Author: Osiris

  • Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    Maximum-Severity SonicWall SMA 1000 Flaws Under Active Exploitation, CISA Warns

    SonicWall disclosed on September 1, 2026 that two vulnerabilities in its SMA 1000 series secure remote access appliances are being actively exploited in the wild, according to the vendor’s own advisory, SNWLID-2026-0016, and confirmed by CISA, Rapid7 and Qualys Threat Protect.

    A Chainable Path to Unauthenticated RCE

    The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance Work Place interface, carrying the maximum possible CVSS score of 10.0. According to SonicWall’s advisory, an unintended alternate access path causes the appliance to act as an unintended forward proxy, letting a remote unauthenticated attacker reach sensitive functionality. Rapid7’s analysis found that this SSRF flaw can be chained with a second, high-severity OS command injection vulnerability in the Appliance Management Console, CVE-2026-83549, which normally requires authenticated administrator access, to achieve full unauthenticated remote code execution.

    Federal Deadline and Wide Exposure

    CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 5, 2026 remediation deadline for federal civilian agencies. SonicWall SMA 1000 appliances are widely deployed as VPN and zero-trust access gateways by large enterprises, government agencies and managed service providers, making the appliance an attractive target given the level of internal network access it typically brokers.

    Response

    SonicWall has released a hotfix addressing CVE-2026-83548; the company states no workaround is available for organizations that cannot immediately patch. Security researchers recommend organizations apply the hotfix without delay, review SMA 1000 logs for signs of the unauthorized proxy behavior described in the advisory, and treat any indicators of compromise found before the patch was applied as a potential breach requiring further investigation.

  • Microsoft Preparing to Unveil Maia 300 AI Chip as Early as This Month

    Microsoft Preparing to Unveil Maia 300 AI Chip as Early as This Month

    Microsoft is planning to unveil its next-generation Maia 300 AI accelerator chip this fall, potentially as soon as September, Reuters reported on August 10, 2026, citing a report from The Information based on people with direct knowledge of the plans. The report has since been corroborated by multiple outlets including Yahoo Finance and Quartz, though Microsoft has not confirmed an exact date.

    A Third Attempt at Homegrown AI Silicon

    Maia 300 would be Microsoft’s third generation of custom AI silicon following Maia 100, introduced in November 2023, and Maia 200, which arrived in January 2026 built on TSMC’s 3-nanometer process with a large SRAM allocation for inference throughput. According to Reuters, Microsoft is negotiating with TSMC to secure manufacturing capacity for more than 300,000 Maia 300 units for delivery in 2027, with an eventual goal of surpassing one million units, though component supply and ongoing capacity talks could constrain that target. Microsoft general manager for Azure Maia, Andrew Wall, said in a statement reported by Reuters that the company “continues to invest in custom silicon as part of our long-term AI infrastructure strategy,” without confirming reported production volumes.

    Reducing Reliance on Nvidia

    The push comes as Microsoft has lagged rivals Alphabet and Amazon in scaling in-house AI chip programs to reduce dependence on Nvidia’s GPUs. Reuters reported that Microsoft is also seeking to pitch Maia 300 to external cloud customers, including Anthropic, as an alternative to Nvidia hardware. The timing places Maia 300 alongside a broader wave of hyperscaler silicon activity in 2026, including Google’s Ironwood TPU reaching general availability and Meta beginning production of its own AI chip in September.

    What to Watch

    Because Maia 300 has not yet been formally unveiled, key questions remain open: which cloud customers, if any, will be named at launch, what performance benchmarks Microsoft will disclose against Nvidia’s Blackwell-generation chips, and whether the TSMC capacity Microsoft is seeking will materialize on the timeline reported. Widespread availability is not expected before 2027 even if the chip is revealed this fall.

  • UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    UK Aviation Cyber Assessment Finds Suppliers Are the Sector’s Weakest Link

    A new assessment of UK aviation’s external cyber exposure has found that third-party suppliers, not airport operators, account for the overwhelming majority of the sector’s cyber security weaknesses, according to research firm MyDomainRisk and coverage published by International Airport Review on September 3, 2026.

    Scanning 43 Operators and 51 Suppliers From the Outside

    MyDomainRisk said it examined the public web estate of 43 UK airport operators, covering 54 airports, alongside 51 organizations those airports depend on, using only externally visible, unauthenticated scanning. The firm emphasized that no airport operational technology, air-traffic, airline, baggage-handling or screening system was accessed or tested as part of the work; the scope was limited to what is visible to anyone on the public internet.

    Exposure Is Concentrated in the Supply Chain

    Of 1,152 exposed employee credential records identified across both groups, only 10 belonged to airport operators, according to MyDomainRisk; the remainder sat with suppliers, which also accounted for three leak-site mentions. Ground-operations providers were flagged as the weakest supplier class, with the firm reporting that 92 percent of staff-credential exposure across the study sits within three airside supplier categories. Gabriel Higgins, writing for International Airport Review, said suppliers’ average security posture score badly trailed that of the operators they serve.

    The One Place Airports Underperform

    The assessment identified a single measure where airport operators scored worse than their suppliers: email authentication. Seventeen of the 43 airport operators studied, or 40 percent, cannot instruct receiving mail systems to reject an email forged in their name, according to the research. Higgins quoted the study’s author describing this as both one of the sector’s simplest fixes and one of its most consequential, since an airport’s own domain is a far more attractive identity for attackers to spoof than that of a lesser-known supplier.

  • Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google Patches Actively Exploited Chrome V8 Zero-Day, Sixth of 2026

    Google released Chrome 152 security updates on September 3, 2026, patching 12 vulnerabilities including a high-severity flaw that attackers are already exploiting, according to Google’s own advisory and reporting from The Hacker News, SecurityWeek and BleepingComputer.

    A Type Confusion Bug in Chrome’s Core Engine

    The exploited flaw, tracked as CVE-2026-85046 and rated CVSS 8.8, is a type confusion vulnerability in V8, the JavaScript and WebAssembly engine that powers Chrome. Google’s advisory describes the bug as allowing a remote attacker to execute arbitrary code inside Chrome’s sandbox via a specially crafted HTML page. Google said it is aware that an exploit for the flaw exists in the wild but withheld technical details of the observed attacks to limit further exploitation while users update. Security researcher Salvatore Gulizia, credited with reporting the issue on August 4, 2026, received a $1,000 bug bounty for the disclosure.

    Sixth Exploited Chrome Zero-Day This Year

    CVE-2026-85046 is the sixth actively exploited Chrome zero-day Google has patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The same update, which brings Chrome to version 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, also fixes nine other high-severity issues spanning Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools and Skia components.

    Why It Matters for Security Operators

    Chromium-based browsers sit behind a large share of enterprise workstations, control-room terminals and web-based video management and access-control clients, making browser zero-days a recurring entry point into otherwise segmented environments. Google is rolling out the fix gradually; users and IT administrators are advised to confirm they are running version 152.0.7977.82 or later via Chrome’s Settings > About Chrome menu and restart the browser to complete the update rather than waiting for automatic rollout.

  • Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Attackers Exploit MikroTik RouterOS Flaw Chain to Seize Routers Without Authentication

    Poland’s national CSIRT, CERT Polska, disclosed on September 5, 2026 that attackers are actively exploiting a chain of MikroTik RouterOS vulnerabilities to gain full administrative control of internet-exposed routers with no valid login and no private key required, according to CERT Polska’s advisory and reporting by The Hacker News and Security Affairs.

    Two Flaws Chained Into Full Takeover

    CERT Polska disclosed six RouterOS vulnerabilities in total, naming the exploited chain “MikroTrick.” The first, CVE-2026-67276 (CVSS 9.2), is an SSH authentication bypass rooted in how RouterOS verifies RSA public keys: an attacker who knows a valid username and the public portion of that user’s RSA key can forge a key and log in without possessing the corresponding private key. The second, CVE-2026-86060 (CVSS 9.2), is a privilege-escalation flaw triggered by a crafted username beginning with a disallowed character, which alters the trusted RouterOS policy mask and grants the resulting SSH session full administrative rights. Chained together, the two flaws let an attacker take over any internet-facing RouterOS device with SSH enabled.

    Exploitation Already Under Way

    CERT Polska said observed exploitation dates back to at least September 2, 2026, three days before public disclosure. Independent researcher Costin Raiu published a technical breakdown the same day as the advisory, writing that anyone running a MikroTik router with SSH exposed to the internet should treat the device as compromised until proven otherwise. Shodan scans referenced in coverage of the advisory show roughly 300,000 vulnerable devices still reachable from the public internet.

    Fixes and Recommended Response

    MikroTik has released patched builds: 6.49.21 for the long-term 6.x branch, 7.23.4 for the long-term 7.x branch, and 7.24.2 for the stable 7.x branch. CERT Polska is advising administrators to update immediately, restrict SSH management access to trusted networks rather than the open internet, and check devices for unknown users, unfamiliar scripts and other signs of compromise before assuming a device is clean.

  • Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Sangoma Switchvox Flaw Under Active Exploitation as CISA Sets Federal Patch Deadline

    Threat actors are actively exploiting a critical vulnerability in Sangoma’s Switchvox enterprise VoIP phone system, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog and order federal civilian agencies to remediate it on an accelerated timeline, according to Horizon3.ai, SecurityWeek and CISA’s own advisory.

    An Unauthenticated Path to Remote Code Execution

    Tracked as CVE-2026-9586 and rated CVSS 9.3, the flaw sits in Switchvox’s /pa endpoint, which processes XML content from supported IP phones. According to research published by Horizon3.ai, the endpoint concatenates a user-controlled PhoneIP value directly into PostgreSQL queries without sanitization or parameterization, allowing an unauthenticated remote attacker to execute arbitrary SQL with a single crafted HTTP request. Horizon3.ai reported that exploitation can be chained into full remote code execution, including database modification, privilege escalation within the application, operating-system command execution and extraction of authentication secrets.

    Patch Timeline and a Compressed Federal Deadline

    Horizon3.ai said it reported the flaw to Sangoma in April 2026, and Sangoma shipped a fix in Switchvox 8.4.0.2 on July 14, 2026. Security firm Field Effect reported that researchers began observing exploitation attempts in the wild on August 30, 2026, including reverse-shell deployment and post-exploitation reconnaissance on compromised systems. CISA added CVE-2026-9586 to its KEV catalog on September 2, 2026, and set a September 5, 2026 remediation deadline for federal civilian agencies under Binding Operational Directive 26-04.

    Why It Matters

    Shodan scans cited by researchers show roughly 4,000 Switchvox systems reachable from the open internet. Because Switchvox functions as a business’s core telephony and call-management platform, a successful compromise can expose call records, credentials and internal network access alongside the immediate database and code-execution impact. Organizations running on-premises Switchvox deployments are advised to apply version 8.4.0.2 or later immediately, restrict management interfaces from the public internet, and review logs for indicators of compromise identified by Horizon3.ai and Field Effect.

  • Biometric Access Control Compared: Fingerprint, Iris, Face and Vein Recognition

    Biometric Access Control Compared: Fingerprint, Iris, Face and Vein Recognition

    Biometric access control has moved from a specialist technology into a mainstream option for offices, data centers, airports and critical infrastructure sites. But “biometrics” is not one technology — fingerprint, iris, facial and vein-pattern recognition each rely on different physical traits, different sensors and different deployment trade-offs. Choosing the right modality, or combination of modalities, depends heavily on the environment, the threat model and how the system will be used day to day.

    Fingerprint Recognition

    Fingerprint readers remain the most widely deployed biometric modality because the sensors are inexpensive, compact and familiar to users from consumer smartphones. Most systems capture a digital image of the fingerprint ridge pattern and extract minutiae points — the specific locations where ridges end or split — to build a template for matching, rather than storing the raw image. Fingerprint readers perform well in controlled indoor environments but can struggle with dirty, wet, gloved or worn fingertips, which is a common consideration for industrial and outdoor sites.

    Iris Recognition

    Iris recognition captures the intricate pattern in the colored ring around the pupil using a near-infrared camera, converting the pattern into a mathematical template. Because the iris pattern is highly detailed and stable over a person’s lifetime, iris systems are often used where very high assurance is required, such as border control, data centers and other high-security facilities. Iris cameras typically require the user to look toward the sensor within a defined distance, which makes enrollment and enforcement more deliberate than a simple badge tap.

    Facial Recognition

    Facial recognition systems map geometric features of the face, or increasingly use deep-learning models to generate a numerical embedding of the face, and compare that embedding against enrolled templates. The major advantage of facial recognition for access control is speed and convenience: many systems can identify an authorized person without requiring them to touch a sensor or stop moving, which supports high-traffic entrances and touchless access goals. Accuracy can be affected by lighting conditions, camera angle, face coverings and image quality, and the technology has also drawn regulatory and public scrutiny over data protection and consent, which organizations need to factor into deployment plans.

    Vein Pattern Recognition

    Vein recognition, most commonly implemented as finger-vein or palm-vein scanning, uses near-infrared light to image the pattern of veins beneath the skin’s surface, since deoxygenated blood in veins absorbs infrared light differently than surrounding tissue. Because the vein pattern sits inside the body rather than on an exposed surface, it is difficult to capture or replicate without the cooperation of a live subject, which makes vein recognition attractive for high-security financial and data center environments concerned about spoofing. The trade-off is that vein scanners are typically more expensive than fingerprint or facial recognition hardware and are less commonly integrated into general-purpose access control platforms.

    Choosing the Right Modality

    In practice, the choice between modalities usually comes down to a handful of operational questions: How much throughput does the entrance need to support? Will users wear gloves, masks or personal protective equipment on site? Is the environment indoors and climate-controlled, or exposed to dirt, moisture and temperature swings? And what level of assurance does the asset being protected actually require? Many organizations end up deploying more than one modality across a site — for example, facial recognition for high-traffic general entrances and iris or vein recognition for a smaller number of high-security zones such as server rooms or vaults.

    Privacy and Data Protection Considerations

    Because biometric data is permanently tied to an individual and cannot be reset the way a password or badge can, organizations deploying any of these modalities need a clear policy for how templates are stored, encrypted, and eventually deleted, along with a legal basis for collecting biometric data that satisfies applicable regional privacy laws. Storing a mathematical template rather than a raw image, and keeping that template on a secure local device rather than in a shared cloud database, are common practices for reducing the impact of a potential breach.

  • NHTSA Opens Audit Into Tesla’s Cybercab Safety Self-Certification After Austin Launch

    NHTSA Opens Audit Into Tesla’s Cybercab Safety Self-Certification After Austin Launch

    The National Highway Traffic Safety Administration (NHTSA) has opened an Audit Query, numbered AQ26002, into the technical data and process Tesla used to self-certify that its new Cybercab complies with all applicable Federal Motor Vehicle Safety Standards (FMVSS), according to an NHTSA press release and reporting by the New York Times and Electrek. The investigation, opened September 3, 2026, covers an estimated 1,000 Cybercab vehicles and was prompted by public information, according to the filing.

    A Vehicle With No Manual Controls

    Cybercab has no steering wheel or pedals, and Tesla began putting paying passengers in the vehicles in Austin, Texas the same day the audit was opened. NHTSA said it will examine “the extent to which Tesla’s certification depended on determinations that certain FMVSS are inapplicable to the Cybercab,” according to Electrek, focusing on whether standards written for vehicles with traditional human controls can be validly waived for a fully autonomous design.

    How Self-Certification Works

    Under the US system, automakers certify their own compliance with federal safety standards rather than obtaining pre-approval from regulators, with NHTSA auditing that certification after the fact. The audit will assess the technical data and processes underlying Tesla’s compliance determination and how occupant protection is addressed in a vehicle operating without a human driver behind physical controls, according to NHTSA.

    Stakes for Tesla’s Robotaxi Rollout

    Tesla has said it plans to gradually expand Cybercab deployment to more vehicles and locations. The outcome of the audit could influence the pace of that expansion and is being closely watched as a test case for how federal vehicle safety standards, largely written around human-operated cars, apply to commercially deployed vehicles with no manual controls at all.

