ARCHIVED READING · PERMANENT RECORD
WEEK OF SEPTEMBER 7, 2026
69/ 100HIGH PRESSURE
Two chained SonicWall zero-days and admin-token forgery in Artifactory lead a hot exploitation week, while three material-incident filings mark rising intrusion tempo.
↑ 3 POINTS SINCE LAST WEEK2026-W37ISSUED 2026-09-07 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION↑
RISING
Nine current KEV additions — no vintage padding this week — led by two SonicWall SMA1000 zero-days that may chain, and an Artifactory flaw exploited to mint admin tokens days after disclosure.
RATIONALE & SOURCE TYPES
CISA added seven CVEs on Sep 2 (two SonicWall SMA1000 zero-days reportedly forming an attack chain — SonicWall's third appearance in five weeks; JFrog Artifactory improper authentication exploited to forge admin tokens; Sangoma Switchvox delivering reverse shells; Kestra, Starlette, and LiteLLM — developer and AI infrastructure again) after cataloging both PaperCut zero-days on Aug 31. Elementor Pro exploitation and Langflow/Rails credential-probing continue. All nine are current-year flaws under active attack. Confidence is high.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
An RMM-lure phishing wave makes the US its top target across 46 countries; the Shai-Hulud credential worm's reach keeps growing.
RATIONALE & SOURCE TYPES
A large phishing campaign impersonating remote-management tools now spans 46 countries with the US the top target; the Shai-Hulud npm credential worm's haul grew to 469 credential locations; China-linked Fire Ant hijacks Cisco routers to steal credentials and blind logging. Significant activity, but all evidence sits in one source class this week, so the two-source rule holds the signal steady. Confidence is medium.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO↑
RISING
Three material-incident (Item 1.05) filings in one window — triple the recent baseline — alongside a court-records breach spanning twelve jurisdictions.
RATIONALE & SOURCE TYPES
Nutex Health, Park Dental Partners, and NovoCure all filed Item 1.05 8-Ks this window — three material cybersecurity incidents against a baseline of roughly one per week — providing the public-disclosure source class that, with incident reporting, satisfies the two-source rule for a raise. Thomson Reuters' C-Track court platform breach was publicly disclosed Sep 2 (intrusion ran March–June), potentially exposing SSNs and sealed documents across twelve jurisdictions; Aurora ransomware operators used AI-assisted tooling against ten targets. Confidence is medium: disclosure lag limits week-level precision.
PUBLIC DISCLOSUREINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch or take SonicWall SMA1000 appliances offline now — two zero-days that may chain are under active exploitation — and hunt for pre-patch access.
02Patch Artifactory, then rotate tokens and audit admin-token issuance since disclosure; treat artifact registries and CI secrets as tier-0.
03Brief helpdesk and MSP contacts on the RMM-impersonation phishing wave; pin an allowlist of approved remote-access tools and alert on the rest.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 3711 RECEIPTS
REVISION HISTORY
2026-09-07 · 14:00 UTCOriginal publication.
← FULL ARCHIVE