daily cyber × ai intelligence

index

tagged

[CVE-2026-83548]

2 editions · 2 items

September 4, 2026

  • CISA added seven actively exploited flaws to KEV, spanning an unusually broad stack: CVE-2026-83548 (SonicWall SMA 1000 pre-auth SSRF, CVSS 10.0), CVE-2026-82329 (JFrog Artifactory auth bypass), CVE-2026-9586 (Sangoma Switchvox pre-auth SQLi), CVE-2026-59822 (BerriAI LiteLLM improper authentication), CVE-2026-48710 (Starlette request smuggling) and CVE-2026-49869 (Kestra OSS command injection) (CISA). Observed post-exploitation is reverse shells and crypto miners (The Hacker News); the Artifactory bug is being used to forge admin tokens (BleepingComputer). LiteLLM sitting in KEV is the signal to watch — AI gateway middleware is now in the exploited-in-the-wild category. · Exploitation & Vulnerabilities

in Malware That Gaslights the AI Analyst

September 3, 2026

  • SonicWall SMA 1000 zero-days chained for unauthenticated RCE, exploited in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-auth SSRF in the Appliance Work Place interface; chained with CVE-2026-83549 it yields unauthenticated remote code execution. Both were found internally by SonicWall and are confirmed under active exploitation (SonicWall PSIRT, BleepingComputer). This is the third round of edge-device zero-day exploitation at the vendor this summer (Dark Reading). · Vulnerabilities & Exploitation

in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion