View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise

๐Ÿšจ ACTIVE EXPLOITATION

  • SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise CVE-2026-15409 and CVE-2026-15410
    Attackers exploited two vulnerabilities to gain root access on SonicWall SMA 1000 series VPN appliances.

    • Applies to SonicWall SMA 1000 series including SMA 6210, 7210, 8200v, and vCMS deployments
    • Vulnerabilities: CVE-2026-15409 (pre-auth wsproxy bypass) and CVE-2026-15410 (path traversal in removehotfix)
    • Crafted web requests open WebSocket tunnels to internal services, bypassing local access restrictions
    • Exploitation leads to root-level control, persistent backdoors, credential theft, and lateral movement
    • INC Ransomware group has exploited these flaws since at least June 22, 2026, before July patches ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Russian APT Midnight Blizzard hacks public Wi-Fi gateways to steal Microsoft credentials
    Russian state-sponsored APT Midnight Blizzard targets hospitality organizations worldwide by hacking public Wi-Fi gateways.

    • Compromises SOHO routers to manipulate DNS and HTTP traffic for credential theft
    • Uses adversary-in-the-middle attacks to intercept Microsoft 365 credentials
    • Delivers Golang-based Windows RATs via fake browser updates and Android APKs
    • Employs device code phishing integrated into captive portal authentication flows ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ“„ Original: securityweek.com ยท ๐Ÿ‘ via SecurityWeek, @campuscodi@mastodon.social (+1)

โš ๏ธ ADVISORIES

  • Thermo Fisher Patches High-Severity Flaw Allowing Nearly Undetectable DNA File Tampering
    Thermo Fisher patched a flaw that allowed near-undetectable tampering of DNA data files in Applied Biosystems human identification software.
    • Vulnerability allows alteration of .fsa and .hid DNA data files before analysis software loads them
    • Attack requires local or remote access to lab servers and knowledge of DNA testing
    • Updates add digital signatures to verify file integrity in five supported product lines
    • Three end-of-life product lines receive no updates; flaw likely existed since 1995 ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check