively serving Mirai ELF binaries across multiple architectures including ARM, RISCV64, and S390X for IoT device compromise campaigns.
Critical vulnerabilities in widely deployed software packages and platforms requiring immediate patching.
Cisco released comprehensive security hardening update addressing multiple internally discovered critical vulnerabilities in IOS XR Software. CVE-2026-20279 and CVE-2026-20274 both rated 9.8 CVSS, enabling unauthenticated remote code execution. Proactive internal security review identified flaws before exploitation.
Vulnerability in Silicon One integration for Cisco Nexus 9000 Series Switches allows unauthenticated remote attackers to execute code with root privileges. TCP ports 43210 and 43211 accessible in default Layer 3 virtual routing configuration, enabling network-based exploitation without authentication.
DSpace repository software versions 8.0-rc1 through 8.4, 9.0-rc1 through 9.3, and 10-rc1 vulnerable to RCE via Velocity Templates used for COAR Notify/LDN messages. CVSS 8.0 HIGH severity flaw enables arbitrary code execution in widely deployed academic repository platform.
BerriAI LiteLLM contains improper authentication vulnerability in MCP Streamable HTTP endpoint allowing unauthenticated attackers to establish authenticated MCP sessions using arbitrary Bearer tokens. Affects AI/LLM proxy infrastructure.
Cybersecurity incidents affecting critical infrastructure and healthcare operations.
Luminis Health confirmed cybersecurity incident affecting systems across its organization. Health system stated priority remains providing safe, high-quality patient care despite ongoing security incident affecting IT infrastructure.
DoD confirmed refrigeration outages at 14 commissaries on military bases across the continental U.S. While the cause remains officially unconfirmed, the simultaneous nature of failures across multiple facilities raised suspicions of potential cyberattack targeting critical infrastructure supporting military families.
Microsoft investigating issue causing Defender for Office 365 to mistakenly flag and block access to legitimate Google search result links. Widespread false positive detections disrupting normal business operations for enterprise customers.
Critical vulnerabilities in web browsers and client applications requiring immediate patching.
Google released emergency Chrome updates addressing two critical vulnerabilities that could allow malicious websites to execute arbitrary code on visitor devices. Users urged to update immediately to prevent exploitation.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.