<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: SonicWall Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving SonicWall.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch</title><link>https://securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch</link><guid isPermaLink="false">cst-2840</guid><description>Two zero-day vulnerabilities in SonicWall products (CVE-2026-15409 and CVE-2026-15410) were exploited in the wild to deploy custom malware, with attacks occurring for weeks before patches became available. The threat actor tracked as UTA0533 conducted the campaign.</description><pubDate>Mon, 20 Jul 2026 14:11:05 GMT</pubDate></item><item><title>⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More</title><link>https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html</link><guid isPermaLink="false">cst-2838</guid><description>This weekly recap highlights multiple critical vulnerabilities discovered in WordPress, SonicWall, and SharePoint products, along with attacks targeting artificial intelligence services. The incidents involved simple attack vectors such as exposed systems, insufficient input validation, outdated drivers, and malicious prompts that enabled remote code execution, data theft, and security tool circumvention.</description><pubDate>Mon, 20 Jul 2026 13:32:26 GMT</pubDate></item><item><title>20th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/20th-july-threat-intelligence-report</link><guid isPermaLink="false">cst-2835</guid><description>Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.</description><pubDate>Mon, 20 Jul 2026 12:18:41 GMT</pubDate></item><item><title>SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access</title><link>https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html</link><guid isPermaLink="false">cst-2802</guid><description>A threat actor tracked as UTA0533 exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to achieve root access before the vulnerabilities were publicly disclosed on June 22, 2026. Volexity discovered the activity during an incident response investigation. The attacker gained access to affected SMA devices prior to patches becoming available.</description><pubDate>Sun, 19 Jul 2026 13:18:56 GMT</pubDate></item><item><title>Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation</title><link>https://volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation</link><guid isPermaLink="false">cst-2789</guid><description>In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.</description><pubDate>Fri, 17 Jul 2026 22:10:37 GMT</pubDate></item><item><title>Inc Ransomware Exploits SonicWall SMA Zero-Days</title><link>https://darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days</link><guid isPermaLink="false">cst-2785</guid><description>Two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances can be chained together to grant attackers root-level access. The Inc ransomware group is actively exploiting these flaws against targeted organizations.</description><pubDate>Fri, 17 Jul 2026 20:01:13 GMT</pubDate></item><item><title>SonicWall SMA1000 vulnerabilities in active exploitation</title><link>https://sophos.com/en-us/blog/sonicwall-sma1000-vulnerabilities-in-active-exploitation</link><guid isPermaLink="false">cst-2629</guid><description>SonicWall announced vulnerabilities affecting the SMA1000 series appliance that are currently being exploited in the wild. The vulnerabilities allow remote attackers to compromise the appliance without authentication, potentially granting access to sensitive network resources and data.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)</title><link>https://helpnetsecurity.com/2026/07/14/sonicwall-sma-attacks-via-cve-2026-15409-cve-2026-15410</link><guid isPermaLink="false">cst-2523</guid><description>SonicWall has released patches for two actively exploited zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances. The company recommends affected organizations upgrade firmware, search for indicators of compromise, and if found, re-image or re-deploy appliances and reset credentials and multi-factor authentication tokens.</description><pubDate>Tue, 14 Jul 2026 17:40:10 GMT</pubDate></item><item><title>A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400</title><link>https://greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400</link><guid isPermaLink="false">cst-1848</guid><description>Security researchers at GreyNoise have detected a new spike in scanning activity targeting SonicWall devices that follows a similar pattern to activity preceding a prior vulnerability (CVE-2026-0400). The researchers are documenting the activity and providing guidance on indicators defenders should monitor.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>VPN Exploitation When Patched Doesn't Mean Protected</title><link>https://reliaquest.com/blog/threat-spotlight-vpn-exploitation-when-patched-doesnt-mean-protected</link><guid isPermaLink="false">cst-2118</guid><description>CVE-2024-12802 is an authentication bypass vulnerability in SonicWall SSL VPN appliances that reduces security to single-factor authentication and bypasses MFA. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, yet standard patch management workflows do not verify these steps, leaving devices appearing patched while remaining exploitable. ReliaQuest identified in-the-wild exploitation of this vulnerability between February and March 2026, where threat actors brute-forced VPN credentials and deployed ransomware staging tools within 30 minutes of initial access.