Dissecting a PHP web server rootkit

2026-09-07T20:51:31Z17867451aacd8bb44e06ae6fb2b8c82f96b8c5f0cd6923ac556a2efeb52bb20b
CVE-2026-83548CVE-2026-83549AI brand impersonationGOLD SHERWOODNetNTLMv1PHP malwareSonicWall SMA1000active exploitationcredential attackscybersecurity researchmalware distributionpatch managementransomwareweb server rootkit

What happened

Sophos reporting highlights active exploitation of two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549), PHP web-server rootkit activity, ransomware tradecraft linked to GOLD SHERWOOD affiliates, impersonation of AI brands to distribute malware, and continued risks from legacy NetNTLMv1 authentication. The most urgent item is the reported in-the-wild exploitation of the SonicWall vulnerabilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
17867451aacd8bb44e06ae6fb2b8c82f96b8c5f0cd6923ac556a2efeb52bb20b
Enrichment time
2026-09-07T20:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.