On 2 September 2026, SonicWall disclosed two vulnerabilities in the SMA1000 remote access appliance series being actively chained together for remote code execution at the time of public disclosure. This episode provides immediate guidance for organisations running SonicWall perimeter devices, including patch verification and compromise auditing procedures. The briefing examines the Spring Ring campaign, a sustained Microsoft Teams vishing operation documented by Unit 42 that successfully targeted over 150 employees across ten companies between January and April 2026, using impersonated IT helpdesk calls to deploy remote monitoring tools and credential theft techniques including PetitPotam. Coverage includes Dropbox account compromises resulting from a Lenovo email verification flaw, illustrating third-party identity risk in business service authentication. Additional notes cover the multi-agency Sality botnet takedown after 23 years of operation, and emerging UK cyber legislation placing regulatory responsibility for AI deployment risk on end-user organisations rather than vendors.