SonicWall SMA 1000 flaws under active attack
Two vulnerabilities in the remote-access appliance are being exploited. NCSC rates both likelihood and impact high and urges immediate updates plus compromise checks.
Two vulnerabilities in the remote-access appliance are being exploited. NCSC rates both likelihood and impact high and urges immediate updates plus compromise checks.
READ NCSC-NLSIMULATED HEAT + ROUTES // VISUAL MODEL // NOT LIVE ATTACK ATTRIBUTION
Two vulnerabilities in the remote-access appliance are being exploited. NCSC rates both likelihood and impact high and urges immediate updates plus compromise checks.
The FBI is investigating after a dark-web identity service advertised a vast cache of US and Canadian identity documents reportedly linked to IDScan.
Sensors recorded attempts matching a public proof of concept for CVE-2026-19490. Exposed ADC and Gateway appliances should be assessed and patched.
Google fixed CVE-2026-85046, a type-confusion flaw in V8 with an exploit already in the wild. Chromium-based browsers require an update and restart.
C-Track files affecting courts across the US and Canada may include sealed information, social security numbers, licence data and medical details.
Attackers added unauthorised registry servers to Coder infrastructure and served malicious Terraform modules carrying credential-theft code.
China-linked actors compromised routers to monitor traffic, collect credentials and create durable paths into connected high-value environments.
US and European authorities used the malware’s peer-to-peer architecture against it, severing thousands of infected machines from operators.
A legacy identity integration let attackers register fraudulent Lenovo IDs and enter linked Dropbox accounts without the existing password.
Stolen browser cookies can preserve access after credentials change. Response teams need to revoke sessions, rotate exposed secrets and inspect the infected host.
Unit 42 investigated an intrusion where agentic tooling mapped services, harvested secrets and abused pipelines. Human direction remained central, but operational speed increased sharply.
Microsoft documented two delivery paths used to deploy ACR Stealer and published defensive context for responders tracking credential theft in enterprise environments.
Google Threat Intelligence and Mandiant detail recent repository and dependency attacks, plus practical controls for reducing package and build-pipeline exposure.
The monthly TLP:CLEAR brief reviews hundreds of open-source reports, including EU-focused espionage, phishing, infrastructure disruption and dependency compromise.
CVE-2026-9586 can allow unauthenticated remote code execution against the enterprise VoIP platform. Exploitation evidence and indicators are now public.
12 VERIFIED SOURCES // 11 AUTO-SYNC FEEDS // 3H CACHE
PATCH THE EDGE. Prioritise internet-facing KEVs and remote-access infrastructure.
KILL THE SESSION. Password resets alone do not revoke stolen browser cookies.
VERIFY THE SOURCE. Treat third-party identity and build systems as part of your perimeter.