
SonicWall's Second Zero-Day, September 3 Patch
This month the artifacts split from the announcements on four fronts at once: a router logged a tunnel nobody configured, an AI agent logged its own ten-hour compromise, and one insurer's client logged a breach before saying so.
Continuous threat exposure management
Two edge-device chains this month, both pre-authentication, both already exploited before the vendor advisory existed. SonicWall shipped patches September 3 for two zero-days in the SMA 1000 series, chained together for unauthenticated remote code execution on a box that terminates VPN sessions before internal authentication runs. It is the second SonicWall edge-device zero-day of the summer, on a different flaw pair, same product line. Google's September 4 patch for CVE-2026-85046, a V8 sandbox escape, listed active exploitation before it listed a fix for most users. SonicWall shipped the SMA 1000 patch September 3; Google shipped the V8 fix September 4, a day after CVE-2026-85046 was already listed as under active exploitation. Neither vendor's scanner caught either chain before the exploitation log did.
Agentic governance
A multi-agent frontier AI system ran a full enterprise compromise on September 2, from initial access to cloud, identity, and CI/CD control, in under ten hours, chaining more than 50 MITRE ATT&CK techniques. Dark Reading's comparison point is a two-week human red team engagement for equivalent scope. The system produced an 80-page audit trail of its own actions. The compromise ran September 2, start to finish, under ten hours, and left an 80-page trail naming every technique that succeeded. Most firms running agents with standing credentials still have no equivalent log for their own systems tonight.
Board reporting
ATF confirmed only a generic cyber incident this month, after Qilin posted the leak claim to its site, naming no scope and no affected systems. That is the disclosure runbook working as written under NIST CSF RS.CO-02: verify scope internally before any public confirmation, say only what is verified. A board pack built from that confirmation will show less than the eventual scope statement shows, once it comes. Fire Ant's tampering with Cisco IOS XR logging pipelines this month sharpens the same problem: a board metric sourced from a log an operator has already edited is not a conservative number, it is a wrong one. Does our incident metric come from a log the operator could have touched, or one they could not?
Two dates anchor the month: September 2, when a multi-agent system finished a full enterprise compromise in under ten hours against a two-week human baseline, and September 3-4, when SonicWall and Google shipped patches after exploitation was already confirmed, not before. AI governance programmes, red teaming, post-quantum readiness, cyber risk quantification, the dashboard revamp, and continuous controls monitoring produced no linked movement this month.
The brief is free to read here and always will be. If you would rather it came to you, put your address on the list. One email a month, a confirmation click before anything is sent, and a one-click unsubscribe on every issue. The address is used for this and nothing else; the privacy policy says exactly what is stored.
One section per standing theme that moved this month, written from the desk's own filings, the regulatory landscape monitor, the incident register and the one-control entries; edited through the desk's tells and closer passes. The themes registry and its evidence are on the Cyber desk.