Daily Cyber Threat Intel Brief — 2026-09-03
Generated: 2026-09-03 08:01:32 UTC
Executive summary
Priority technology watch items
- Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve…
- SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
- Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
- A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
- Affected software updated with new package information.
- Affected software updated with new package information.
- International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-83548` | Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the | Rapid7 Blog |
| cve | `CVE-2026-83549` | Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the | Rapid7 Blog |
| cve | `CVE-2026-9586` | Hackers exploit Sangoma Switchvox flaw to deploy reverse shells | BleepingComputer Ransomware News |
| cve | `CVE-2026-82329` | Hackers exploit critical JFrog Artifactory flaw to forge admin tokens | BleepingComputer Ransomware News |
| cve | `CVE-2026-69320` | CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70336` | CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69278` | CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69306` | CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62768` | CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62880` | CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50376` | CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `176.65.139.206` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `a54827e084a5e2b1a855d24b2c79b809621be1d5` | RansomLook: (EVIDENCE)REXT Holdings Co., Ltd. claimed by ransomhouse | RansomLook Recent Listings |