Weekly review

ThreatNoir Morning Brief — September 3

2026-09-03Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — September 3, 2026

The cybersecurity landscape continues to face active exploitation of critical vulnerabilities across multiple platforms. Today's briefing covers urgent threats affecting VoIP infrastructure, edge security devices, WordPress installations, and the takedown of a persistent botnet operation that evaded disruption for over two decades.

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that enables remote code execution. The vulnerability allows threat actors to gain unauthorized access to affected systems and deploy reverse shells for persistent command and control. This active exploitation represents an immediate risk to organizations relying on Sangoma Switchvox for their telecommunications infrastructure.

Source: Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

SonicWall's SMA 1000 edge device has been targeted by exploitation activity involving zero-day vulnerabilities that permit unauthenticated remote code execution. This campaign follows earlier attacks during the summer targeting two additional zero-day flaws in the vendor's edge device portfolio. The recurring exploitation of SonicWall edge appliances indicates a sustained focus by threat actors on perimeter security infrastructure.

Source: SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

WordPress Backup Plugin Flaw Exposes Millions of Sites to Takeover Attacks

An SQL injection vulnerability tracked as CVE-2026-19949 has been discovered in the All-in-One WP Migration and Backup plugin for WordPress. The flaw permits unauthenticated attackers to execute remote code and assume complete control of affected websites. With millions of WordPress installations relying on this backup plugin, the vulnerability poses a significant supply chain risk to a substantial portion of the web.

Source: WordPress backup plugin flaw exposes millions of sites to takeover attacks

Dogged Russia-Based Botnet Dismantled After 23-Year Run

The Sality botnet, a Russia-based peer-to-peer malware operation, has been successfully dismantled following an exceptional 23-year operational period. The botnet's distributed infrastructure allowed it to evade system-wide disruption efforts for an unusually prolonged timeframe before authorities and cybersecurity experts finally achieved its takedown. This operation represents one of the longest-running botnet campaigns in recorded history.

Source: Dogged Russia-based botnet dismantled after 23-year run

Organizations should prioritize patching the identified vulnerabilities in Sangoma Switchvox, SonicWall SMA 1000, and WordPress backup plugins while maintaining vigilance for any indicators of compromise related to these active exploitation campaigns.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).