grc-scanSecurity & governance
News digest3 September 2026Archived edition

Cybersecurity News

This edition was published on 3 September 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This edition's stories share one thread: attackers are going after the systems built to prove who someone is — VPN logins, single sign-on, mail servers, ID checks — rather than breaking in through the front door.

  • Patch internet-facing VPN and mail-server appliances (SonicWall, Exchange) the moment a fix ships — public exploit code turns a bug into mass scanning within days.
  • Require MFA on every login option, including "sign in with" shortcuts — every hacked account in this edition's Dropbox breach lacked it.
  • Treat a driver's-licence or ID-verification leak as advance warning of impersonation attempts, not just data theft.

Cybersecurity News — 2026-09-03

Generated: 2026-09-03 | Sources: BleepingComputer, Help Net Security, SecurityWeek, The Hacker News, Cybernews, TechRadar, Malwarebytes, Sophos


1. Two Unpatched Flaws in a Popular Remote-Access Appliance Are Being Actively Exploited

SonicWall has warned that two previously unknown vulnerabilities in its SMA1000 range of secure remote-access appliances — the boxes many businesses use to let staff connect to internal systems from outside the office — are being exploited right now. One flaw lets an attacker reach privileged internal functions with no login at all; chained with the second, it lets them run their own commands directly on the device that decides who gets onto the network. SonicWall has confirmed active exploitation and released a hotfix for both.

Why it matters for your business: if your business or IT provider uses a SonicWall SMA1000 appliance for remote access or VPN, install the hotfix immediately rather than waiting for a routine maintenance window — this is the device that decides who's allowed onto your network, so a compromise here bypasses everything behind it.


2. Attackers Broke Into 5,000 Dropbox Accounts Using Nothing But an Email Address

Dropbox confirmed that roughly 5,000 accounts were accessed without permission after attackers exploited a flaw in Lenovo's sign-in system, which some Dropbox users had linked as a "sign in with Lenovo ID" shortcut. A gap in Lenovo's email verification let someone register a new Lenovo ID using a stranger's email address, then use that ID to log straight into the matching Dropbox account — no password needed. Dropbox says every affected account lacked multi-factor authentication, which would have stopped the takeover even with the underlying flaw in play.

Why it matters for your business: check which staff use "sign in with X" shortcuts (Google, Microsoft, Lenovo, and similar) for business accounts, and make sure multi-factor authentication is switched on for the account being logged into, not just the shortcut provider — MFA on the destination account is what actually stopped this style of attack.


3. Nearly 22,000 Mail Servers Are Sitting Exposed to a Bug That Hands Over Every Mailbox

Security researchers have published working attack code for a flaw in Microsoft Exchange Server — the software many businesses run in-house to manage email — that lets someone with only basic access to the server take over every mailbox on it: reading messages, downloading attachments, sending as anyone. Microsoft patched the underlying bug, CVE-2026-62911, back in August, but researchers estimate almost 22,000 servers worldwide, including hundreds in the UK, are still running the vulnerable version.

Why it matters for your business: if your business runs its own Exchange server rather than cloud email such as Microsoft 365, check with whoever manages it that August's security update is installed — with working attack code now public, this moves from "patch when convenient" to "patch this week."


4. A Firm That Verifies IDs for Car-Rental and Delivery Companies Reportedly Leaked 153 Million Driver's Licences

A dark-web marketplace began selling a haul of 153 million driver's licences and other ID documents that researchers trace back to IDScan.net, a US company whose identity-verification technology is used behind the scenes by firms like Hertz and FedEx to check customers' documents. The listing reportedly includes scanned images, not just names and numbers — exactly what's needed to open accounts, pass identity checks, or talk a call centre into believing you're someone else. IDScan hasn't confirmed a breach; the FBI has opened an investigation.

Why it matters for your business: your customers' ID documents are only as safe as the weakest verification vendor in the chain — if you use a third-party service to check customers' age or identity, ask what happens to the document image after the check runs, and how long it's kept.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.