Weekly review

ThreatNoir Afternoon Brief — September 2

2026-09-02Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 2, 2026

The afternoon briefing for September 2, 2026, brings critical security developments across multiple fronts, with particular emphasis on actively exploited zero-day vulnerabilities in enterprise infrastructure and emerging safeguards in artificial intelligence systems. Organizations face immediate threats requiring urgent patching and deployment of defensive measures.

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates addressing two critical security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall researchers William Perry and Adam Babis, include CVE-2026-83548 with a CVSS score of 10.0, which represents a pre-authentication SSRF vulnerability in the appliance. These flaws have been observed being chained together by threat actors to achieve unauthenticated remote code execution. The attack chain demonstrates sophisticated exploitation techniques targeting organizations that rely on SonicWall's remote access infrastructure. Source: Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall Warns of Actively Exploited SMA1000 Zero-Day Flaws

SonicWall has issued warnings to customers regarding threat actors actively chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The vulnerabilities tracked as CVE-2026-83548 and CVE-2026-83549 represent an immediate and ongoing threat to deployed SonicWall infrastructure globally. The active exploitation in the wild underscores the urgency of applying available security patches and implementing network-level protections for affected systems. Source: SonicWall warns of actively exploited SMA1000 zero-day flaws

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, enabling unauthenticated remote code execution. CVE-2026-9586, rated at CVSS 9.3, is a critical unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8.3 (build 104997). Attackers are leveraging this flaw to deploy reverse shells and gain arbitrary code execution without requiring any credentials, creating a significant exposure for organizations running unpatched instances. The vulnerability impacts an estimated 4,000 systems left vulnerable to unauthenticated remote code execution. Source: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

Anthropic has introduced Enterprise Frontier Safeguards (EFS), a comprehensive security system combining zero data retention with automated monitoring for misuse detection. The new safeguards represent the company's response to security incidents and demonstrate a commitment to protecting enterprise deployments of AI models. The system addresses concerns regarding unintended access and unauthorized actions that may occur when AI systems interact with external systems and networks. Source: Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

Organizations should prioritize patching of SonicWall SMA 1000 and Sangoma Switchvox systems immediately, as both vulnerabilities are currently under active exploitation. The afternoon's threat landscape emphasizes the critical importance of rapid vulnerability response and the emerging need for robust safeguards in AI-driven enterprise systems.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
CVE4
  • Pre-authentication SSRF vulnerability in SonicWall SMA 1000 Appliance Work Place interface (CVSS 10.0)
  • Post-authentication OS command injection in SonicWall SMA 1000 Appliance Management Console (CVSS 7.8)
  • Prior SonicWall SMA 1000 vulnerability exploited by UTA0533 to deploy KNUCKLEBALL malware (CVSS 10.0)
  • Prior SonicWall SMA 1000 vulnerability exploited by UTA0533 (CVSS 7.2)
Malware1
  • KNUCKLEBALL
    Malware deployed by threat actor UTA0533 via SonicWall SMA 1000 exploitation