Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Wednesday, September 2, 2026

Here are today’s top cybersecurity stories for Wednesday, September 2, 2026.

SonicWall Warns of Two Chained SMA1000 Zero-Days Under Active Exploitation
SonicWall disclosed two vulnerabilities in its SMA1000 secure access appliances: an unauthenticated server-side request forgery flaw rated CVSS 10.0 (CVE-2026-83548) and an authenticated OS command injection bug (CVE-2026-83549). Attackers chain the pair to reach the management plane without credentials and execute arbitrary code on affected 6210, 7210, and 8200v models. Hotfixes 12.4.3-03526 and 12.5.0-02952 patch both flaws, and SonicWall confirms exploitation in the wild. SecurityWeek | Help Net Security

Dark Web Service Sells Scans of 153 Million US and Canadian Driver’s Licenses
A dark web operation called Nexus offered digital scans of more than 153 million driver’s licenses along with millions of passports, ID cards, and other government-issued documents. Evidence points to Louisiana-based identity verification firm IDScan.net as the source, and Krebs on Security traced timestamps on affected license images to infrared and ultraviolet scanning systems deployed at rental car counters and dispensaries. The FBI’s New Orleans field office opened an inquiry, and the leaked archive includes documents belonging to Canadian residents alongside US victims. Krebs on Security

International Law Enforcement Dismantles 23-Year-Old Sality Botnet
The US Department of Justice, FBI, and authorities in Bulgaria, Hungary, and Romania seized domains tied to the Sality peer-to-peer botnet, working with CrowdStrike and the Shadowserver Foundation to sinkhole its command infrastructure. Sality has infected machines since 2003, and its payload for the past eight years has silently swapped cryptocurrency wallet addresses copied to victim clipboards. CrowdStrike says it fed the botnet false peer data to cut infected machines off from their operator. BleepingComputer

Malicious Git Configuration Files Trigger Code Execution in AI Coding Agents
Manifold Security disclosed eight flaws across seven command-line AI coding agents, including Claude Code, Codex, Cursor, Hermes Agent, Qwen Code, and Grok Build, where a hostile repository’s .git/config file names a command the agent runs automatically. The payload fires when the agent performs a routine context-gathering git operation inside the poisoned repository, executing with the full privileges of the logged-in user outside any sandbox. Patches shipped for Claude Code, Cursor, and goose, while several affected tools remained vulnerable at disclosure. The Hacker News

BGP Hijack Delivers Malicious Software Update to Virtualizor Customers
A threat actor diverted a block of Softaculous IP addresses through a BGP hijack between August 28 and August 30, using a valid TLS certificate for the company’s domain to redirect update traffic to attacker-controlled servers. Virtualizor customers who checked for updates during the roughly 33-hour window received a malicious package establishing persistent root access. Softaculous restored routing and published guidance for affected customers. SecurityWeek

Federal Deadline Arrives for Actively Exploited MLflow Credential-Theft Flaw
Today marks the CISA remediation deadline for federal agencies to patch CVE-2026-64849, a CVSS 9.3 unauthenticated server-side request forgery flaw in the MLflow machine learning platform. Attackers began scanning for exposed MLflow Tracking Servers within hours of the CVE’s August 18 disclosure, using the flaw to reach cloud metadata services and steal AWS, Google Cloud, and Azure credentials. Versions before 3.15.0 remain vulnerable. The Hacker News

Dropbox Accounts Compromised Through Flaw in Lenovo Sign-In Integration
Dropbox says an attacker accessed roughly 5,000 accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs tied to victims’ email addresses. Because Dropbox accepts verified Lenovo ID sign-ins as an authentication method, the attacker bypassed passwords entirely on accounts without two-factor authentication enabled between August 4 and August 21. Dropbox expired all Lenovo ID sessions and now requires a Dropbox password alongside Lenovo ID sign-in. BleepingComputer

Microsoft 365 Services Recover After Multi-Day Exchange Online Outage
Microsoft says service availability sits above 99 percent following an outage beginning August 31, traced to an authentication configuration issue affecting Exchange Online, Teams, SharePoint, OneDrive for Business, and several other Microsoft 365 services. Mailbox connectivity returned within about 12 hours, while search functionality across the affected services stayed degraded into September 2. BleepingComputer

US Charges Extradited Russian National Over Malware Campaign Against 80,000 Freelancers
A federal grand jury indicted Searzhudin Tamirlanovich Aktulaev, extradited after his arrest in Cyprus, on conspiracy, computer damage, and aggravated identity theft charges tied to a phishing campaign running from 2016 to 2017. Prosecutors say Aktulaev used 255 fake accounts on a freelance platform to send malicious Excel macro attachments to 80,000 freelancers, deploying TVRAT and DarkVNC remote-access tools to steal credentials and personal data. Roughly half the victims were located in the United States. BleepingComputer

OpenAI Says Astra Model Crosses “Critical” Cybersecurity Capability Threshold
OpenAI says its newest model, Astra, reached the “Critical” tier under the company’s Preparedness Framework after finding zero-day vulnerabilities during testing, the first time an OpenAI model has reached this classification. The designation follows an earlier pause on Astra’s development and a broader security overhaul including stricter sandboxing and a 30-minute alerting system for concerning model behavior. SecurityWeek

Meta and TikTok Ads Push New StreamRat Android Trojan to Spanish-Speaking Users
Researchers at ThreatFabric disclosed StreamRat, a new Android banking trojan distributed through fake television-streaming advertisements on Meta platforms and TikTok, reaching an estimated 570,950 accounts in the European Union. Once sideloaded, the malware abuses Android’s MediaProjection API and Accessibility services to capture the screen and grant operators near-complete control of infected devices. The Hacker News

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.