</description><pubDate>Tue, 19 May 2026 10:00:00 GMT</pubDate></item><item><title>Active Reconnaissance Campaign Targets SonicWall Firewalls Through Commercial Proxy Infrastructure</title><link>https://greynoise.io/blog/active-reconnaissance-campaign-targets-sonicwall-firewalls-through-commercial-proxy-infrastructure</link><guid isPermaLink="false">cst-1857</guid><description>GreyNoise detected over 84,000 scanning sessions targeting SonicWall SonicOS firewalls within four days, using coordinated rotating proxy infrastructure to conduct active reconnaissance. The campaign indicates organized threat actor activity probing SonicWall deployments at scale.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate></item><item><title>They Got In Through SonicWall. Then They Tried to Kill | Huntress</title><link>https://huntress.com/blog/encase-byovd-edr-killer</link><guid isPermaLink="false">cst-759</guid><description>Huntress responded to an intrusion where attackers used compromised SonicWall VPN credentials and a revoked EnCase forensic driver to disable endpoint detection and response (EDR) processes through a bring-your-own-vulnerable-driver (BYOVD) attack. The incident demonstrates the attack chain from initial access through VPN compromise to EDR evasion. The attacker's ability to leverage legitimate-looking drivers highlights the sophistication of post-compromise techniques.</description><pubDate>Wed, 04 Feb 2026 15:00:00 GMT</pubDate></item><item><title>A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect</title><link>https://greynoise.io/blog/hidden-pattern-credential-based-attacks-palo-alto-sonicwall</link><guid isPermaLink="false">cst-1871</guid><description>GreyNoise observed over 7,000 IP addresses attempting to log into Palo Alto GlobalProtect, with attack signatures matching earlier SonicWall API scanning and previous Palo Alto campaigns. The incidents indicate a sustained pattern of credential-based attacks spanning several months against these security vendors' products.</description><pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Huntress Threat Advisory: Widespread SonicWall SSLVPN Compromise</title><link>https://huntress.com/blog/sonicwall-sslvpn-compromise</link><guid isPermaLink="false">cst-809</guid><description>Huntress has identified an increase in compromises affecting SonicWall SSLVPN (Secure Sockets Layer Virtual Private Network) devices across multiple customer environments. The advisory indicates a widespread pattern of attacks targeting this remote access solution. The company has documented these incidents to alert organizations using this technology.</description><pubDate>Fri, 10 Oct 2025 04:00:00 GMT</pubDate></item><item><title>The Dangers of Storing Unencrypted Passwords</title><link>https://huntress.com/blog/dangers-of-storing-unencrypted-passwords</link><guid isPermaLink="false">cst-819</guid><description>Threat actors exploited a SonicWall VPN vulnerability to gain initial access, deployed Akira ransomware, and uninstalled Huntress Managed Endpoint Detection and Response (EDR) agents after discovering plaintext recovery codes stored on the compromised systems. The incident demonstrates the risk posed by inadequate credential protection and the importance of secure credential management practices.</description><pubDate>Mon, 15 Sep 2025 05:00:00 GMT</pubDate></item><item><title>Firewall Lockouts: Play Ransomware and SonicWall Exploits</title><link>https://halcyon.ai/blog/firewall-lockouts-play-ransomware-and-sonicwall-exploits</link><guid isPermaLink="false">cst-2051</guid><description>Ransomware groups including Play, Akira, and Qilin are exploiting SonicWall firewalls to gain such complete control that victims are forced to perform hard resets and physically disconnect network equipment. These attacks leverage compromised firewall access to establish persistent footholds and lock defenders out of their own infrastructure.</description><pubDate>Thu, 11 Sep 2025 21:14:23 GMT</pubDate></item><item><title>Active Exploitation of SonicWall VPNs</title><link>https://huntress.com/blog/exploitation-of-sonicwall-vpn</link><guid isPermaLink="false">cst-831</guid><description>A zero-day vulnerability in SonicWall VPNs is being actively exploited by threat actors to bypass multi-factor authentication (MFA) and deploy ransomware. Attackers are rapidly moving to domain controllers after initial compromise. Huntress recommends immediately disabling the VPN service or restricting access through IP allow-listing.</description><pubDate>Wed, 13 Aug 2025 22:00:00 GMT</pubDate></item><item><title>Heightened In-The-Wild Activity On Key Technologies Observed On March 28</title><link>https://greynoise.io/blog/heightened-in-the-wild-activity-key-technologies</link><guid isPermaLink="false">cst-1908</guid><description>On March 28, GreyNoise detected a sharp increase in wild exploitation activity targeting multiple vendors including SonicWall, Zoho, Zyxel, F5, Linksys, and Ivanti. The affected technologies span both edge systems and internal management tools, suggesting a broad attack campaign.</description><pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate></item></channel></rss>