SonicWall has warned that hackers are actively exploiting two new zero-day vulnerabilities in its SMA1000 remote access appliances. The flaws, tracked as CVE-2026-83548 and CVE-2026-83549, can be chained together to carry out remote code execution attacks. The first one affects the Appliance WorkPlace interface; the second impacts the Appliance Management Console and can allow attackers with administrator access to run operating system commands.
Attackers are actively exploiting a serious vulnerability (CVE-2026-9586) in the Sangoma Switchvox business VoIP platform. The flaw allows attackers to access systems without authentication and potentially execute remote code.
Recently patched vulnerabilities in PaperCut, Langflow, and JFrog Artifactory have been actively exploited to steal sensitive data and gain unauthorized access. The targeted flaws include CVE-2026-81578 and CVE-2026-82078 in PaperCut, which can enable authentication bypass and remote code execution, CVE-2026-0768 in Langflow, which is being used to steal credentials, AWS secrets, and OpenAI API keys, and CVE-2026-82329 in JFrog Artifactory, which allows attackers to bypass authentication and create administrator tokens.
Arctic Wolf discovered a large credential attack targeting hundreds of organizations using Fortinet VPNs. The attackers used known usernames and email addresses, causing millions of failed login attempts.
A financially motivated threat actor called BREEZE COMET has been observed targeting Brazilian financial, retail, and eCommerce organizations. The group targets banking and payment systems to carry out fraudulent transfers. The threat actor uses various methods for initial access, including password spraying and impersonating IT support over phone calls to trick employees into installing remote-access tools such as AnyDesk.
Check Point Researchs says that a Chinese-speaking cybercrime group named Gambling Goblin has hacked Brazilian government and educational websites to install malicious Apache modules that redirect visitors to fake pages promoting online gambling and sports betting. The attackers appear to use trusted government websites to manipulate search engine rankings (SEO) and make the gambling pages more visible online.
A China-linked cyber espionage group, known as Fire Ant, has expanded its long-running campaign from VMware environments to Cisco IOS XR routers, TACACS authentication servers and Linux management hosts. The attackers used compromised Cisco routers as network monitoring points, allowing them to capture traffic, collect credentials and hide malicious activity from security teams.
Another suspected Chinese-speaking threat actor has targeted two Philippine organizations, including a nuclear research agency and a marine engineering company that supports the Philippine Navy. The researchers said the attackers exploited known vulnerabilities in internet-facing ownCloud and WordPress systems. The nuclear research organization was targeted through an ownCloud server. The attackers exploited an authentication-bypass flaw (CVE-2023-49105) that could allow access to files without authentication.
Recorded Future’s Insikt Group has uncovered a new cyber-espionge campaign targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The campaigns, active between September 2025 and April 2026, leveraged a previously unknown Windows backdoor called Hookedge. The malware was delivered through malicious Microsoft Word documents designed to look like diplomatic or government-related files.
Russia-aligned threat actor UAC-0099 has used a new technique called GuardBreaker in an attack against a Ukrainian target. The technique is designed to interfere with AI tools that analyze malicious code. Researchers at ESET said the attackers placed text about making a nuclear weapon inside a malicious Visual Basic Script (VBS) as a comment. The text is intended to trigger an AI model’s safety protections, causing it to stop or limit its analysis of the rest of the code.
Microsoft discovered a malware campaign using fake software-download websites to impersonate trusted vendors. The campaign mainly targets Chinese-speaking users and China-based operations of multinational organizations across sectors such as healthcare, manufacturing, technology, and government. Microsoft believes the activity is likely linked to the Chinese Silver Fox threat actor.
In a separate report, Microsoft has detailed a new TerminalFix campaign targeting organizations across multiple industries. The campaign is a variant of the ClickFix technique, but instead of directing victims to the Windows Run dialog, it tricks them into opening Windows Terminal or PowerShell and executing a malicious command.
Hackers compromised the update infrastructure used by Virtualizor, a VPS management tool from Softaculous, and deployed a malicious software update to a small number of servers. The attack took place between August 28 and August 30. The attackers hijacked BGP routes for IP addresses hosted by Hetzner, allowing them to redirect traffic intended for Softaculous's update systems and client portal to malicious servers.
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process. The attackers were able to create fake Lenovo IDs using victims’ email addresses. They then used the Lenovo IDs to sign in to Dropbox accounts linked to the same email addresses without knowing the users’ Dropbox passwords.
METR, a nonprofit that tests advanced AI models, disclosed two security incidents involving attempts by outside threat actors to access its systems without permission. METR said it does not believe any sensitive information was accessed. The attacks have not been linked to any known group and did not involve AI agents breaking into its systems.
Attackers breached Coder’s Cloudflare infrastructure and added unauthorized registry servers. The servers delivered malicious Terraform modules designed to steal users’ credentials and send them to a remote server. A limited number of users may have been affected if they used Coder’s main module registry and updated components while the malicious code was available. Coder currently has no evidence that customer data was compromised.
US authorities have indicted a Russian national accused of running a phishing campaign that infected thousands of freelancers with malware. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and later extradited to the United States. He is accused of targeting about 80,000 freelancers between 2016 and 2017 through an online messaging platform used by a freelance employment company.
According to court documents, Aktulaev used 255 fake accounts to send Microsoft Excel files containing malicious macros. The files installed TVRAT and DarkVNC malware on victims' computers.
In a separate action, international law enforcement agencies and private companies have taken down parts of the Sality malware botnet that has been active for over 20 years. Sality has infected more than 15,000 devices since 2003 and is linked to a cybercriminal group known as SALTY SPIDER, believed to operate from Russia.