Rapid7 reports that a stealthy espionage campaign has compromised South Korean automotive and media companies since early 2025, with medium-confidence attribution to North Korean APT37 based on overlapping command-and-control infrastructure. The attackers exploited the open-source HAProxy load balancer to install a custom Linux toolkit called TED, granting them visibility into and control over victims' network traffic.
darkreading.com
· 2026-09-16
SonicWall disclosed two vulnerabilities in its SMA 1000 series appliances: a maximum-severity SSRF flaw (CVE-2026-83548) in the user-facing Work Place portal and an OS command injection bug (CVE-2026-83549) in the admin console. SonicWall's security team confirmed active exploitation in the wild and urged customers to patch immediately, while researchers at Rapid7 noted the two bugs can be chained together for unauthenticated remote code execution.
darkreading.com
· 2026-09-02
Threat intelligence firm Defused reports that hackers are actively probing SharePoint servers by combining two vulnerabilities: an authentication bypass in JWT token validation (CVE-2026-55040) and a Business Connectivity Services flaw (CVE-2026-63520) that enables remote code execution. Proof-of-concept code for both bugs was published publicly in August by researchers at Rapid7 and VulnCheck, and Defused says it has already observed the bypass being exploited alongside admin enumeration on honeypots, though no successful code execution has been confirmed yet.
bleepingcomputer.com
· 2026-08-26