View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Microsoft Defender flags legitimate Google search links as malicious β€” BleepingComputer

  • US charges Russian for infecting 80,000 freelancers with malware β€” BleepingComputer

  • Malicious Virtualizor Update Served via BGP Hijacking β€” SecurityWeek

  • OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold β€” SecurityWeek

  • Wireless Routers as Motion Detectors β€” Schneier on Security

  • Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon β€” Check Point Research

  • An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation β€” Palo Alto Unit 42

  • Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain β€” The Hacker News

  • GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends β€” The Hacker News

  • Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands β€” The Hacker News

  • Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_passwor... β€” CVE ThreatInt

  • Broken Link Checker through 2.4.13 - Unauthenticated Stored Cross-Site Scripting v... β€” CVE ThreatInt

  • Easy Waveform Player through 1.2.2 - Authenticated (Contributor+) Stored Cross-Sit... β€” CVE ThreatInt

  • Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 vers... β€” CVE ThreatInt

  • WordPress Login With Ajax plugin through 4.5.1 - Cross Site Scripting (XSS) vulner... β€” CVE ThreatInt

  • Fulcrumsec list a lot of other orgs they're attempting to extort on their website. β€” @GossiTheDog@cyberplace.social

  • The Manchester Airports Group thing from Fulcrumsec is making the media rounds. β€” @GossiTheDog@cyberplace.social

  • Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Windows PCs β€” Cyber Security News

  • Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems β€” Cyber Security News

  • PikiwiDB (Pika) Unauthenticated Replication Server Access (CVE-2026-84700) β€” thehackerwire.com (discovered)

  • The PAM Migration Trap: Modernizing Your Vault Doesn’t Modernize Privileged Access β€” securityboulevard.com (discovered)

  • 427 or 4 Devices?: Measuring Internet-Exposed Industrial Infrastructure in the UK β€” securityboulevard.com (discovered)

  • Fixing insufficient_scope 403s in MCP Step-Up Authorization β€” securityboulevard.com (discovered)

  • Is Silent Network Authentication a Restricted Authenticator Under SP 800-63-4? β€” securityboulevard.com (discovered)

  • There is so much cyber news going on this week that one could be forgiven for missing this: ShinyHunters launched a... β€” @metacurity@infosec.exchange

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check