Ticker feed
CISA added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026, giving federal agencies just three days to act. SonicWall disclosed both as zero-days after finding them under active exploitation.
CVE-2026-83548 (CVSS 10.0, Critical) is a pre-authentication SSRF flaw in the Appliance Work Place interface. CVE-2026-83549 (CVSS 7.8, High) is an OS command injection in the Appliance Management Console that normally requires admin authentication. Chained, the SSRF supplies that access — turning the pair into unauthenticated remote code execution.
SonicWall says it has seen exploitation of both, which points to chaining, and that no public proof-of-concept exists. Affected models are the 6210, 7210, and 8200v; the fix is hotfix 12.4.3-03526 or 12.5.0-02952 and higher.
SMA1000 appliances handle enterprise remote access, making them high-value targets. CISA has flagged both under Binding Operational Directive 26-04, requiring forensic triage — not just patching. Audit admin activity, check for new accounts, and review outbound connections. If you find signs of compromise, SonicWall says to re-image, rotate all passwords, and reset TOTP tokens.
Source: Cybersecurity News
CISA added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026, giving federal agencies just three days to act. SonicWall disclosed both as zero-days after finding them under active exploitation.
CVE-2026-83548 (CVSS 10.0, Critical) is a pre-authentication SSRF flaw in the Appliance Work Place interface. CVE-2026-83549 (CVSS 7.8, High) is an OS command injection in the Appliance Management Console that normally requires admin authentication. Chained, the SSRF supplies that access — turning the pair into unauthenticated remote code execution.
SonicWall says it has seen exploitation of both, which points to chaining, and that no public proof-of-concept exists. Affected models are the 6210, 7210, and 8200v; the fix is hotfix 12.4.3-03526 or 12.5.0-02952 and higher.
SMA1000 appliances handle enterprise remote access, making them high-value targets. CISA has flagged both under Binding Operational Directive 26-04, requiring forensic triage — not just patching. Audit admin activity, check for new accounts, and review outbound connections. If you find signs of compromise, SonicWall says to re-image, rotate all passwords, and reset TOTP tokens.
Source: Cybersecurity News
8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.
HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.
Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.
FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.
Source: BBC News
8.7 million people are at risk after hackers breached Manchester Airports Group (MAG) — operator of Manchester, Stansted, and East Midlands airports — and published the stolen data for free. FulcrumSec extorted MAG for an undisclosed sum, failed to get paid, and dumped half a terabyte in response: "every byte of it is pure PII," the gang wrote.
HaveIBeenPwned indexed the dump within a day — names, emails, phone numbers, IP addresses, and 108,000 vehicle plates among them. Unlike most leak sites, this one sits on the open internet rather than the dark web, so anyone can reach it.
Security researcher Kevin Beaumont warned that wealthy or high-profile people face particular risk: the files map where customers have been and where they're going next, including some 190,000 upcoming bookings. MAG says it contacted those travelers separately. Everyone else should expect scammers who know their phone number and car registration.
FulcrumSec says it got in the same way it hit Arup and Novo Nordisk: admin keys to Iterable, MAG's marketing platform, left in the airport websites' JavaScript. "Any of the millions of visitors to the site could have right-clicked 'inspect' and seen the keys," the gang wrote. MAG hasn't confirmed it.
Source: BBC News
A hacking group linked to Silver Fox (also known as Yinhu) is running a campaign that tricks users into downloading fake installers disguised as Razer, Microsoft Edge, Kaspersky, and other trusted tools. The sites look legitimate — until you open the ZIP file. Microsoft says the payload changes on every download, so hashes shift while filenames stay put.
Once installed, the malware doesn't switch Microsoft Defender off — it uses short-lived SYSTEM scheduled tasks to write sweeping scan exclusions, then deletes the tasks to cover its tracks. It also deletes shadow copies, stops Windows Update, and sets up recurring tasks that restart malicious code every 60 seconds.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, most of them the China-based operations of multinational organizations, or Chinese-speaking users. Microsoft assesses with moderate confidence that the activity is consistent with the reported Silver Fox campaign, and has stopped short of attributing it to a nation-state.
