HeadFlash

Security

SonicWall SMA 1000 Zero-Days Exploited, Patches Issued

Two actively exploited SonicWall zero-days allow unauthenticated RCE; CISA adds them to KEV catalog as attacks continue.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

SonicWall SMA 1000 Zero-Days Under Active Attack, CISA Adds to KEV

SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 appliances, CVE-2026-83548 and CVE-2026-83549, both of which are being actively exploited in the wild. The company released patches and issued a security advisory on Tuesday, with the Cybersecurity and Infrastructure Security Agency adding the flaws to its known exploited vulnerabilities catalog the following day. Rapid7 researchers described the pair as a max-severity pre-authentication server-side request forgery and a high-severity OS command injection vulnerability that can be chained to achieve unauthenticated remote-code execution.

The disclosure leaves several critical questions unanswered, as SonicWall did not state how many customers were impacted, when the first exploitation occurred, or which threat group was responsible. The advisory also lacked indicators of compromise, prompting criticism from security researchers. Jake Knott of watchTowr questioned how SonicWall could claim the vulnerabilities were internally discovered while also investigating active exploitation. SonicWall has urged customers to contact tech support for help reviewing IOCs and, if compromise is detected, to reimage appliances, change all passwords, and reset tokens. Notably, all five defects added to CISA’s KEV catalog since mid-December 2025 impact SonicWall SMA 1000 appliances, and ten of the 19 SonicWall flaws in the catalog since late 2021 have been tied to ransomware campaigns including INC and Akira.

Attackers exploit zero-days in consistently besieged SonicWall product →

EU Cyber Resilience Act 24-Hour Reporting Deadline Reshapes Supply Chain Security

Starting September 11, manufacturers of products with digital elements sold in the European Union must notify regulators within 24 hours of learning that a vulnerability in their product is being actively exploited, with a fuller report due within 72 hours. This Cyber Resilience Act reporting obligation precedes the regulation’s broader engineering requirements, which take effect in December 2027. The tight timeline is forcing manufacturers across automotive, medical-device, aerospace, and consumer-electronics sectors to rethink how they track software components across complex, multi-tier supply chains.

Software Bills of Materials (SBOMs) provide a machine-readable inventory of components, but for large manufacturers, supplier files often arrive in different formats with varying detail levels, making reconciliation difficult. FossID, a software composition analysis company, argues that an SBOM is only as useful as the confidence organizations can place in its contents. Chief Growth Officer Aaron Branson emphasized the need for source-code analysis to verify that declared SBOM information matches the underlying software. Katie Norton of IDC noted that enterprises need processes flexible enough to accommodate differences in suppliers and regulatory requirements. The core question, Branson said, is shifting from Do we have an SBOM? to Can we continuously verify the software supply chain that the SBOM represents?

The 24-hour CRA deadline is changing software supply chain visibility →

Microsoft Warns of Teams Helpdesk Impersonation Campaign Ending in Ransomware

Microsoft is warning about an ongoing hacking campaign that begins with a Microsoft Teams message impersonating IT staff and ends with ransomware infection and data theft. Unnamed threat actors contacted enterprise targets via Teams chat, coercing victims into granting remote access through screen sharing or remote monitoring and management tools. The attackers then installed malware loaders and other implants, conducted host reconnaissance, enumerated domain accounts and servers using native tools and ADSI queries, and moved laterally across networks.

The final stage involved identifying and extracting valuable data before deploying ransomware. Microsoft did not attribute the campaign to a specific group, referring only to threat actors. The company advises enterprises to establish internal helpdesk authentication phrases, train employees to recognize external-tenant indicators, and verify unsolicited support contact. Microsoft also recommends hardening Teams and email against social engineering, including using Defender for Office 365 with Safe Links and Zero-hour auto purge to neutralize malicious messages and URLs at click time and remove them after delivery.

IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools →

Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites

A critical vulnerability in the Elementor Pro WordPress plugin, CVE-2026-32475, is being actively exploited to deliver webshell payloads and execute arbitrary commands on servers. The plugin, which has more than 6 million active installations, was patched on August 19 with version 4.2.2. Since then, Defiant’s Wordfence firewall has blocked almost 200,000 exploitation attempts. The flaw stems from faulty validation of file-upload arrays in Elementor Pro forms, affecting versions 4.2.1 and earlier.

Attackers exploit the bug by submitting an empty file as the first array element and a malicious PHP file as the second, causing the plugin to stop validating subsequent files. The payload is stored under /wp-content/uploads/elementor/forms/ and can be accessed to execute commands remotely. Exploitation requires a published Elementor Pro Form widget with a File Upload field, a common configuration. Wordfence observed increased attack activity between August 19 and 23, blocking more than 190,000 attempts, and provided a list of attacking IP addresses. Administrators should upgrade to Elementor Pro 4.2.2 or later immediately and inspect the forms directory for rogue PHP files, as their presence is a strong indicator of compromise.

Critical Elementor Pro flaw exploited to take over WordPress sites →

Memory Poisoning Emerges as New Threat to AI Agents

Researchers at the University of Calgary have identified a new cybersecurity threat targeting memory-enabled AI agents: memory poisoning, where an attacker inserts a misleading instruction into an agent’s stored memory without directly controlling the AI. The poisoned information can remain dormant while the agent works normally, only affecting behavior days or several interactions later when the agent retrieves and trusts it. This makes the attack particularly difficult to detect through conventional security testing.

The study examined 2,614 simulated multi-step attack trajectories and analyzed four attack types: chain poisoning, policy rewriting, backdoor triggering, and slow drift. Results showed that slow-drift and backdoor-trigger attacks could evade evaluations examining only individual steps, becoming apparent only in later interactions. Some attacks produced non-monotonic patterns, where behavior appeared more concerning at one stage and less at another before fully developing. The research argues for trajectory-aware security testing that follows an agent’s behavior across sequences of interactions rather than judging each step in isolation. Because memory-enabled agents can use tools, poisoned memories can influence decisions about actions, resource access, and which instructions to follow, meaning security evaluations must account for what the system carries forward, not just the prompts in front of it.

AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches