Wednesday, September 2, 2026 | Jonathan Brown
Actively exploited SonicWall and Artifactory flaws lead today’s feed, alongside a Dropbox identity-chain breach, the Sality disruption, a second German grid attack, major browser patches and Telstra’s timing-system postmortem.
SonicWall confirms active exploitation of two SMA 1000 zero-days
On September 1, SonicWall disclosed CVE-2026-83548 and CVE-2026-83549 in its SMA 1000 secure-access appliances and confirmed that both vulnerabilities have been exploited in the wild.
CVE-2026-83548 is a pre-authentication server-side request forgery flaw involving an unintended forward proxy and carries a CVSS score of 10.0. CVE-2026-83549 is a post-authentication remote-code-execution flaw scored 7.8. The pair creates a plausible path from unauthenticated access to code execution, but SonicWall has not publicly described the observed attack sequence or confirmed that attackers chained the two flaws.
The exposure covers SMA 1000 models 6210, 7210 and 8200v on all hypervisors when running affected 12.4.3 or 12.5.0 firmware. SonicWall lists platform hotfixes 12.4.3-03526 and 12.5.0-02952 as the fixed builds. Apply the appropriate update immediately and restrict appliance-management access. SonicWall advises customers to open a support case for indicator review; where compromise is found, reimage or redeploy the appliance, change all user and administrator passwords, and reset TOTP enrollment.
Watch for: SonicWall-published indicators, confirmation of the exploitation chain, scope estimates and any change to CISA Known Exploited Vulnerabilities status.
Sources: SonicWall Product Notice SNWLID-2026-0016, September 1, 2026; SonicWall PSIRT entries for CVE-2026-83548 and CVE-2026-83549; SecurityWeek reporting, September 1, 2026.
Attackers probe a critical JFrog Artifactory authentication flaw
On August 31, watchTowr reported exploitation of CVE-2026-82329 against its global Attacker Eye honeypot network. The critical Artifactory flaw, scored 9.8 under CVSS 3.1, can let an unauthenticated attacker with network access obtain administrator privileges when a self-hosted instance is in its default configuration.
Observed activity included minting administrator tokens and enumerating users, groups, credential sets and federated-access relationships. The evidence is high-confidence exploitation telemetry, but its scope matters: watchTowr saw a small number of source addresses, and neither JFrog nor the cited researchers had confirmed production victims or broad mass exploitation at publication time. This is an authentication failure, not a demonstrated remote-code-execution vulnerability.
JFrog published fixed self-hosted builds 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20; use the fixed release appropriate to the installed branch. JFrog Cloud was fortified by the vendor and requires no customer action. For exposed self-hosted systems, preserve logs, investigate unexpected token issuance and administrative changes, revoke unknown tokens, review federation activity, and validate repository permissions and artifact integrity.
Watch for: Confirmed production compromise, a rise from targeted probing to mass exploitation, new forensic guidance and CISA Known Exploited Vulnerabilities status.
Sources: JFrog Security Advisory for CVE-2026-82329, August 28, 2026; watchTowr Labs analysis and Attacker Eye telemetry, August 31, 2026; Dark Reading reporting, September 1, 2026.
A Lenovo identity weakness opens roughly 5,000 Dropbox accounts
Dropbox notified affected users that attackers accessed roughly 5,000 accounts between August 4 and August 21. Files were accessed in fewer than one-third of the compromised accounts, according to Dropbox statements and notifications reported by Bloomberg and Reuters.
The entry path did not require a victim’s Dropbox password. Attackers exploited weak email verification in Lenovo ID to register identities using victims’ Dropbox email addresses—even where a victim had never created a Lenovo ID—then used a legacy Lenovo-Dropbox trust integration to reach the matching Dropbox accounts. Dropbox said every compromised account lacked two-factor authentication.
Dropbox terminated Lenovo-authenticated sessions, removed the account links and changed the integration to require a Dropbox password. Affected users should review device, session, connected-app and file-activity records; invalidate unfamiliar sessions; enable phishing-resistant MFA where available; and rotate credentials or secrets only when evidence shows they were stored in or accessed from exposed files. Lenovo said its own customer accounts were not affected and that its investigation continues.
