<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj" -->

---
title: SonicWall&#x27;s SMA1000 gets chained into RCE, JFrog...
description: Two more enterprise perimeter products join the exploited-in-the-wild list today: SonicWall&#x27;s SMA1000 appliances and JFrog Artifactory both have critical...
canonical: https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SonicWall&#x27;s SMA1000 gets chained into RCE, JFrog Artifactory follows with its own critical bypass | daily.dev
og:description: Two more enterprise perimeter products join the exploited-in-the-wild list today: SonicWall&#x27;s SMA1000 appliances and JFrog Artifactory both have critical...
og:url: https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj
og:image: https://api.daily.dev/og/posts/UWGfisuvj.png
og:image:alt: SonicWall&#x27;s SMA1000 gets chained into RCE, JFrog Artifactory follows with its own critical bypass
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SonicWall's SMA1000 gets chained into RCE, JFrog Artifactory follows with its own critical bypass

**[Security Digest](https://daily.dev/sources/security_digest)** · 4 min read · 0 upvotes · 0 comments

## Summary

Two more enterprise perimeter products join the exploited-in-the-wild list today: SonicWall's SMA1000 appliances and JFrog Artifactory both have critical auth-bypass chains under active attack. Booz Allen's first Cyber Weapon Index found Claude Mythos is the only model that can autonomously complete a full offensive cyber kill chain, and warns most competitors could catch up within six months. A BGP hijack at Hetzner spent 33 hours redirecting Softaculous update traffic to malware because the update client never checked signatures. Palo Alto Networks also bought an AI help desk startup for roughly $500 million to bolt agentic triage onto Cortex.

## Content

**TLDR:** Two more enterprise perimeter products join the exploited-in-the-wild list today: SonicWall's SMA1000 appliances and JFrog Artifactory both have critical auth-bypass chains under active attack. Booz Allen's first Cyber Weapon Index found Claude Mythos is the only model that can autonomously complete a full offensive cyber kill chain, and warns most competitors could catch up within six months. A BGP hijack at Hetzner spent 33 hours redirecting Softaculous update traffic to malware because the update client never checked signatures. Palo Alto Networks also bought an AI help desk startup for roughly $500 million to bolt agentic triage onto Cortex.

---

## SonicWall SMA1000 chain lets unauthenticated attackers get full RCE, exploitation predates disclosure

CVE-2026-83548 (CVSS 10.0, pre-auth SSRF in the Work Place interface) and CVE-2026-83549 (CVSS 7.8, OS command injection in the admin console) chain into unauthenticated remote code execution on SMA 6210, 7210, and 8200v appliances. SonicWall shipped hotfixes but is explicit that patching alone won't cut it here — attackers were already in before the disclosure went public. If you're running one of these boxes, check for IOCs, re-image if you find compromise, and rotate every password and TOTP token. This pattern mirrors last year's SonicWall chain tied to INC ransomware, and the vendor has racked up somewhere between 18 and 22 CVEs in the past year alone. [Read more](https://daily.dev/posts/6hvOQbRdH)

## JFrog Artifactory's 'phantom join key' bug is being actively exploited

CVE-2026-82329 (CVSS 9.8) lets unauthenticated attackers with network access grab admin privileges on Artifactory instances that never configured an additional join key. watchTowr saw attackers minting admin tokens and enumerating users, credentials, and federated access as early as September 1, just days after JFrog's August 28 disclosure. Patches exist (7.111.21 through 7.161.20), but tokens minted before you patched are still valid — rotate admin tokens and check audit logs regardless of patch status. [Read more](https://daily.dev/posts/fl2nmMeCb)

## Claude Mythos is the only model to run a full autonomous cyber kill chain, Booz Allen finds

Booz Allen's first Cyber Weapon Index tested 18 US and Chinese models on offensive capability. Mythos achieved administrator-level control with stolen credentials every time, and full domain compromise even without credentials — nothing else in the field got that far unassisted, though Grok-4.5, Muse Spark 1.1, and GLM-5.2 reached full domain access. The uncomfortable finding: strap an attack harness onto a lesser model like Claude Sonnet and it starts rivaling Mythos, and the report expects most tested models to reach that weaponization level within six months. [Read more](https://daily.dev/posts/WZTaXk5w0)

## BGP hijack at Hetzner turned Softaculous updates into malware for 33 hours

Attackers exploited weak BGP filtering at Hetzner to hijack the IP space Softaculous uses to serve Virtualizor updates, then pushed malware disguised as legitimate patches. Virtualizor's update client never cryptographically verified packages, so nothing stopped a malicious payload from installing silently. Hetzner reclaimed the addresses once, the attacker just repeated the hijack, and it took nearly 10 hours to respond the second time. Anyone who pulled updates during the window should assume compromise and audit installed packages. [Read more](https://daily.dev/posts/bt4TZaZNE)

---

## Also notable

- **Palo Alto Networks buys AI help desk startup Console for ~$500M:** The two-year-old startup, last valued at $157M after raising $29M, gets folded into Cortex to add agentic alert-resolution capability — Palo Alto's seventh acquisition this year. [Read more](https://daily.dev/posts/xX0oK8CPd)
- **Dropbox breach traced to Lenovo ID integration flaw:** About 5,000 Dropbox accounts were accessed between August 4-21 because Lenovo's login integration never verified email ownership, and every affected account had MFA disabled. [Read more](https://daily.dev/posts/HXmuG5XWg)
- **GitSpawn shows malicious Git repos can trigger command execution in AI coding agents:** Eight related vulnerabilities across seven agents (Claude Code, Codex, Cursor) exploit Git's core.fsmonitor config during routine git status or git diff, with no need to trick the model itself. [Read more](https://daily.dev/posts/DtZ8OT1uU)
- **HiddenLayer raises $100M Series B as AI security spend accelerates:** Gartner now projects enterprise AI security spend hitting $2.83 billion this year, up 83% from 2025, and $4.78 billion next year. [Read more](https://daily.dev/posts/T3SIAMUL9)
- **WordPress patch-to-exploit window has collapsed to about five hours:** The recent wp2shell exploit saw mass scanning within 30 minutes of patch release, according to a Monarx executive discussing AI-accelerated vulnerability chaining. [Read more](https://daily.dev/posts/mO2mxN69J)

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#ai-security](https://daily.dev/tags/ai-security)

[View this post on daily.dev](https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"DiscussionForumPosting","mainEntityOfPage":"https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj","headline":"SonicWall's SMA1000 gets chained into RCE, JFrog Artifactory follows with its own critical bypass","text":"Two more enterprise perimeter products join the exploited-in-the-wild list today: SonicWall's SMA1000 appliances and JFrog Artifactory both have critical auth-bypass chains under active attack. Booz Allen's first Cyber Weapon Index found Claude Mythos is the only model that can autonomously complete a full offensive cyber kill chain, and warns most competitors could catch up within six months. A BGP hijack at Hetzner spent 33 hours redirecting Softaculous update traffic to malware because the update client never checked signatures. Palo Alto Networks also bought an AI help desk startup for roughly $500 million to bolt agentic triage onto Cortex.","url":"https://daily.dev/posts/sonicwall-s-sma1000-gets-chained-into-rce-jfrog-artifactory-follows-with-its-own-critical-bypass-uwgfisuvj","datePublished":"2026-09-03T04:18:14.450Z","dateModified":"2026-09-03T04:18:37.807Z","author":{"@type":"Organization","name":"Security Digest","logo":"https://media.daily.dev/image/upload/s--m4ZKB_C0--/f_auto,q_auto/v1779959612/logos/security_digest","url":"https://daily.dev/sources/security_digest"},"interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"isPartOf":{"@type":"WebPage","url":"https://daily.dev/sources/security_digest","name":"Security Digest"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Digest","item":"https://daily.dev/sources/security_digest"},{"@type":"ListItem","position":3,"name":"SonicWall's SMA1000 gets chained into RCE, JFrog Artifactory follows with its own critical bypass"}]}
```