Turn on Tamper Protection — Microsoft says it blocks Defender exclusion and registry writes even when the payload is running as SYSTEM, which is exactly what this campaign depends on. And always download software directly from official publishers.
Source: Cybersecurity News
A hacking group linked to Silver Fox (also known as Yinhu) is running a campaign that tricks users into downloading fake installers disguised as Razer, Microsoft Edge, Kaspersky, and other trusted tools. The sites look legitimate — until you open the ZIP file. Microsoft says the payload changes on every download, so hashes shift while filenames stay put.
Once installed, the malware doesn't switch Microsoft Defender off — it uses short-lived SYSTEM scheduled tasks to write sweeping scan exclusions, then deletes the tasks to cover its tracks. It also deletes shadow copies, stops Windows Update, and sets up recurring tasks that restart malicious code every 60 seconds.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, most of them the China-based operations of multinational organizations, or Chinese-speaking users. Microsoft assesses with moderate confidence that the activity is consistent with the reported Silver Fox campaign, and has stopped short of attributing it to a nation-state.
Turn on Tamper Protection — Microsoft says it blocks Defender exclusion and registry writes even when the payload is running as SYSTEM, which is exactly what this campaign depends on. And always download software directly from official publishers.
Source: Cybersecurity News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
Chick-fil-A began notifying customers across 11 jurisdictions in late July after a credential-stuffing attack on its loyalty program between June 17 and 19. Thieves used usernames and passwords stolen from a third-party source to break into Chick-fil-A One accounts through the website and app. The company had concluded on July 13 that data may have been accessed.
Data that may have been accessed includes names, email addresses, membership numbers, Mobile Pay numbers, partial payment card digits, gift card balances, and QR codes. Customers who had saved more to their accounts may also have had their birth month and day, phone number, and address accessed.
Chick-fil-A calls it a limited number of accounts and hasn't given a total; filings show 2,182 in Texas and 39 in Massachusetts. It's the second credential-stuffing hit on Chick-fil-A One — an earlier one in 2023 reached more than 71,000 customers.
The company logged out affected users, removed stored payment methods, restored balances, and added rewards as compensation. Customers should reset their passwords and make them unique — reuse is what credential stuffing runs on — then check account activity. A law firm has been investigating a possible class action since early August.
Source: CBS News
A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.
If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.
Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.
Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.
Source: Cybersecurity News
A researcher known as MSNightmare — also tracked as Nightmare Eclipse and Chaotic Eclipse — has published a proof-of-concept called HardBreacher, claiming a local privilege-escalation zero-day in Kaspersky Endpoint Security on fully patched Windows 11 (version 25H2), running product version 14.0.0.504.
If real, a low-privileged user could write a DLL to System32 — normally off-limits — and seize a Kaspersky UI process, letting them stop the product, override its allow-or-block decisions, and destabilize the operating system. The researcher's previous drops have a mixed record: some stayed proof-of-concept, others ended up in active attacks.
Kaspersky says it has already addressed the issue, with the fix delivered through an automatic update — users can also trigger a database update manually. No CVE has been assigned. The PoC is unstable, error-prone, and requires multiple attempts.
Organizations should confirm their Kaspersky databases are current, review process telemetry, and avoid running the public code on production systems.
Source: Cybersecurity News
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Norcross, Georgia is dealing with the fallout from a ransomware attack that hit some of the city's computer systems on August 1. Officials didn't go public until August 28 — nearly four weeks later — saying they responded as soon as the incident was detected, bringing in cybersecurity experts and notifying law enforcement.
Most city systems are back up and running, but some disruptions may continue as restoration work wraps up. The city is also rolling out new security measures.
Details are still limited given the ongoing investigation. Norcross hasn't said whether any resident or employee data was taken, nobody has claimed the attack, and the city hasn't disclosed a ransom demand. It says it will share more as things develop.
Source: CBS News Atlanta
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Healthcare giant McKesson confirmed hackers stole customer data after discovering a breach on August 25. Attackers had been pulling data since the 21st. The company, which delivers roughly one-third of North American prescription medicines, said unauthorized access affected its Oncology & Multispecialty and Medical-Surgical business units — though it hasn't disclosed how many people were impacted.
