The industry turned XDR and SIEM into categories. Sophos turned them into outcomes.
2026-09-16T20:51:31Z•1348d3cb5563e6cd3067ef81d73ae5a37997e8e5d56ec5884f2304fabdb2c91c
CVE-2026-76461CVE-2026-83548CVE-2026-83549AI-enabled cybercrimeCisco Firewall Management CenterCisco Secure Email GatewayCyclops BlinkMITRE ATT&CKPHP web-server rootkitSIEMSonicWall SMA1000XDRactive exploitationmalwarerootkitthreat intelligencevulnerability management
What happened
Sophos security intelligence highlights active exploitation of a Cisco Secure Email Gateway vulnerability (CVE-2026-76461) and two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549). It also covers Cyclops Blink malware activity targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, underground uncensored AI services, and defensive security operations topics.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 1348d3cb5563e6cd3067ef81d73ae5a37997e8e5d56ec5884f2304fabdb2c91c
- Enrichment time
- 2026-09-16T20:51:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.