View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SonicWall SMA 1000 VPN Zero-Days Exploited Pre-Disclosure for Root

🚨 ACTIVE EXPLOITATION

  • SonicWall SMA 1000 VPN Zero-Days Exploited Pre-Disclosure for Root Access — The Hacker News
    A threat actor exploited multiple zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances before public disclosure.

    • Applies to SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
    • Exploited vulnerabilities CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) enable arbitrary command execution and root access
    • Attack involves unauthenticated WebSocket tunnel creation via /wsproxy, CouchDB exploitation, and privilege escalation through path traversal
    • Threat actor UTA0533 deployed custom malware including ROOTRUN setuid binary, KNUCKLEBALL Python script, Suo5 HTTP proxy, and ORANGETAIL Java web shell
    • Exploitation discovered by Volexity during incident response; patches released by SonicWall after June 22, 2026
  • UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware — The Hacker News
    Russian group UAC-0145 uses ClickFix CAPTCHAs to deliver malware to Ukrainian devices.

    • Targets Ukrainian users via compromised websites with fake CAPTCHA prompts
    • Instructs victims to run PowerShell commands that download malware like GHETTOVIBE
    • Uses PowerShell script SCOUTCURL for reconnaissance and loaders FLUIDLEECH, LOADLOOP
    • Deploys backdoors such as FREAKYPOLL (Python) and Android backdoor COWARDDUCK via APKs
    • Employs traffic filtering and dynamic page content tools Cloaking.House and SMARTAXE

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check