DAILY BRIEFING
SonicWall SMA 1000 Zero-Days, Virtualizor BGP Hijack, and StreamRat Trojan
Today's briefing covers active zero-day exploitation of SonicWall VPN appliances, BGP hijacking delivering malicious Virtualizor updates, and Meta ads distributing the StreamRat Android trojan.
5 stories2 min read

Critical infrastructure and software supply chains face active targeting today. Attackers are currently chaining two newly disclosed zero-day vulnerabilities in SonicWall SMA 1000 series appliances to achieve remote code execution. Network security administrators managing these appliances must prioritize applying vendor patches immediately.
Meanwhile, consumer and enterprise mobile security is challenged as Meta ad campaigns push StreamRat, a new Android banking trojan capable of taking full control of devices once granted accessibility permissions.
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Threat actors executed a BGP hijack against Softaculous traffic to deliver a malicious Virtualizor update package between August 28 and August 30, resulting in root-level host compromises.
- Why it matters
- Virtualizor hypervisor operators face host-level root compromise and persistence across affected infrastructure without a clear list of affected software versions.
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
- Why it matters
- Organizations using SonicWall SMA 1000 series appliances face active zero-day exploitation leading to unauthenticated remote code execution.
Dropbox accounts breached through Lenovo email verification flaw
Unauthorized parties accessed selected Dropbox accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.
- Why it matters
- Users relying on integrated identity services or Lenovo email verification mechanisms risk unauthorized exposure of sensitive Dropbox account data.
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
A malvertising campaign on Meta targeted EU users with ads for a fake TV-streaming app that distributed StreamRat, an Android banking trojan capable of full device control via accessibility privileges.
- Why it matters
- Android users who install sideloaded applications risk complete keylogging, credential theft, and full operator control over affected mobile devices.
How to Secure Enterprise AI: From Adoption to Incident Readiness
A survey of 600 senior IT and security leaders showed that while nearly one-third actively use AI in security operations, 73% report their organizations are unprepared to handle a major cyberattack.
Key takeaways
- Patch SonicWall SMA 1000 series appliances immediately to fix active zero-day vulnerabilities CVE-2026-83548 and CVE-2026-83549.
- Run Virtualizor Patch 9 Security Analyzer and rotate API credentials following a BGP hijacking attack that injected malicious hypervisor updates.
- Fraudulent Lenovo ID creation via email verification flaws enabled unauthorized access to certain Dropbox accounts.
- StreamRat Android banking trojan reaches over 570,000 EU Meta accounts using malicious ads to lure users into granting accessibility permissions.