Skip to content

Sam's News — security — 2026-10-07

Security

7.5 SonicWall patches critical SSRF vulnerability in SMA1000 gateways

SonicWall confirmed active exploitation of two critical pre-authentication vulnerabilities in SMA 1000 Series appliances enabling unauthenticated remote code execution. CISA mandated federal agencies patch within 72 hours; at least 420 devices remain exposed to the public internet, marking the third zero-day wave in 13 months.

  • CVE-2026-83548: critical pre-authentication SSRF (CVSS 10.0); CVE-2026-83549: command injection
  • Affects SMA 1000 models 6210, 7210, 8200v (Linux platform)
  • No credentials required for exploitation; can chain for unauthenticated RCE
  • ShadowServer identified 420+ SMA 1000 devices exposed to public internet
  • Third confirmed zero-day exploitation wave in just over a year; CISA 72-hour patch mandate for federal agencies

Sources: Cybersecurity news source reporting on SonicWall SMA1000 zero-day AI Web Searched, Cybernews - SonicWall SMA 1000 under attack AI Web Searched, BleepingComputer RSS, Help Net Security RSS

7.5 100+ websites compromised to deliver LunexStealer malware via fake Cloudflare checks

Ukrainian CERT-UA identified over 100 compromised websites injected with LunexStealer malware in September 2026, attributed to UAC-0277. Attackers used forged Cloudflare verification pages and ClickFix delivery; malware steals browser credentials and files while supporting remote browser control.

  • 100+ websites compromised with malicious JavaScript in September 2026
  • LunexStealer (aka Psychedelic Stealer) delivered via fake Cloudflare verification pages
  • ClickFix technique triggers malicious MSI package download
  • EtherHiding retrieves configuration from Polygon/Ethereum smart contracts; three operating modes (inactive, passive tracking, phishing)
  • LUNARAXE browser extension steals cookies, history, web form credentials; NAIVEMESS component provides file system access via PowerShell Native Messaging Host

Sources: The Hacker News AI Web Searched

7.5 Atlassian patches critical vulnerability affecting 8 products

Atlassian released security patches for a critical unauthenticated vulnerability allowing access to files in the web application root directory across 8 products.

  • CVE-2026-21589 (CVSS 9.3) affects eight Atlassian Data Center products
  • Unauthenticated file access if exact filename and path known; no directory listing possible
  • Affected products: Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, Fisheye
  • Atlassian Cloud SaaS already patched and unaffected
  • Atlassian recommends immediate upgrade or restrict external network access until patched

Sources: SecurityWeek RSS Update to: Atlassian Data Center Products Vulnerable to Unauthenticated File Access Exploit

7.5 Over 1 Million Records Stolen in Cyberattack on Arizona Court System

A cyberattack on Arizona's court system compromised personal information for 1.3 million people with unpaid court fees and approximately 30,000 protection orders dating back 30 years. Attack originated from an employee clicking a malicious email link; staff shut down the breach on backup server within two hours.

  • 1.3 million records compromised (unpaid fees and restitution, traffic/criminal violations)
  • 29,996 active/inactive orders of protection stolen
  • 150,000 foster care reports compromised (dating to 2010)
  • Records span approximately 30 years; attack detected and shut down ~2 hours after discovery on September 24, 2026

Sources: SecurityWeek AI Web Searched

7 Termite Group Exploits Cleo Software Vulnerability CVE-2024-50623 in Aon Ransomware Attack

Termite ransomware group exploited unpatched CVE-2024-50623 in Cleo software to breach Aon on October 6–7, 2026. Once inside, attackers enumerated network shares, encrypted resources, deleted shadow copies, and stopped security services.

  • CVE-2024-50623: unauthenticated RCE in Cleo LexiCom, VLTransfer, Harmony
  • Vulnerability affected even systems patched to version 5.8.0.21
  • Termite ransomware used for initial access; enumerated shares using WNetOpenEnum/WNetEnumResourcesW APIs
  • Deleted shadow copies via vssadmin.exe, stopped critical Windows security/backup services

Sources: Rescana Solutions AI Web Searched, Rescana RSS

7 Android October 2026 security updates patch 25 vulnerabilities including critical privilege escalation

Google's October 2026 Android updates resolve 25 vulnerabilities with a critical system component flaw enabling privilege escalation.

Sources: SecurityWeek RSS

6.5 Chrome 155 update patches 247 vulnerabilities including four critical flaws

Google released Chrome version 155, addressing 247 security vulnerabilities including four critical-severity use-after-free defects.

Sources: SecurityWeek RSS

6.5 Anthropic launches three-tier cyber verification program for AI access

Anthropic has integrated its CVP and Project Glasswing into a single three-tier cyber verification offering for tiered access to its most capable AI models.

Sources: SecurityWeek RSS

6.5 Ernst & Young data breach exposes client information via third-party IT support platform

Ernst & Young disclosed a data breach in which a compromised third-party IT support platform exposed sensitive client information.

Sources: Rescana RSS

Technology

6.5 Apple releases verified photography system for image authenticity

Apple introduced 'Reference Image,' a system that verifies photographs are unaltered as taken by recent iPhone models without tying verification to a specific device or photographer.

Sources: Schneier on Security RSS