Why Should I Care? โ 2026-09-03 | ๐ด 1 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 25 RADAR ยท โช 48 FILTERED
๐ Briefing โ 2026-09-03
26 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 0 MEDIUM | ๐ต 25 RADAR | โช 48 FILTERED
๐ด Critical โ action required:
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CVE-2026-9586, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549) โ Yes, if you run any of the affected versions of Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, or SonicWall SMA1000 Appliances: these vulnerabilities can be exploited by attackers to gain unauthorized access or execute commands on your systems.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2026-9586, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549
โ Why Should I Care?
Yes, if you run any of the affected versions of Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, or SonicWall SMA1000 Appliances: these vulnerabilities can be exploited by attackers to gain unauthorized access or execute commands on your systems.
๐ฏ Affected versions: All versions of Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 Appliances mentioned in the advisory
๐ญ In plain English:
These vulnerabilities allow attackers to inject malicious SQL commands, smuggle HTTP requests, execute unauthorized commands, or bypass authentication. For example, an attacker could use an SQL injection vulnerability to steal sensitive data from your database.
๐ง Prerequisites:
- Running an affected version of the software
- Publicly exposed systems
โฑ Urgency: High urgency due to active exploitation and the potential for total control of affected assets.
๐ก Context: The root cause includes insecure coding practices, lack of proper input validation, and insufficient authentication mechanisms.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (25)
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells (BleepingComputer) โ A critical SQL injection flaw in Sangoma Switchvox allows attackers to execute remote code and deploy reverse shells. This affects internet-exposed systems and could compromise your VoIP infrastructure.
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender (The Hacker News) โ A malware campaign is using fake software installers to weaken Windows and Microsoft Defender, primarily targeting Chinese-speaking users and China-based operations of multinational organizations. This can lead to system vulnerabilities and data breaches.
- WordPress backup plugin flaw exposes millions of sites to takeover attacks (BleepingComputer) โ A critical security flaw in the All-in-One WP Migration and Backup plugin for WordPress could let attackers take over your site. This affects millions of sites, and only about 35% have updated to the latest, secure version.
- Dropbox accounts breached through Lenovo email verification flaw (BleepingComputer) โ A security flaw in Lenovo's email verification process allowed unauthorized access to some Dropbox accounts. This means if you use Dropbox and have linked it with a Lenovo ID, your account might have been compromised.
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens (BleepingComputer) โ A critical flaw in JFrog Artifactory allows attackers to create admin tokens, giving them full control over the system. This can lead to the replacement of trusted software packages with malicious ones, affecting downstream systems.
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain (The Hacker News) โ SonicWall has identified and patched two critical vulnerabilities in their SMA 1000 series devices that have been exploited in the wild. These flaws could allow attackers to gain unauthorized access and execute arbitrary commands.
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (The Hacker News) โ A critical vulnerability in Sangoma Switchvox allows attackers to execute code remotely without needing any credentials, potentially compromising your VoIP system and network.
- SonicWall warns of actively exploited SMA1000 zero-day flaws (BleepingComputer) โ SonicWall has identified two zero-day vulnerabilities in their SMA1000 appliances that are being actively exploited by threat actors. These vulnerabilities allow for remote code execution, which means attackers can take control of your devices. For example, if your organization uses SMA1000 appliances for secure remote access, you are at risk of unauthorized access and potential data breaches.
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control (The Hacker News) โ A new Android trojan called StreamRat has been discovered, which can give attackers near-complete control over infected devices. It was spread through fake TV-streaming ads on Meta, targeting Spanish-speaking users.
- BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access (The Hacker News) โ Hackers used a BGP hijack to deliver a malicious update to Virtualizor, compromising root access on some servers. This means if you use Virtualizor or related products, your systems might have been compromised.
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages (The Hacker News) โ A cybercrime group is exploiting Apache modules on Brazilian government and educational web servers to redirect users to gambling sites. This attack could affect any organization using Apache and highlights the need for robust security measures.
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code (The Hacker News) โ Malicious Git configurations can trick AI coding agents into running harmful code on your machine, potentially giving attackers access to your files and resources. This affects multiple AI tools, and some are still unpatched.
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends (The Hacker News) โ Two vulnerabilities in GeoNetwork can be exploited together to allow unauthenticated remote code execution, impacting many government and agency geoportals. This means attackers can execute arbitrary code on your servers without needing any credentials.
- US charges Russian for infecting 80,000 freelancers with malware (BleepingComputer) โ A Russian national has been indicted for infecting 80,000 freelancers with malware through phishing attacks, highlighting the risks of phishing and the importance of securing freelance platforms and user credentials.
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another (The Hacker News) โ Researchers used AI to adapt an existing exploit to new PLC models, showing how AI can help attackers quickly adapt to new targets. This means that if you have vulnerable WAGO PLCs, you're at higher risk of cyberattacks.
โช 48 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV