Dropbox Breach, SonicWall Zero-Days, and 20-Year Botnet Takedown

by The Creator | Sep 2, 2026

Patch management failures are creating active attack windows for small businesses right now. Four separate threats hitting SMBs this week, from Dropbox account compromises to SonicWall VPN exploits to Chrome vulnerabilities, all trace back to unpatched systems and delayed security updates.

Today's cybersecurity update covers critical threats affecting small businesses. Dropbox reported 5,000 accounts compromised through a Lenovo authentication flaw, emphasizing the importance of two-factor authentication. SonicWall SMA 1000 VPN devices face active exploitation through two critical zero-day vulnerabilities requiring immediate patching. Chrome users must update immediately to address critical flaws that allow malicious websites to execute code. The healthcare sector continues under ransomware assault with Proliance Surgeons and Nutex Health suffering data breaches. On a positive note, the FBI and CrowdStrike successfully disrupted the 20-year-old Sality botnet, freeing over 15,000 infected systems. Key takeaways: patch quickly, authenticate strongly, and backup religiously.

Why is patch management urgent for your small business right now?

This week's threat landscape shows SMBs cannot delay patching. Dropbox reported 5,000 compromised accounts tied to a Lenovo authentication flaw, exposing credential exposure across connected services. SonicWall SMA 1000 VPN devices face active zero-day exploitation right now, meaning attackers are already inside networks using these devices. Chrome's critical flaws allow malicious websites to execute code directly on your machines. Healthcare providers like Proliance Surgeons and Nutex Health suffered ransomware attacks that could have been contained with faster response. The single most important action: audit which systems run SonicWall, Chrome, and Dropbox in your environment today, then prioritize patches for internet-facing devices (VPNs first). CISA tracks active exploitation of these CVEs. Set a 48-hour patch window for critical vulnerabilities affecting remote access tools.

Key takeaways

  • SonicWall SMA 1000 VPN devices are under active attack through zero-day flaws, patch immediately if you use this device
  • Dropbox compromises show credential theft spreads across connected services, enable two-factor authentication on all business accounts
  • Chrome critical updates block code execution exploits from malicious websites, deploy updates across your organization this week
  • Ransomware attacks on healthcare providers accelerate when patch backlogs exist, prioritize backups and offline copies alongside patching

Frequently asked questions

What should we do if we use SonicWall SMA 1000 devices?

Contact your SonicWall provider or check the security advisory immediately for your device model and firmware version. Apply patches within 48 hours if your device is internet-facing. If patching is not available for your model, isolate the device behind a firewall with restricted access until a patch releases.

How do we know if our Dropbox accounts were part of the 5,000 compromised?

Check your Dropbox notification history and security log for unauthorized login attempts. Enable two-factor authentication on your business Dropbox account today. Reset passwords for all staff with Dropbox access and check for suspicious file access or sharing.

Do we need to update Chrome right away?

Yes. These are critical flaws that allow remote code execution from websites. Roll out Chrome updates to all machines this week. If your business uses managed Chrome, deploy the update through your admin console. End users should check Settings > About Chrome to force an immediate update.

What is patch management as a service?

Patch management services automate the testing and deployment of security updates across your business. MSPs like TC3 handle patch scheduling, testing, and rollout so your team doesn't have to track each vendor release. This reduces the window between a vulnerability's release and your systems being protected.

Sources

Keep reading