SonicWall Zero-Days and a Hijacked Update Route (09/02/2026)
- › SonicWall patched two SMA 1000 zero-days already exploited in the wild, and researchers say they may chain into unauthenticated remote code execution.
- › Attackers used a BGP hijack to divert Softaculous update traffic and deliver a malicious Virtualizor package that establishes persistent root access.
- › Manifold Security found eight flaws across seven command-line AI coding agents where a repository's own Git config names a command the agent then runs.
- › An unauthenticated SQL injection flaw in Sangoma Switchvox, tracked as CVE-2026-9586, is being exploited to drop reverse shells.
- › A SQL injection bug in the All-in-One WP Migration and Backup plugin exposes millions of WordPress sites to unauthenticated takeover.
Every significant story today arrived through a channel the target had already decided to trust. The VPN appliance at the edge, the vendor’s update route, the repository you just cloned, and the backup plugin you installed on purpose all did exactly what they were built to do, which is why none of them looked like an attack while it was happening.
Top 5 Critical Security Alerts
1. SonicWall Patches Two SMA 1000 Zero-Days Under Active Attack
SonicWall released updates for two flaws in its Secure Mobile Access 1000 series VPN appliances that were already being exploited when the company found them internally, and researchers say the pair may form an attack chain reaching unauthenticated remote code execution. This is the second round of zero-day exploitation against SonicWall edge hardware in a matter of months, following attacks earlier this summer on two other flaws in the same product family. Third-party security operations centers monitoring the activity say further attacks are close to certain. The Hacker News and The Register both have detail, and Dark Reading covers the chain.
Operator Note: An SMA 1000 sits in front of everything, so treat this as an intrusion investigation and not a patch ticket, and pull authentication logs for the window before the fix landed.
2. A BGP Hijack Delivered a Poisoned Virtualizor Update
Attackers hijacked Border Gateway Protocol routes to divert Softaculous traffic, then used the redirected update channel to push a malicious Virtualizor package that establishes persistent root access on affected hosting infrastructure. The update mechanism worked correctly at every step. It fetched from the address it was supposed to fetch from, and the attackers moved that address out from under it at the routing layer, which is a level most defenders never see at all. The Hacker News has the analysis.
Operator Note: Pin update sources to a signature you verify rather than to a hostname, because a hostname is only as trustworthy as the routing table that resolves it that day.
3. A Repository’s Git Config Can Make Your AI Coding Agent Run Attacker Code
Manifold Security disclosed eight flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent then executes on the developer’s machine, and four of the eight remain unpatched. The attack needs nothing more than a developer cloning a repository and pointing an agent at it, which is a workflow that happens hundreds of times a day inside any engineering team. Every agent in that list runs with the developer’s own credentials and network access. The Hacker News names the affected tools.
Operator Note: Treat a cloned repository as untrusted input to an agent, and run agents against unfamiliar code inside a container that holds no credentials worth stealing.
4. Sangoma Switchvox Flaw Exploited to Drop Reverse Shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox voice over IP platform that leads to remote code execution, and the observed activity involves deploying reverse shells. Phone systems tend to sit on their own network segment with an aging patch cadence and no endpoint agent, which makes them a comfortable place for an intruder to wait. The traffic they generate afterward looks like a phone system talking to the internet, because that is what it is. BleepingComputer has the details.
5. WordPress Backup Plugin Flaw Puts Millions of Sites at Risk
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin allows unauthenticated attackers to execute code remotely and take over affected WordPress installations, and the plugin is deployed on millions of sites. A backup plugin is an unusually valuable target because it already has read access to everything on the site and usually holds credentials for wherever the backups are shipped. Compromising it hands over the current site and the archive of every previous version. BleepingComputer has the writeup.
Additional Security Alerts
Threat Intelligence
- Gambling Goblin turns Brazilian government sites into SEO weapons: A Chinese-speaking cybercrime cluster installed malicious Apache modules on compromised servers run by Brazilian government and educational institutions, using them to divert visitor traffic to betting pages while leaving the sites otherwise functional. The Hacker News
- StreamRat Android trojan pushed through Meta ads: Researchers detailed a new Android banking trojan promoted to Spanish-speaking users through a fake television-streaming campaign on Meta, capable of giving operators near-complete control of an infected device. The Hacker News
- Spring Ring vishing campaign targets Microsoft Teams users: A threat group is calling Teams users to compromise their sessions, spread malware, and in some cases move on to infrastructure takeover. Dark Reading
Security Breaches and Incidents
- Legacy Lenovo login exposes 5,000 Dropbox accounts: Dropbox severed an old Lenovo integration after attackers reached roughly 5,000 accounts through it, and is telling affected users to reset credentials. The integration was dormant rather than removed, which is the usual shape of this failure. The Register
- AI agents ran an entire ransomware attack, then left an audit report: Researchers documented an intrusion in which AI agents carried out every stage of a ransomware attack and finished by generating an 80-page security audit for the victim. The Register
- Russian national extradited over campaign that hit 80,000 freelancers: The Department of Justice charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced spreadsheet attachments to about 80,000 users. The Hacker News
Cloud and Network Security
- GeoNetwork patches an unauthenticated remote code execution chain: Two vulnerabilities in the open-source geospatial metadata catalog can be chained for unauthenticated remote code execution, and the software sits behind a large number of government and agency geoportals. The Hacker News
- Fake installers disable Windows Update and weaken Defender: An active campaign uses bogus download sites impersonating trusted vendors to distribute installers that turn off Windows Update and degrade Microsoft Defender before delivering their payload. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.