Watch for: A final root-cause account from Lenovo and Dropbox, regulator notices, a revised victim count, and phishing or credential-abuse campaigns using exposed file contents.
Sources: Dropbox user notifications and spokesperson statements reported by Bloomberg and Reuters, September 1–2, 2026; Lenovo statements reported by Reuters and Bloomberg, September 2, 2026.
Google and Mozilla ship broad browser security updates
Google and Mozilla released new desktop-browser security builds on September 1. Google Chrome 152.0.7977.75/.76 for Windows and macOS and 152.0.7977.75 for Linux address 26 security defects, including two rated critical.
The critical Chrome issues are CVE-2026-84352, a use-after-free vulnerability in WebGL, and CVE-2026-84353, a use-after-free vulnerability in Shared Tab Groups. Mozilla released Firefox 155 and ESR versions 153.2, 140.15 and 115.40. Its advisories include high-severity memory-safety rollups CVE-2026-84144 and CVE-2026-84145; the ESR 115.40 advisory also lists sandbox escapes CVE-2026-75874 and CVE-2026-84119.
Neither vendor advisory says the listed flaws were exploited before disclosure, so this is preventive patching rather than a confirmed zero-day response. Accelerate browser deployment, require relaunches and verify fleet versions. The new Chrome build does not, by itself, establish the cause of or a remedy for the separate Chrome and Brave Linux launch failures covered on September 1.
Watch for: Vendor exploitation-status changes, follow-on stable-channel revisions and endpoint populations that remain on pre-update browser builds.
Sources: Google Chrome Releases, “Stable Channel Update for Desktop,” September 1, 2026; Mozilla Foundation Security Advisories MFSA 2026-82 through MFSA 2026-85, September 1, 2026.
An international operation disconnects the Sality botnet—but not its infections
The U.S. Justice Department announced on September 1 that authorities and private-sector partners had disrupted Sality on August 31. The operation involved the United States, Bulgaria, Hungary and Romania, with technical support from CrowdStrike and the Shadowserver Foundation.
CrowdStrike says peer-to-peer sinkholing and false routing data isolated than 15,000 infected machines and made the botnet’s command channel inert. Sality, first observed in 2003, can spread through network shares, removable media and file-sharing systems. Its recent EggJagger payload swaps cryptocurrency addresses in the clipboard; the network has also supported credential theft, spam, proxying, network exploitation and distributed denial-of-service activity.
The disruption removed the operator’s control but did not remove malware from victim systems. Reuters, citing U.S. officials, characterized the operation as Russia-based; the Justice Department’s public release does not identify an operator or assign a country. Organizations receiving Shadowserver notifications should isolate and rebuild infected hosts, investigate lateral spread, and rotate credentials exposed on those systems.
Watch for: Attempts to reconstitute the peer network, fallback command channels, updated Sality variants and additional victim notifications.
Sources: U.S. Department of Justice press release 26-149, “Sality Malware Disrupted in International Cyber Takedown,” September 1, 2026; CrowdStrike, “Peer Pressure: Inside the Sality Botnet Disruption Operation,” August 31, 2026; Reuters reporting, September 1, 2026.
A second German grid attack trips five RWE generating units
At about 8 p.m. on September 1, deliberate interference with transmission lines near an Amprion substation in North Rhine-Westphalia disconnected five RWE lignite units: Neurath F and G and Niederaußem G, H and K. Public electricity supply and overall grid stability were not affected, according to Amprion and RWE.
Authorities and German reporting say conductive material or cables were intentionally placed across overhead lines, causing a short circuit. The five units have 4,200 megawatts of combined nameplate capacity, but they were supplying about 3,000 megawatts when disconnected; the larger figure is not the amount of live generation lost. RWE expected 1,600 megawatts of capacity to return during Wednesday morning, another 1,000 megawatts later Wednesday and the final 1,600 megawatts by the weekend.