  • Nvidia Agrees to Buy Hugging Face for Roughly $13 Billion in Push Up the AI Stack

    Nvidia Agrees to Buy Hugging Face for Roughly $13 Billion in Push Up the AI Stack

    Nvidia has agreed to acquire open-source artificial intelligence platform Hugging Face for approximately $12.9 billion, according to CNBC, the Wall Street Journal and the BBC. The deal, confirmed on September 3, 2026, is Nvidia’s second-largest acquisition after its roughly $20 billion purchase of Groq’s assets late last year, and marks one of the chipmaker’s biggest moves yet to expand beyond hardware and further up the AI software stack.

    Deal Terms and Scale

    Under the agreement, Nvidia will pay about $11.9 billion to Hugging Face investors and offer up to $1 billion in stock-based incentives to employees who join the company, according to the BBC. Hugging Face is used by more than 18 million developers and hosts more than three million AI models, with over 200,000 companies using the platform to discover and deploy AI, the companies said.

    Nvidia Pledges to Keep the Platform Open

    Nvidia CEO Jensen Huang said in a blog post that the companies will “scale Hugging Face’s platform, strengthen its infrastructure and expand access to AI for developers and institutions worldwide,” and that Hugging Face will remain an open platform for the broader AI ecosystem rather than being tied exclusively to Nvidia chips or services, according to CNBC.

    Why It Matters for the AI Ecosystem

    The acquisition comes as Nvidia works to counter the rapid rise of open-weight models developed in China, which pose a growing competitive challenge to leading US AI companies, according to the Wall Street Journal. Industry observers noted the deal could be read either as a consolidation risk for an independent hub of open AI development, or, if Nvidia keeps its commitment to openness, as a boost to smaller developers and startups that rely on Hugging Face’s tooling and model hosting.

  • Public Comment Period Closes Today on Federal Rule Expanding Counter-Drone Authority for Local Police

    Public Comment Period Closes Today on Federal Rule Expanding Counter-Drone Authority for Local Police

    A federal rule that would give trained state, local, tribal and territorial (SLTT) law enforcement and correctional agencies formal authority to detect, track, disable or seize threatening drones closes for public comment on September 6, 2026, according to DRONELIFE. The Interim Final Rule, published by the Department of Homeland Security (DHS) and Department of Justice (DOJ), is the first detailed implementing regulation for counter-unmanned aircraft system (C-UAS) powers created under the SAFER SKIES Act, part of the FY2026 National Defense Authorization Act.

    Certification, Training and Two Approved-Systems Lists

    The rule sets out training and certification requirements, reporting procedures and operational safeguards for agencies seeking to conduct counter-drone operations against credible threats to public safety, critical infrastructure, correctional facilities or major public events. It also establishes an Authorized Technologies List and a more specific Authorized Systems List, both to be maintained through the FBI’s Law Enforcement Enterprise Portal, identifying which categories and specific counter-UAS products agencies may lawfully deploy.

    FCC Actions Address Spectrum and Legal Liability

    Alongside the DHS/DOJ rule, the Federal Communications Commission issued four coordinated actions intended to remove practical barriers to deployment. These include a 180-day blanket Special Temporary Authority letting eligible agencies operate approved counter-UAS systems while longer-term licensing is developed, an equipment-authorization waiver allowing manufacturers to sell approved radio-frequency systems to qualified agencies sooner, and declaratory rulings clarifying that SLTT personnel acting under the Act’s oversight can receive derivative immunity from Section 333 of the Communications Act, which otherwise prohibits interference with licensed radio communications.

    Guardrails Remain in Place

    The frameworks do not authorize unrestricted counter-drone activity. Agencies must still meet federal certification requirements, use only systems on the Authorized Systems List, follow operational restrictions written into the SAFER SKIES Act, and report qualifying mitigation actions to federal authorities. With the comment period closing today, stakeholders across the public safety, drone and counter-UAS industries have had a final opportunity to weigh in before the rule is finalized.