The ShinyHunters extortion group is claiming responsibility, alleging they stole 284 million customer records including medical histories, prescriptions, billing data, and employee files. The group has since conceded that figure counts rows of raw data, not individual people, and that it hasn't finished going through what it took.
They're demanding around $55 million and threatening to publish everything unless McKesson opens payment negotiations by September 1 — that deadline expires today. McKesson hasn't engaged, says its services remain operational, and still hasn't determined how much data was taken. None of ShinyHunters' claims have been verified.
Source: SecurityWeek
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News
The Bureau of Alcohol, Tobacco, Firearms, and Explosives confirmed on Wednesday, August 26, 2026, that a cyberattack hit a standalone system containing information about its investigation targets. Senior Justice Department officials have designated the compromise a major incident under federal guidelines.
The agency says it was contained: the standalone system was not connected to any other ATF systems — including case management, laboratory, and eForms systems — and it was shut down as soon as it was discovered. ATF says its operations remain fully functional.
The Russian-speaking ransomware group Qilin claimed responsibility by adding ATF to its leak site, but published no samples and gave no indication of what or how much it took.
ATF declined to comment on Qilin's alleged involvement or say when the attack occurred. Qilin has claimed hundreds of victims across more than 60 countries since 2022, and was among the five most-reported ransomware variants in complaints to the FBI's Internet Crime Complaint Center in 2025.
Source: CyberScoop
The Bureau of Alcohol, Tobacco, Firearms, and Explosives confirmed on Wednesday, August 26, 2026, that a cyberattack hit a standalone system containing information about its investigation targets. Senior Justice Department officials have designated the compromise a major incident under federal guidelines.
The agency says it was contained: the standalone system was not connected to any other ATF systems — including case management, laboratory, and eForms systems — and it was shut down as soon as it was discovered. ATF says its operations remain fully functional.
The Russian-speaking ransomware group Qilin claimed responsibility by adding ATF to its leak site, but published no samples and gave no indication of what or how much it took.
ATF declined to comment on Qilin's alleged involvement or say when the attack occurred. Qilin has claimed hundreds of victims across more than 60 countries since 2022, and was among the five most-reported ransomware variants in complaints to the FBI's Internet Crime Complaint Center in 2025.
Source: CyberScoop
Microsoft has confirmed a critical remote code execution vulnerability in Entra ID, its cloud identity platform used across Microsoft 365, Azure, and thousands of third-party apps. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 — the maximum possible — and stems from a deserialization bug that let attackers run arbitrary code remotely, with no login required.
Microsoft disclosed it on August 20, 2026, with the advisory's exploitation flag set to "Yes." A day later the company flipped that flag to "No," and has not explained why. No exploitation has ever been confirmed, and the flaw was found by one of Microsoft's own security engineers.
Because Entra ID is a managed cloud service, Microsoft patched it server-side; the company says the issue is fully mitigated and there is no action for customers to take. What it hasn't said is how long the service was vulnerable, whether any tenant data was reached, or why the exploitation flag changed.
With exploitation unconfirmed, there's no incident to respond to — but the audit is easy to do. Review Entra ID sign-in logs, conditional access policies, and privileged role assignments for anything anomalous predating the fix.
Source: Cybersecurity News
Microsoft has confirmed a critical remote code execution vulnerability in Entra ID, its cloud identity platform used across Microsoft 365, Azure, and thousands of third-party apps. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 — the maximum possible — and stems from a deserialization bug that let attackers run arbitrary code remotely, with no login required.
Microsoft disclosed it on August 20, 2026, with the advisory's exploitation flag set to "Yes." A day later the company flipped that flag to "No," and has not explained why. No exploitation has ever been confirmed, and the flaw was found by one of Microsoft's own security engineers.
Because Entra ID is a managed cloud service, Microsoft patched it server-side; the company says the issue is fully mitigated and there is no action for customers to take. What it hasn't said is how long the service was vulnerable, whether any tenant data was reached, or why the exploitation flag changed.
With exploitation unconfirmed, there's no incident to respond to — but the audit is easy to do. Review Entra ID sign-in logs, conditional access policies, and privileged role assignments for anything anomalous predating the fix.
Source: Cybersecurity News