Daily Security Intel

Archives
Log in
Subscribe
September 3, 2026

[SecurityIntel] 03 Sep | BGP Hijack Delivers Malicious Virtualizor Software Updates

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, September 03, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

BGP Hijack Delivers Malicious Virtualizor Software Updates

CRITICAL

5

C2 IPs

81

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by highly sophisticated infrastructure attacks and critical software vulnerabilities, notably a BGP hijack targeting Softaculous to distribute malicious Virtualizor updates, and active zero-day exploits targeting SonicWall SMA 1000 series VPNs. Additionally, threat actors are leveraging social engineering via Microsoft Teams to impersonate IT support and deploy Node.js implants, while critical vulnerabilities in JFrog Artifactory (CVE-2026-82329) and Sangoma Switchvox (CVE-2026-9586) are being actively targeted. Organizations must immediately prioritize patching these edge devices, web applications, and developer environments to prevent unauthorized administrative access and remote code execution.

■ CRITICAL STORIES

CRITICAL#1

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Threat actors executed a highly sophisticated Border Gateway Protocol (BGP) hijack to divert Softaculous traffic and deliver malicious Virtualizor update packages. This supply-chain attack allowed attackers to bypass standard trust boundaries using valid TLS certificates and establish persistent root access on affected host installations.

CRITICAL#2

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has rushed out security patches for two zero-day vulnerabilities in its SMA 1000 series VPN appliances that are actively being exploited in the wild. If chained, these flaws allow unauthenticated remote attackers to compromise enterprise perimeter security and gain internal network access.

CRITICAL#3

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is under active exploitation. Attackers are leveraging the flaw to forge admin tokens, granting them full administrative control over software repositories and enabling potential downstream supply chain attacks.

HIGH#4

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft has warned of a human-operated campaign where attackers use Microsoft Teams external collaboration to impersonate IT support staff. This social engineering tactic tricks users into initiating remote sessions, leading to the deployment of a Node.js-based implant and subsequent network-wide lateral movement.

■ CVEs IDENTIFIED

CVE-2026-9586

Sangoma Switchvox — Unauthenticated SQL injection leading to remote code execution (RCE)

Critical

CVE-2026-82329

JFrog Artifactory — Authentication bypass allowing administrative token forgery

Critical

[CVE-TBD]

SonicWall SMA 1000 Series — Zero-day vulnerability chain leading to appliance compromise

Critical

[CVE-TBD]

WordPress All-in-One WP Migration and Backup Plugin — SQL injection leading to remote code execution and site takeover

Critical

■ THREAT ACTORS

Gambling Goblin

Cybercrime Cluster

Installing malicious Apache modules on compromised web servers in Brazil to divert traffic to betting sites.

VantaCore

Ransomware Group

Targeting Russian companies with custom ransomware in pro-Ukraine hacktivist campaigns.

Searzhudin Tamirlanovich Aktulaev

Individual / Cybercriminal

Indicted for orchestrating a malware campaign using TVRAT and DarkVNC to infect 80,000 freelancers.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploited in Sangoma Switchvox (CVE-2026-9586), JFrog Artifactory (CVE-2026-82329), Cleo Harmony, and SonicWall SMA 1000 zero-days.
T1584.004
Compromise Infrastructure: DNS / BGP Hijacking | Threat actors hijacked BGP routing to divert Softaculous update traffic to deliver malicious Virtualizor updates.
T1195.002
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malicious Virtualizor updates served to hosting providers via diverted traffic.
T1566.003
Phishing: Spearphishing Link | Threat actors used Microsoft Teams external collaboration to impersonate IT support and trick users into remote sessions.
T1219
Remote Access Software | Attackers used remote sessions to gain enterprise-wide access and deploy Node.js-based implants.
T1562.001
Impair Defenses: Disable or Modify Tools | Malicious software installers disabled Windows Update and weakened Microsoft Defender.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — Sangoma Switchvox — CVE-2026-9586 unauthenticated SQL injection leading to RCE — [BC] Hackers exploit Sangoma Switchvox flaw

[P3 PATCH NOW]≤1 week

CRITICAL — JFrog Artifactory — CVE-2026-82329 authentication bypass leading to admin token forgery — [BC] Hackers exploit critical JFrog Artifactory flaw

[P3 PATCH NOW]≤1 week

CRITICAL — SonicWall SMA 1000 series VPN — Zero-day vulnerabilities exploited in the wild — [THN] Attackers Exploit Two SonicWall SMA 1000 Zero-Days

[P3 PATCH NOW]≤1 week

CRITICAL — WordPress All-in-One WP Migration and Backup plugin — Critical SQL injection leading to RCE and site takeover — [BC] WordPress backup plugin flaw

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Now: Immediately apply security updates for Sangoma Switchvox to address the CVE-2026-9586 SQL injection vulnerability.
2[P1] Patch Now: Apply the latest security patches for JFrog Artifactory to mitigate CVE-2026-82329 and prevent administrative token forgery.
3[P1] Patch Now: Deploy emergency firmware updates released by SonicWall for SMA 1000 series VPN appliances to remediate the actively exploited zero-day vulnerabilities.
4[P1] Patch Now: Update Google Chrome and Mozilla Firefox to their latest versions to patch critical use-after-free and sandbox escape vulnerabilities.
5[P1] Patch Now: Apply updates to WordPress All-in-One WP Migration and Backup plugin to resolve the critical SQL injection vulnerability.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 04 Sep | Critical Cisco Nexus Root RCE Flaw Actively Threatens Older → [SecurityIntel] 02 Sep | Critical Langflow and JFrog Flaws Exploited Wildly
Powered by Buttondown, the easiest way to start and grow your newsletter.