Jessica Entwistle
September 2 2026
Today's stories reflect a recurring pattern: attackers are moving quickly to exploit newly disclosed vulnerabilities, organisations are grappling with the operational security challenges of AI systems, and trust in third-party platforms remains fragile. For UK businesses, these developments highlight the importance of disciplined patch management, clear ownership of emerging technology risks, and realistic expectations about the security posture of platforms we rely on daily.
SecurityWeek reports that SonicWall has disclosed two zero-day vulnerabilities in its SMA1000 series appliances, CVE-2026-83549 and CVE-2026-83548, which are being actively exploited in the wild. The flaws can be chained together to achieve unauthenticated remote code execution on affected devices. SonicWall has released patches and is urging customers to update immediately. The vulnerabilities affect widely deployed SSL VPN appliances used by organisations for secure remote access.
For UK businesses using SonicWall SMA1000 appliances, this is a critical operational risk. SSL VPN devices sit at the perimeter and provide direct access to internal networks, making them high-value targets. Active exploitation of zero-day vulnerabilities means attackers are already scanning for and compromising vulnerable systems. Organisations that have not yet applied the patches are exposed to potential network compromise, lateral movement and data exfiltration. The fact that these vulnerabilities can be exploited without authentication significantly lowers the barrier for attackers.
For UK businesses running SonicWall SMA1000 appliances, this is a prompt to verify patch status immediately and review access logs for signs of compromise. If patching cannot be completed urgently, consider temporary mitigations such as restricting access to the management interface or placing devices behind additional network controls until updates are applied.
Source: SecurityWeek
The Register reports that attackers are actively exploiting CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, just days after public disclosure. The flaw, which has a CVSS score of 9.8, allows unauthenticated attackers to mint administrative tokens and gain full control of affected Artifactory instances. Exposed servers are already being targeted. JFrog released patches in late August, but organisations that have not yet updated remain at significant risk.
Artifactory is a widely used repository manager for software development pipelines, storing build artifacts, container images, dependencies and credentials. Compromise of an Artifactory instance can provide attackers with access to source code, supply chain components, API keys and deployment credentials. For UK organisations using Artifactory in their CI/CD pipelines, this vulnerability represents a direct route into the software supply chain. The speed at which exploitation began after disclosure underscores how quickly attackers are weaponising newly published vulnerabilities, particularly those affecting development infrastructure.
For many organisations, Artifactory sits at the heart of software delivery. This is a prompt to verify that all Artifactory instances are patched, review access logs for suspicious administrative token creation, and ensure that repository access controls and credential management practices are robust enough to limit the impact of any potential compromise.
Source: The Register
Infosecurity Magazine reports that attackers stole an API key belonging to METR, an AI safety research organisation, and used it for three weeks to consume approximately $600,000 worth of AI model credits. The stolen key provided access to large language model APIs from multiple providers. METR has revoked the compromised key and is working with affected vendors to understand how the breach occurred. The incident highlights the operational security challenges organisations face when managing access to high-value cloud AI services.
For UK businesses deploying AI agents, large language models or cloud-based AI services, this incident is a reminder that API keys represent significant financial and operational risk. A single compromised key can result in substantial unexpected costs, potential data exposure if the key is used to query models with sensitive prompts, and reputational damage. The fact that the abuse continued for three weeks suggests that monitoring and alerting for unusual API usage patterns were either absent or insufficient. As AI adoption accelerates, the operational discipline around credential management, usage monitoring and cost controls must keep pace.
For UK businesses using AI services, this is a prompt to review how API keys are stored, rotated and monitored. Consider implementing usage alerts, spending caps and anomaly detection for AI service consumption. Ensure that access to high-value API credentials is tightly controlled and that unusual usage patterns trigger investigation before costs spiral.
Source: Infosecurity Magazine
The BBC reports that consumer group Which? successfully created a fake listing for 10 Downing Street on Booking.com as part of a test to assess the platform's verification controls. The listing was approved and published, complete with fabricated reviews. Booking.com removed the listing after being contacted by Which? and stated that the test was not representative of the experience across millions of legitimate listings. However, the test highlights ongoing concerns about the effectiveness of platform verification processes and the ease with which fraudulent listings can be created.
For UK businesses that rely on third-party platforms for travel bookings, accommodation or vendor management, this story is a reminder that platform trust cannot be assumed. Employees booking travel through consumer platforms may be exposed to fraudulent listings, financial loss or personal safety risks. The incident also reflects a broader pattern of platform verification failures that affect businesses in other contexts, from fake supplier profiles on procurement platforms to fraudulent service providers on freelance marketplaces. Organisations need to consider how they verify the legitimacy of third-party services, particularly when employees are booking independently or using corporate credit cards.
For UK businesses, this is a prompt to review corporate travel policies and consider whether employees have clear guidance on verifying accommodation bookings, particularly when using consumer platforms. Organisations may wish to evaluate whether managed travel services or pre-approved supplier lists provide better assurance than open platform bookings.
Source: BBC News
Today's stories reflect a consistent theme: security risks emerge not just from sophisticated attacks, but from the operational gaps in how we manage technology, credentials and third-party relationships. The organisations that respond most effectively to these challenges are those that have already embedded disciplined patch management, clear ownership of emerging technology risks, and realistic expectations about platform trust into their everyday operations. Good security is not about reacting to every headline, but about building the habits, processes and governance structures that allow you to respond confidently when risks do materialise. The goal is to feel informed and prepared, not perpetually reactive.