Weekly Threat Report – September 4, 2026
This week’s Threat Report covers actively exploited SonicWall vulnerabilities, a massive exposure of driver’s license data, a breach affecting court systems, and changes to CISA’s critical infrastructure assessment programs.
September 4, 2026
Transcript:
Weekly Threat Report
Cyber threats aren’t slowing down and neither should your response
This week’s threat landscape exposes a defining pattern for organizations across every sector: security risk is distributed across remote access infrastructure, third-party data relationships, shared technology platforms, and external assessment dependencies, all of which can become the source of significant exposure regardless of how strong internal controls are.
The organizations best prepared to manage that risk are those that continuously validate where their data, access, and dependencies live.
Here’s what you need to know:
See What You’ve Missed
SonicWall SMA1000 Vulnerabilities Confirmed Exploited
SonicWall disclosed two actively exploited vulnerabilities in its SMA 1000 remote-access appliances on September 1, a CVSS 10.0 pre-authentication SSRF flaw, and CVE-2026-83545, a CVSS 7.8 post-authentication remote code execution vulnerability.
15.5 Million D-Hole’s License Scans Advertised on Dark Web
A newly identified dark-web service advertised access to more than 15.5 million U.S. and Canadian driver’s license scans this week, with the FBI actively investigating the apparent source.
Thomson Reuters C-Track Breach Affects Court Systems
Thomson Reuters disclosed unauthorized access to its C-Track court case-management platform, affecting systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
CISA Retires Six Critical Infrastructure Assessment Programs
CISA confirmed the retirement of six hands-on assessment programs previously offered to critical infrastructure organizations, including Cyber Resilience Reviews, Ransomware Readiness Assessments, and Incident Management Reviews.
Product Recommendation
Cyber Risk Report for Enterprise Security
Cyber threats are constantly evolving, putting businesses at risk of data breaches, fraud, and compliance violations. Our Cyber Risk Report provides a thorough evaluation of your digital infrastructure, helping you identify vulnerabilities, assess potential risks, and implement robust security measures.
Resource Highlight
As cyber risks ramp up every week, staying ahead with your organization is the top priority.
Learn more about ransomware and how your organization can stay ahead of emerging threats before they happen.
What to Focus on This Week …
Cyber risk is expanding across technology, operations, and human behavior. The common thread across this week’s stories is distribution. Risk living in remote access gateways, third-party data relationships, shared platforms, and external dependencies that organizations do not directly operate but remain fully accountable for.
Closing these gaps requires data inventory, third-party risk governance, continuous monitoring, and detection capability operating alongside preventive controls, not as a separate program, but as an integrated component of how security is managed day to day.
If you’d like guidance tailored to your environment, RSI Security is here to help.
Contact RSI Security today to strengthen your cybersecurity posture.
Stay Ahead of What’s Next
Get practical cybersecurity insights, compliance updates, and emerging threat guidance delivered directly to your inbox.