๐จ ACTIVE EXPLOITATION
-
SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise
CVE-2026-15409andCVE-2026-15410
Attackers exploited two vulnerabilities to gain root access on SonicWall SMA 1000 series VPN appliances.- Applies to SonicWall SMA 1000 series including SMA 6210, 7210, 8200v, and vCMS deployments
- Vulnerabilities: CVE-2026-15409 (pre-auth wsproxy bypass) and CVE-2026-15410 (path traversal in removehotfix)
- Crafted web requests open WebSocket tunnels to internal services, bypassing local access restrictions
- Exploitation leads to root-level control, persistent backdoors, credential theft, and lateral movement
- INC Ransomware group has exploited these flaws since at least June 22, 2026, before July patches ๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Russian APT Midnight Blizzard hacks public Wi-Fi gateways to steal Microsoft credentials
Russian state-sponsored APT Midnight Blizzard targets hospitality organizations worldwide by hacking public Wi-Fi gateways.- Compromises SOHO routers to manipulate DNS and HTTP traffic for credential theft
- Uses adversary-in-the-middle attacks to intercept Microsoft 365 credentials
- Delivers Golang-based Windows RATs via fake browser updates and Android APKs
- Employs device code phishing integrated into captive portal authentication flows ๐ Coverage: securityweek.com ยท ๐ Original: securityweek.com ยท ๐ via SecurityWeek, @campuscodi@mastodon.social (+1)
โ ๏ธ ADVISORIES
- Thermo Fisher Patches High-Severity Flaw Allowing Nearly Undetectable DNA File Tampering
Thermo Fisher patched a flaw that allowed near-undetectable tampering of DNA data files in Applied Biosystems human identification software.- Vulnerability allows alteration of .fsa and .hid DNA data files before analysis software loads them
- Attack requires local or remote access to lab servers and knowledge of DNA testing
- Updates add digital signatures to verify file integrity in five supported product lines
- Three end-of-life product lines receive no updates; flaw likely existed since 1995 ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News