SonicWall SMA1000 flaws exploited before disclosure
SonicWall has confirmed two critical vulnerabilities in its SMA1000 remote access appliances, identified as CVE-2026-83548 and CVE-2026-83549, are being exploited in the wild. These flaws can be chained to let attackers run code on affected systems without authentication. Patches are now available, and security agencies have flagged the issues as known exploited vulnerabilities. There is no information about the number of affected customers.
- Both flaws confirmed actively exploited
- CVE-2026-83548 is a critical SSRF vulnerability
- CVE-2026-83549 allows OS command injection
- Flaws can allow unauthenticated remote code execution
- Patches released; exploitation predates disclosure
Sources covering this
How it unfolded
- Infosecurity Magazine Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
- The Hacker News Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- Rapid7 Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
- Dark Reading SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
- CyberScoop Attackers exploit zero-days in consistently besieged SonicWall product
More in Cybersecurity
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
Breeze Comet targets Brazilian financial firms with fraud
A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.
Phishing Campaign Poses as IT Staff on Microsoft Teams
A coordinated phishing operation dubbed 'Spring Ring' targeted more than 150 employees at at least 10 companies between January and April 2026, according to Palo Alto Networks' Unit 42. Attackers used external Microsoft Teams accounts to impersonate IT support, aiming to trick victims into installing remote monitoring or malicious software. Some attacks escalated to attempted NTLM relay attacks against company domain controllers. No successful compromises or losses were reported in the source.
Google fixes Chrome zero-day exploited in the wild
Google released an update to Chrome addressing a critical security flaw, CVE-2026-85046, that has been actively exploited. The vulnerability, found in the V8 JavaScript engine, could let attackers run code by luring users to malicious web pages. The bug was reported by Salvatore Gulizia, who received a $1,000 bounty. Updates are available for Windows, macOS, and Linux. U.S. agencies are required to patch by September 18.