This is a separate, materially new incident from the Brandenburg grid sabotage covered on September 1. Investigators are examining possible foreign-state direction and domestic extremist involvement, but there is no attribution and no confirmed link between the events.
Watch for: Evidence connecting or separating the two incidents, firm attribution, revised restoration timing and added protection around exposed transmission infrastructure.
Sources: Amprion incident statement, September 2, 2026; RWE, “RWE power stations affected by incident near substation,” September 2, 2026; Associated Press, Reuters and Deutsche Presse-Agentur reporting, September 2, 2026.
Operational Reliability Watch: Telstra traces its July outage to corrupted network time
Telstra released an external review on September 2 of its July 8 nationwide mobile outage. This is a retrospective root-cause report, not a new disruption or a cyberattack. The incident affected voice, messaging and data services across Australia, including some Triple Zero emergency-call attempts.
During planned maintenance on a Network Time Protocol chassis, a GPS card reset its date to 2006. The card lacked a supplier-published critical firmware update intended to prevent that known GPS rollover behavior. A degraded NTP design—with ownership gaps, peering loops and architecture weaknesses that had accumulated since 2020—allowed the incorrect date to propagate to parts of the network.
Telstra told the Australian Senate that the peak impact reached about 45 percent of call and data-session attempts. It recorded 59,321 successful Triple Zero calls and 611 errors that triggered welfare checks, with no known life-threatening outcome. Telstra says it has migrated all three sites to its strategic timing system and added monitoring, alarms, laboratory testing and tighter vendor-update controls.
Watch for: Independent validation of the remediation, regulatory findings, evidence of similar legacy timing dependencies at other carriers and closure of the remaining governance actions.
Sources: Telstra CEO update, September 2, 2026; Technology Audit Partners, external review of the July 8 network incident, dated August 24 and released September 2, 2026; Telstra Senate statement updated September 2, 2026.
Search tags: SonicWall SMA1000 zero-days, JFrog Artifactory CVE-2026-82329, Dropbox Lenovo ID breach, Sality botnet disruption, Germany power grid sabotage, Chrome 152 security update, Firefox 155 security update, Telstra network outage
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
SOURCE VERIFICATION — SEPTEMBER 2, 2026
Publication cutoff: September 2, 2026, 16:00 UTC
1. SONICWALL SMA1000 — CVE-2026-83548 AND CVE-2026-83549
Primary vendor advisory — SonicWall Product Notice SNWLID-2026-0016:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Official CVE record — CVE-2026-83548:
https://www.cve.org/CVERecord?id=CVE-2026-83548
Official CVE record — CVE-2026-83549:
https://www.cve.org/CVERecord?id=CVE-2026-83549
Independent reporting — SecurityWeek, “SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks”:
https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/
2. JFROG ARTIFACTORY — CVE-2026-82329
Primary vendor source — JFrog Security Advisories:
https://docs.jfrog.com/releases/docs/jfrog-security-advisories
Primary vendor source — Artifactory Self-Managed Releases:
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
Official CVE record — CVE-2026-82329:
https://www.cve.org/CVERecord?id=CVE-2026-82329
Original exploitation telemetry — watchTowr Attacker Eye post:
https://x.com/watchtowrcyber/status/2094639075726668267
Independent reporting — Dark Reading, “Attackers Pounce on Critical Artifactory Flaw After Disclosure”:
Independent reporting — SecurityWeek, “Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild”:
3. DROPBOX / LENOVO ID ACCOUNT BREACH
Dropbox did not publish a standalone public incident advisory located by the cutoff. The primary evidence was its affected-user notification and statements from Dropbox and Lenovo reproduced in the following reporting.
