Threat Analysis: SonicWall Zero-Days, Microsoft Teams Vishing, and the Dropbox-Lenovo Account Breach

Threats & Attacks

Threat Analysis: SonicWall Zero-Days, Microsoft Teams Vishing, and the Dropbox-Lenovo Account Breach

Hello, Mauven here.

This is your Daily Threat Analysis for 2nd September 2026.

Three stories today. One requires immediate action. The other two are the kind of thing that will catch your staff off guard if you have not already talked to them about it. Let us get into it.


SonicWall SMA1000: Two Chained Zero-Days Under Active Exploitation

SonicWall published an advisory today confirming that threat actors are chaining two newly discovered vulnerabilities in the SMA1000 appliance series to achieve remote code execution. The two flaws, a server-side request forgery vulnerability and a command injection vulnerability, are being exploited together in the wild. SonicWall confirmed exploitation was active at the time of disclosure.

The SMA1000 series is a remote access appliance. It sits on the perimeter. It is the thing that lets your staff work from home or that your IT provider uses to manage your systems remotely. If it is compromised, the attacker has a foothold that bypasses most of what is sitting behind it.

What the advisory says is that patches are being issued and affected customers should update immediately. What it does not say is how long exploitation has been occurring before SonicWall became aware of it, or how many organisations were compromised before the advisory dropped. That information tends not to appear in vendor advisories. It tends to appear in incident reports six months later.

SonicWall has had a difficult few years with exactly this class of vulnerability. Remote access appliances from multiple vendors have been consistently targeted because they are internet-facing, often under-monitored, and frequently left unpatched longer than internal systems. The NCSC has issued guidance on this pattern repeatedly. The fact we are still having this conversation tells you everything about how seriously organisations take it.

What you need to do:

  • If you or your IT provider run SonicWall SMA1000 appliances, contact them today and confirm the patch status
  • Ask your IT provider whether the appliance has been audited for indicators of compromise, patching an already-compromised device does not clean it
  • If you cannot get a clear answer on both points by end of business today, escalate
  • If you are unsure whether you have SonicWall kit, ask. “I don’t know what’s on our perimeter” is a gap that needs closing regardless of this specific advisory

Microsoft Teams Vishing: Spring Ring Targeted 150+ Employees Across 10 Companies

Unit 42 at Palo Alto Networks published research this week on a coordinated social engineering operation they have named Spring Ring. Between January and April 2026, attackers used external Microsoft Teams accounts to impersonate IT helpdesk personnel and called employees directly, over voice, to coerce them into installing remote monitoring and management tools or custom malware.

The campaign targeted over 150 employees across at least 10 companies. In more advanced variants, the attackers used a technique called PetitPotam to conduct further credential theft once they had established remote access.

This is worth reading carefully. The attackers were not sending phishing emails. They were calling people. On Teams. Claiming to be IT support. And it worked, across multiple organisations, over a period of four months.

The advisory attributes this to a campaign cluster. What it does not say is that the underlying technique, impersonating IT helpdesks via voice calls, using legitimate or compromised communication platforms, has been observed repeatedly since at least 2023. This is not a novel concept. What is notable here is the scale, the persistence, and the fact that Microsoft Teams’ external communication features made it straightforward to initiate contact with targets inside organisations.

For UK SMBs, the specific risk is this: most smaller organisations do not have a clearly communicated protocol for what IT support will and will not ask staff to do over the phone. Attackers know this. They are counting on it.

What you need to do:

  • Brief your staff today: legitimate IT support will never ask you to install software during an unexpected call, regardless of which platform the call comes from
  • Review your Microsoft Teams settings. External access, the ability for people outside your organisation to initiate calls and chats, should be restricted to what you actually need
  • Consider implementing a verbal challenge word or confirmation process for any IT request that involves granting remote access
  • If you use an MSP, ask them what their procedure is for confirming identity before staff allow remote sessions

Dropbox Accounts Breached via Lenovo Email Verification Flaw

Dropbox is notifying users that an unauthorised party accessed accounts by exploiting a vulnerability in Lenovo’s email verification process. The attacker used the flaw to register fraudulent Lenovo IDs, which were then used to gain access to linked Dropbox accounts.

This is a clean illustration of third-party identity risk. Dropbox did not have a vulnerability in its own systems in the conventional sense. The weak link was a hardware vendor’s identity verification process, something Dropbox users had no visibility into and no ability to control.

The practical implication for UK SMBs is broader than Dropbox specifically. How many of your staff have linked work accounts to services through third-party identity providers? How many of those identity providers are hardware vendors, software resellers, or peripheral services whose security posture you have never assessed? The honest answer, for most organisations, is that they do not know.

What you need to do:

  • If you use Dropbox and have a Lenovo ID linked to your account, check whether you have received a notification and review your account activity
  • More broadly: audit which third-party identity providers your staff use to access business services. Single sign-on through Microsoft or Google is generally better governed than through peripheral vendors
  • Enable MFA on Dropbox and any other file-sharing or storage services your business uses. This does not prevent account enumeration but it significantly raises the bar for unauthorised access

In Brief: The Sality Botnet Is Down

On 31st August, US, Bulgarian, Hungarian, and Romanian authorities working with CrowdStrike and the Shadowserver Foundation successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Sality has been active since 2003, twenty-three years. It infected Windows executables and delivered credential theft, spam distribution, DDoS capability, and, more recently, the EggJagger cryptocurrency clipper.

The good news is the botnet infrastructure has been dismantled. The less reassuring context is that Sality has survived previous disruption attempts and that infected machines will continue to carry the malware until cleaned. If you have older Windows systems that were not regularly updated over the past two decades, and in SMB environments, this is not an unusual situation, it is worth running a full scan.

This is also a reminder that law enforcement takedowns of botnets are disruptions, not permanent solutions. The criminal infrastructure tends to adapt. Watch for follow-up advisories.


A Note on the UK Cyber Bill

The Register reported today that the UK government’s cyber bill is being framed around regulating AI users rather than the vendors building AI systems. Ministers rejected proposed mandatory red lines and emergency shutdown powers, pointing instead to voluntary safeguards.

I will not speculate on legislative intent. What I will say is that if the regulatory burden for AI-related cyber risk falls on the organisations deploying AI rather than the companies building it, UK SMBs will need to get ahead of what that means in practice. This is a developing situation and worth watching.


Sources

SourceTitleURL
BleepingComputerSonicWall warns of actively exploited SMA1000 zero-day flawshttps://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
Unit 42 / Palo Alto NetworksAn Inside Look at Voice Phishing Campaigns in Microsoft Teamshttps://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
BleepingComputerDropbox accounts breached through Lenovo email verification flawhttps://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/
BleepingComputerSality botnet infrastructure dismantled in joint global takedownhttps://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
The Hacker NewsAuthorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloadshttps://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html
The RegisterUK cyber bill targets AI users, not the vendors building ithttps://www.theregister.com/security/2026/09/02/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it/5293738

If Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if someone in your network needs the heads-up, a colleague, a business owner, an IT manager who is still treating these things as someone else’s problem, pass it along. That is how this works.

Mauven.

Filed under

  • smb-security
  • uk-business
  • remote-access
  • social-engineering
  • credential-theft
  • vendor-risk
  • incident-response