SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
SonicWall is urging customers running its SMA1000 series secure remote access appliances to patch two zero-day vulnerabilities that have already been exploited in the wild, both discovered internally by the vendor. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF flaw in the Appliance Work Place interface that lets an unauthenticated attacker reach sensitive internal functionality, while CVE-2026-83549 (CVSS 7.8) is an OS command injection flaw in the Appliance Management Console — Rapid7 notes the two can be chained together for fully unauthenticated remote code execution. This marks the second SonicWall SMA1000 zero-day incident in as many months, and the fixed versions from July’s earlier vulnerabilities are themselves affected by this new pair, meaning organizations that already patched still need to apply the new hotfixes immediately.
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, with the intrusion occurring in March 2026 and discovered on June 30 — affecting courts across 11 U.S. states, the U.S. Virgin Islands, and three Ontario court systems. A subset of the exposed court records may contain names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance data, with some affected courts noting that confidential, redacted, or sealed information may also have been impacted. Ohio’s Supreme Court said Thomson Reuters told them the unauthorized access occurred directly on the court’s own production platform, while Alabama’s Chief Justice characterized the incident as confined entirely to the vendor’s systems — a discrepancy that underscores how differently affected courts are being told their exposure occurred.
FBI Probes Service Selling 153M+ Drivers Licenses
A new dark web identity theft service called Nexus launched this week selling digital scans of more than 153 million driver’s licenses from the United States and Canada, along with over 10 million ID cards, three million travel documents, and 579,000 medical cards, with the data appearing to originate from a breach at a widely used, Louisiana-based identity verification company. The FBI’s New Orleans field office has opened a formal inquiry, and researchers who verified sample records found the license of U.S. Secretary of Defense Pete Hegseth among the listings, alongside front-and-back images and infrared/ultraviolet scan data — details that go well beyond a simple photo. Security researchers are calling it the largest exposure of government-issued identity documentation on record, warning the scale creates genuine national security exposure given the high-profile individuals found in the trove.
Global Sinkhole Operation Ends Sality Botnet’s 23-Year Run
Sality, a peer-to-peer botnet running continuously since 2003 and infecting more than 15,000 machines worldwide, was taken down in a joint operation between U.S. and European law enforcement, CrowdStrike, and the Shadowserver Foundation. Rather than a traditional infrastructure seizure, CrowdStrike exploited Sality’s own peer-verification protocol — invalidating legitimate entries in each infected machine’s peer list and replacing them with defender-controlled sinkholes during the botnet’s routine 40-minute check-ins, cutting off operator control even over machines sitting behind firewalls or NAT. For the last eight years, Sality’s primary payload was a clipboard hijacker that silently swapped copied Bitcoin and Ethereum wallet addresses for attacker-controlled ones, and the operation demonstrates that even decentralized P2P botnet architecture isn’t invulnerable to a sufficiently precise protocol-level attack.
US Charges Russian for Infecting 80,000 Freelancers With Malware
A federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev for allegedly using roughly 255 fake accounts on a major freelance employment platform to send malware-laced Excel attachments to approximately 80,000 users between June 2016 and November 2017, with malicious macros in the files downloading TVRAT and DarkVNC malware onto victims’ machines. Both malware families gave Aktulaev remote control over infected systems via TeamViewer and VNC Viewer respectively, with roughly half of the identified victims located in the United States. Aktulaev was arrested in Cyprus in May 2025 and extradited to the U.S. on August 28, making his first federal court appearance in San Francisco — his case is one of several recent instances of U.S. prosecutors using Cyprus as an extradition pathway for Russian nationals, since Russia’s own constitution bars extraditing its citizens.