Reuters, “Dropbox says about 5,000 accounts compromised in August hack”:
Decrypt, including Dropbox's explanation of the authentication mechanism:
https://decrypt.co/377099/dropbox-security-breach?amp=1
9to5Mac, reproducing material from the affected-user notice:
Malay Mail, accessible Bloomberg-derived reporting with the Lenovo ID mechanism and Lenovo's statement:
The Next Web, additional contemporaneous reporting:
https://thenextweb.com/news/dropbox-lenovo-id-breach-5000-accounts
Provenance note: Bloomberg originated or first reported important details used by later coverage, but its canonical article URL could not be independently resolved during this verification pass. The accessible Bloomberg-derived report above is supplied instead; no guessed Bloomberg address is included.
4. GOOGLE CHROME AND MOZILLA FIREFOX SECURITY UPDATES
Primary vendor advisory — Google Chrome Releases, “Stable Channel Update for Desktop”:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
Official CVE record — CVE-2026-84352:
https://www.cve.org/CVERecord?id=CVE-2026-84352
Official CVE record — CVE-2026-84353:
https://www.cve.org/CVERecord?id=CVE-2026-84353
Primary vendor advisory — Mozilla Foundation Security Advisory 2026-82, Firefox 155:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
Primary vendor advisory — Mozilla Foundation Security Advisory 2026-83, Firefox ESR 115.40:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/
Primary vendor advisory — Mozilla Foundation Security Advisory 2026-84, Firefox ESR 140.15:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/
Primary vendor advisory — Mozilla Foundation Security Advisory 2026-85, Firefox ESR 153.2:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/
Official CVE record — CVE-2026-84144:
https://www.cve.org/CVERecord?id=CVE-2026-84144
Official CVE record — CVE-2026-84145:
https://www.cve.org/CVERecord?id=CVE-2026-84145
Official CVE record — CVE-2026-75874:
https://www.cve.org/CVERecord?id=CVE-2026-75874
Official CVE record — CVE-2026-84119:
https://www.cve.org/CVERecord?id=CVE-2026-84119
5. SALITY BOTNET DISRUPTION
Primary government source — U.S. Department of Justice, “Sality Malware Disrupted in International Cyber Takedown”:
https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown
Primary operational source — CrowdStrike, “Peer Pressure: Inside the Sality Botnet Disruption Operation”:
https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/
Primary law-enforcement source — Europol, “Global public-private operation disrupts Sality botnet active for two decades”:
Independent reporting — Reuters:
6. GERMANY POWER-GRID SABOTAGE INVESTIGATION / RWE DISRUPTION
Primary grid-operator source — Amprion incident statement:
https://www.amprion.net/Presse/Presse-Detailseite_98753.html
Primary grid-operator source — Amprion statement in PDF form:
https://www.amprion.net/Dokumente/Presse/260902_PM_Rommerskirchen.pdf
Primary operator source — RWE, “RWE power plants in the Rhenish region affected by an incident near a substation”:
Independent reporting — Reuters:
Independent reporting — Associated Press:
https://apnews.com/article/ef9c21908f232651d056d7462330e2b7
Independent reporting — Deutsche Presse-Agentur via Welt:
Additional German reporting — ZDF:
https://www.zdfheute.de/politik/deutschland/umspannwerk-bergheim-straftat-100.html
Additional German reporting — Tagesschau:
Context for the separate Brandenburg substation incident reported the previous day — Reuters:
7. TELSTRA JULY 8 MOBILE-NETWORK OUTAGE — EXTERNAL FINDINGS
Primary company source — Telstra CEO update, “What we've learned from the external investigation of our July outage”:
https://www.telstra.com.au/exchange/what-we-ve-learned-from-the-external-investigation-of-our-july-o
Primary report — Technology Audit Partners, “Findings Report on the July 8th Telstra Outage,” dated August 24, 2026 and released September 2, 2026:
Primary company source — Telstra CEO's Triple Zero Senate inquiry opening statement:
https://www.telstra.com.au/exchange/triple-zero-senate-inquiry--opening-statement-from-vicki-brady
Primary company source — Telstra's July incident timeline and resolution update:
https://www.telstra.com.au/exchange/some-mobile-calls-and-data-services-are-affected-today--here-s-w
Independent reporting — Reuters, “Telstra says external review finds network timing system caused July outage”:
Member discussion: