Dissecting a PHP web server rootkit
2026-09-09T20:51:31Z•12bea9a4e1a8a0ba6a94ee9e8c08ac8b219ff7678d07c9ef679269872bed23f8
CVE-2026-83548CVE-2026-83549AI brand impersonationGOLD SHERWOODNetNTLMv1PHP malwarePatch TuesdaySonicWall SMA1000active exploitationcredential attackseducation sectormalware distributionransomwareweb server rootkit
What happened
Sophos reporting highlights active exploitation of SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549, a PHP web server rootkit, ransomware activity attributed to GOLD SHERWOOD affiliates, impersonation of AI brands to distribute malware, and renewed practical exploitation of legacy NetNTLMv1 authentication. The most urgent item is the active exploitation of the SonicWall vulnerabilities.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 12bea9a4e1a8a0ba6a94ee9e8c08ac8b219ff7678d07c9ef679269872bed23f8
- Enrichment time
- 2026-09-09T20:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.