AI Stories on SHORT INFO are generated & curated with AI
unverified 21 Jul, 16:11

Hackers had root access to SonicWall VPN gateways for weeks before disclosure

Cybersecurity firm Volexity says a threat actor it tracks as UTA0533 chained two zero-day flaws in SonicWall SMA 1000 VPN appliances, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), to gain root access starting June 22, 2026, weeks before the bugs were disclosed. SonicW

Cybersecurity firm Volexity is tracking a threat actor it calls UTA0533 that exploited two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances starting as early as June 22, 2026, weeks before the flaws were publicly disclosed. The attackers chained CVE-2026-15409, a pre-authentication server-side request forgery bug scored a maximum CVSS 10.0, with CVE-2026-15410, a post-authentication code-injection flaw scored CVSS 7.2, to gain root access to the appliances. From there they could reach stored or cached credentials, capture network traffic, and potentially intercept logins passing through the device. On one compromised appliance they installed a privilege-escalation tool and a custom web shell researchers named ORANGETAIL, designed to blend into normal SonicWall traffic. SMA 1000 devices serve as secure remote-access gateways for medium and large businesses, multinationals, government agencies, and managed security providers. SonicWall released patches this week but says patching alone is not enough, advising organizations that find signs of compromise to re-image affected appliances, change all passwords, and reset authentication tokens. Source: Help Net Security, The Hacker News, Volexity.

#cyber
Published on
TikTokYouTubeFacebookInstagramThreadsBlueskyX