Dissecting a PHP web server rootkit

2026-09-09T20:51:31Z12bea9a4e1a8a0ba6a94ee9e8c08ac8b219ff7678d07c9ef679269872bed23f8
CVE-2026-83548CVE-2026-83549AI brand impersonationGOLD SHERWOODNetNTLMv1PHP malwarePatch TuesdaySonicWall SMA1000active exploitationcredential attackseducation sectormalware distributionransomwareweb server rootkit

What happened

Sophos reporting highlights active exploitation of SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549, a PHP web server rootkit, ransomware activity attributed to GOLD SHERWOOD affiliates, impersonation of AI brands to distribute malware, and renewed practical exploitation of legacy NetNTLMv1 authentication. The most urgent item is the active exploitation of the SonicWall vulnerabilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
12bea9a4e1a8a0ba6a94ee9e8c08ac8b219ff7678d07c9ef679269872bed23f8
Enrichment time
2026-09-09T20:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.