Cybersecurity News — 2026-09-03
Generated: 2026-09-03 | Sources: BleepingComputer, Help Net Security, SecurityWeek, The Hacker News, Cybernews, TechRadar, Malwarebytes, Sophos
1. Two Unpatched Flaws in a Popular Remote-Access Appliance Are Being Actively Exploited
SonicWall has warned that two previously unknown vulnerabilities in its SMA1000 range of secure remote-access appliances — the boxes many businesses use to let staff connect to internal systems from outside the office — are being exploited right now. One flaw lets an attacker reach privileged internal functions with no login at all; chained with the second, it lets them run their own commands directly on the device that decides who gets onto the network. SonicWall has confirmed active exploitation and released a hotfix for both.
Why it matters for your business: if your business or IT provider uses a SonicWall SMA1000 appliance for remote access or VPN, install the hotfix immediately rather than waiting for a routine maintenance window — this is the device that decides who's allowed onto your network, so a compromise here bypasses everything behind it.
2. Attackers Broke Into 5,000 Dropbox Accounts Using Nothing But an Email Address
Dropbox confirmed that roughly 5,000 accounts were accessed without permission after attackers exploited a flaw in Lenovo's sign-in system, which some Dropbox users had linked as a "sign in with Lenovo ID" shortcut. A gap in Lenovo's email verification let someone register a new Lenovo ID using a stranger's email address, then use that ID to log straight into the matching Dropbox account — no password needed. Dropbox says every affected account lacked multi-factor authentication, which would have stopped the takeover even with the underlying flaw in play.
Why it matters for your business: check which staff use "sign in with X" shortcuts (Google, Microsoft, Lenovo, and similar) for business accounts, and make sure multi-factor authentication is switched on for the account being logged into, not just the shortcut provider — MFA on the destination account is what actually stopped this style of attack.
3. Nearly 22,000 Mail Servers Are Sitting Exposed to a Bug That Hands Over Every Mailbox
Security researchers have published working attack code for a flaw in Microsoft Exchange Server — the software many businesses run in-house to manage email — that lets someone with only basic access to the server take over every mailbox on it: reading messages, downloading attachments, sending as anyone. Microsoft patched the underlying bug, CVE-2026-62911, back in August, but researchers estimate almost 22,000 servers worldwide, including hundreds in the UK, are still running the vulnerable version.
Why it matters for your business: if your business runs its own Exchange server rather than cloud email such as Microsoft 365, check with whoever manages it that August's security update is installed — with working attack code now public, this moves from "patch when convenient" to "patch this week."
4. A Firm That Verifies IDs for Car-Rental and Delivery Companies Reportedly Leaked 153 Million Driver's Licences
A dark-web marketplace began selling a haul of 153 million driver's licences and other ID documents that researchers trace back to IDScan.net, a US company whose identity-verification technology is used behind the scenes by firms like Hertz and FedEx to check customers' documents. The listing reportedly includes scanned images, not just names and numbers — exactly what's needed to open accounts, pass identity checks, or talk a call centre into believing you're someone else. IDScan hasn't confirmed a breach; the FBI has opened an investigation.
Why it matters for your business: your customers' ID documents are only as safe as the weakest verification vendor in the chain — if you use a third-party service to check customers' age or identity, ask what happens to the document image after the check runs, and how long it's kept.
Sources
- SecurityWeek — SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
- BleepingComputer — SonicWall warns of actively exploited SMA1000 zero-day flaws
- Help Net Security — SonicWall SMA 1000 appliances under attack via zero-day flaws
- The Hacker News — Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- TechRadar — Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
- Cybernews — Dropbox Lenovo Breach Let Hackers Access 5,000 Accounts Without Passwords
- Help Net Security — Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
- BleepingComputer — Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
- Cybernews — 153M driver's licenses for sale after alleged leak from IDScan
- Malwarebytes — 153M+ driver's licenses for sale on new dark web platform