SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, September 03, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY BGP Hijack Delivers Malicious Virtualizor Software Updates | CRITICAL |
|
5 C2 IPs | 81 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by highly sophisticated infrastructure attacks and critical software vulnerabilities, notably a BGP hijack targeting Softaculous to distribute malicious Virtualizor updates, and active zero-day exploits targeting SonicWall SMA 1000 series VPNs. Additionally, threat actors are leveraging social engineering via Microsoft Teams to impersonate IT support and deploy Node.js implants, while critical vulnerabilities in JFrog Artifactory (CVE-2026-82329) and Sangoma Switchvox (CVE-2026-9586) are being actively targeted. Organizations must immediately prioritize patching these edge devices, web applications, and developer environments to prevent unauthorized administrative access and remote code execution. |
|
■ CRITICAL STORIES BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access Threat actors executed a highly sophisticated Border Gateway Protocol (BGP) hijack to divert Softaculous traffic and deliver malicious Virtualizor update packages. This supply-chain attack allowed attackers to bypass standard trust boundaries using valid TLS certificates and establish persistent root access on affected host installations. |
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain SonicWall has rushed out security patches for two zero-day vulnerabilities in its SMA 1000 series VPN appliances that are actively being exploited in the wild. If chained, these flaws allow unauthenticated remote attackers to compromise enterprise perimeter security and gain internal network access. |
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is under active exploitation. Attackers are leveraging the flaw to forge admin tokens, granting them full administrative control over software repositories and enabling potential downstream supply chain attacks. |
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Microsoft has warned of a human-operated campaign where attackers use Microsoft Teams external collaboration to impersonate IT support staff. This social engineering tactic tricks users into initiating remote sessions, leading to the deployment of a Node.js-based implant and subsequent network-wide lateral movement. |
|
■ CVEs IDENTIFIED CVE-2026-9586 Sangoma Switchvox — Unauthenticated SQL injection leading to remote code execution (RCE) |
CVE-2026-82329 JFrog Artifactory — Authentication bypass allowing administrative token forgery |
[CVE-TBD] SonicWall SMA 1000 Series — Zero-day vulnerability chain leading to appliance compromise |
[CVE-TBD] WordPress All-in-One WP Migration and Backup Plugin — SQL injection leading to remote code execution and site takeover |
|
■ THREAT ACTORS Gambling Goblin | Cybercrime Cluster |
Installing malicious Apache modules on compromised web servers in Brazil to divert traffic to betting sites. |
VantaCore | Ransomware Group |
Targeting Russian companies with custom ransomware in pro-Ukraine hacktivist campaigns. |
Searzhudin Tamirlanovich Aktulaev | Individual / Cybercriminal |
Indicted for orchestrating a malware campaign using TVRAT and DarkVNC to infect 80,000 freelancers. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploited in Sangoma Switchvox (CVE-2026-9586), JFrog Artifactory (CVE-2026-82329), Cleo Harmony, and SonicWall SMA 1000 zero-days. |
| T1584.004 | | Compromise Infrastructure: DNS / BGP Hijacking | Threat actors hijacked BGP routing to divert Softaculous update traffic to deliver malicious Virtualizor updates. |
| T1195.002 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malicious Virtualizor updates served to hosting providers via diverted traffic. |
| T1566.003 | | Phishing: Spearphishing Link | Threat actors used Microsoft Teams external collaboration to impersonate IT support and trick users into remote sessions. |
| T1219 | | Remote Access Software | Attackers used remote sessions to gain enterprise-wide access and deploy Node.js-based implants. |
| T1562.001 | | Impair Defenses: Disable or Modify Tools | Malicious software installers disabled Windows Update and weakened Microsoft Defender. |
|
■ PATCH PRIORITY CRITICAL — Sangoma Switchvox — CVE-2026-9586 unauthenticated SQL injection leading to RCE — [BC] Hackers exploit Sangoma Switchvox flaw |
CRITICAL — JFrog Artifactory — CVE-2026-82329 authentication bypass leading to admin token forgery — [BC] Hackers exploit critical JFrog Artifactory flaw |
CRITICAL — SonicWall SMA 1000 series VPN — Zero-day vulnerabilities exploited in the wild — [THN] Attackers Exploit Two SonicWall SMA 1000 Zero-Days |
CRITICAL — WordPress All-in-One WP Migration and Backup plugin — Critical SQL injection leading to RCE and site takeover — [BC] WordPress backup plugin flaw |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Now: Immediately apply security updates for Sangoma Switchvox to address the CVE-2026-9586 SQL injection vulnerability. |
| 2 | [P1] Patch Now: Apply the latest security patches for JFrog Artifactory to mitigate CVE-2026-82329 and prevent administrative token forgery. |
| 3 | [P1] Patch Now: Deploy emergency firmware updates released by SonicWall for SMA 1000 series VPN appliances to remediate the actively exploited zero-day vulnerabilities. |
| 4 | [P1] Patch Now: Update Google Chrome and Mozilla Firefox to their latest versions to patch critical use-after-free and sandbox escape vulnerabilities. |
| 5 | [P1] Patch Now: Apply updates to WordPress All-in-One WP Migration and Backup plugin to resolve the critical SQL injection vulnerability. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |