DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-14 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF SEPTEMBER 7, 2026

69/ 100HIGH PRESSURE

Two chained SonicWall zero-days and admin-token forgery in Artifactory lead a hot exploitation week, while three material-incident filings mark rising intrusion tempo.

↑ 3 POINTS SINCE LAST WEEK2026-W37ISSUED 2026-09-07 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
RISING

Nine current KEV additions — no vintage padding this week — led by two SonicWall SMA1000 zero-days that may chain, and an Artifactory flaw exploited to mint admin tokens days after disclosure.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

An RMM-lure phishing wave makes the US its top target across 46 countries; the Shai-Hulud credential worm's reach keeps growing.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
RISING

Three material-incident (Item 1.05) filings in one window — triple the recent baseline — alongside a court-records breach spanning twelve jurisdictions.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch or take SonicWall SMA1000 appliances offline now — two zero-days that may chain are under active exploitation — and hunt for pre-patch access.
02Patch Artifactory, then rotate tokens and audit admin-token issuance since disclosure; treat artifact registries and CI secrets as tier-0.
03Brief helpdesk and MSP contacts on the RMM-impersonation phishing wave; pin an allowlist of approved remote-access tools and alert on the rest.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 3711 RECEIPTS
CISA KEV · ANCHORCISA adds seven CVEs to the KEV catalog (SonicWall SMA1000 ×2, Artifactory, Switchvox, Kestra, Starlette, LiteLLM)Both SonicWall CVEs exploited as zero-days and reportedly chainable EXPLOITATION · 2026-09-02
CISA KEV · ANCHORCISA adds both PaperCut NG/MF CVEs to the KEV catalogCatalogs last week's PaperCut zero-day exploitation EXPLOITATION · 2026-08-31
VENDOR ADVISORY · CORROB.SonicWall PSIRT advisory SNWLID-2026-0016: SMA1000 SSRF and command injection EXPLOITATION · 2026-09-02
INCIDENT REPORTING · CORROB.The Hacker News: two SonicWall SMA1000 zero-days exploited, may form an attack chain EXPLOITATION · 2026-09-02
PUBLIC DISCLOSURE · ANCHORNutex Health SEC 8-K (Item 1.05): material cybersecurity incidentOne of three Item 1.05 filings this window — roughly triple the recent weekly baseline INTRUSION · 2026-08-31
PUBLIC DISCLOSURE · CORROB.NovoCure SEC 8-K (Item 1.05): material cybersecurity incidentPark Dental Partners filed the third Item 1.05 the same day INTRUSION · 2026-09-01
INCIDENT REPORTING · CORROB.The Hacker News: Thomson Reuters C-Track court-software breach may have exposed SSNs and sealed dataDisclosed Sep 2 across twelve jurisdictions; the intrusion itself ran March-June INTRUSION · 2026-09-03
INCIDENT REPORTING · CORROB.The Hacker News: Shai-Hulud's reach grows to 469 credential locations IDENTITY · 2026-09-03
REVISION HISTORY
2026-09-07 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE