Thursday, September 3, 2026
Daily digest
SonicWall's SMA 1000 series is under active, chained zero-day exploitation (CVSS 10.0 SSRF plus a second flaw), and CISA has added it and six other actively-exploited flaws to the KEV catalog — patch and check exposure now if you run these appliances.
CISA Adds Seven Actively Exploited Flaws to KEV Catalog
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, including a critical (CVSS 10.0) SSRF flaw in SonicWall SMA 1000 appliances (CVE-2026-83548). Attackers have been observed deploying reverse shells and crypto miners via these flaws.
Why it matters: Federal contractors under CMMC/FAR are required to remediate KEV-listed vulnerabilities on an accelerated timeline — confirm no SonicWall SMA 1000 or other listed devices sit on your network perimeter.
SonicWall Patches Two SMA 1000 Zero-Days Exploited as an Attack Chain
SonicWall released patches for two zero-day vulnerabilities in its SMA 1000 series VPN appliances that attackers chained together for unauthenticated remote code execution. The flaws were discovered internally after active exploitation was detected, following earlier zero-day attacks on the vendor's edge devices this summer.
Why it matters: This is SonicWall's third round of exploited edge-device zero-days this year; if SMA 1000 boxes are part of your remote-access architecture, patch immediately and review logs for indicators of compromise dating back to the disclosed exploitation window.
Researcher Releases FalconFlank PoC for CrowdStrike Falcon Privilege Escalation
A security researcher published a proof-of-concept for a zero-day privilege escalation flaw in CrowdStrike Falcon Sensor, dubbed FalconFlank, which abuses the product's malicious-macro remediation feature. The PoC and technical details were posted publicly on GitHub.
Why it matters: If Falcon is deployed as your EDR in a CMMC L2 environment, treat this as an active local privilege-escalation risk until CrowdStrike issues a fix — monitor vendor advisories closely.
Malicious Git Configs Can Trigger Code Execution in Claude, Codex, Cursor, and Other AI Coding Agents
Manifold Security disclosed eight vulnerabilities across seven command-line AI coding agents where a repository's Git configuration can name a command the agent executes automatically outside its sandbox and without an approval prompt. Four of the eight flaws remain unpatched at time of disclosure.
Why it matters: Any self-hosted AI-assisted coding workflow that clones untrusted repos is exposed to arbitrary code execution as the developer's user — audit which AI coding tools are in use and disable auto-run of repo-defined commands until patched.
Threat Actors Impersonate IT Support via Microsoft Teams to Gain Enterprise Access
Microsoft Threat Intelligence detailed a human-operated intrusion campaign abusing Microsoft Teams external collaboration features to impersonate IT support, establish remote sessions, and deploy a Node.js-based implant for lateral movement. The campaign has been observed moving from social engineering to enterprise-wide compromise.
Why it matters: M365 GCC High tenants should verify external Teams access/federation settings are locked down and that helpdesk-impersonation scenarios are covered in user awareness training and Conditional Access policies.
BGP Hijack Used to Deliver Malicious Virtualizor Update with Persistent Root Access
Attackers used a BGP hijack to redirect Softaculous update traffic and deliver a malicious Virtualizor hypervisor management package, granting persistent root access on affected installations. A hosting provider reported that 5 of 34 checked Virtualizor hypervisors were compromised during the roughly two-day incident window.
Why it matters: This is a reminder that hypervisor management update channels are a supply-chain attack surface; verify update-source integrity checks and network-path controls for any virtualization management tooling, even outside your primary Nutanix stack.
House Committee Votes to Subpoena Oracle Over VA's $27B EHRM Contract
The House Veterans' Affairs Committee voted 19-0 to subpoena Oracle Chairman Larry Ellison and CEO Mike Sicilia after Oracle pulled out of a hearing on the VA's electronic health records contract, which recently saw its ceiling raised by $17 billion. Lawmakers cited Oracle's earlier commitment not to raise costs.
DoD Seeks Interim Encryption Software to Protect Data Ahead of Post-Quantum Transition
The Department of Defense is requesting encryption software to protect programs of record as an interim measure while it works toward adopting post-quantum cryptography by the early 2030s. The request signals near-term procurement activity ahead of the broader PQC migration timeline.
Why it matters: Contractors handling CUI should start tracking DoD's post-quantum cryptography timeline now, as NIST 800-171 and future CMMC revisions are expected to eventually mandate PQC-ready algorithms.
GSA Terminates Hundreds of Security Clearances After Review
The General Services Administration revoked the security clearances of several hundred employees following an audit intended to ensure clearances remain "strictly aligned with operational necessity." No further details on the scope of affected roles were disclosed.
AWS Publishes Guidance on Managing IAM Identity Center Identity Source Migrations
AWS updated its security blog with guidance on transitioning identity sources in AWS IAM Identity Center, including Active Directory migration strategies and automation for permission sets. The update expands on prior guidance for managing access to AWS accounts and applications during identity provider changes.
Why it matters: If you manage federated identity into AWS GovCloud via IAM Identity Center, this guidance is directly applicable when planning AD or IdP migrations without disrupting permission sets or access reviews needed for NIST 800-171 audit evidence.
Microsoft Confirms KB5120998 Preview Update Resets Windows Desktop Settings
Microsoft confirmed that some Windows devices lose or have desktop settings reset after installing the KB5120998 August 2026 preview update. The company is investigating the cause and has not yet issued a fix.
Why it matters: Hold or pilot-test this preview update in Intune update rings before broad deployment to your managed Windows 11 fleet to avoid unexpected desktop configuration resets.
VMware Refocuses on Low-End Server Virtualization, Plans vSphere Standard Upgrade
VMware (under Broadcom) announced it is shifting focus back toward low-end server virtualization customers and plans an upgrade to vSphere Standard, after adjusting sales incentives that previously pushed customers toward full private cloud bundles. The move follows broader industry pushback on VMware licensing changes.