๐จ ACTIVE EXPLOITATION
- INC Ransomware Dominates Exploitation of SonicWall SMA 1000 Vulnerabilities
INC Ransomware is actively exploiting SonicWall Secure Mobile Access (SMA) 1000 series VPN vulnerabilities CVE-2026-15409 and CVE-2026-15410 to execute arbitrary commands and maintain persistence.- Targets SonicWall SMA 1000 VPN appliances globally across private and government sectors
- Uses Python script KNUCKLEBALL, Suo5 HTTP proxy, and ORANGETAIL Java web shell for persistence
- Attacks began before public patch release in mid-July 2026, with over 885 victims identified
- Victims span multiple countries including the US, Australia, and UAE
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ต๏ธ RESEARCH & DEEP DIVES
- Malware on Windows Can Hijack Google Passkey Accounts Without User Verification
Malware on compromised Windows PCs can silently hijack Google passkey-protected accounts by extracting device identity keys and security domain secrets from Chrome's local storage and memory.- Applies to Google Password Manager in Chrome on Windows with TPM hardware
- Three attack paths: Pass-ta-key (sign in without user verification), Silver Pass-ta-key (register attacker keys during re-enrollment), Golden Pass-ta-key (extract master encryption key for all synced passkeys)
- Attacks bypass fingerprint, PIN, or user prompts by exploiting flaws in Chrome's cloud authenticator and device trust model
- No CVEs assigned; attacks require malware already running on victim device
- Some relying parties, like eBay, have patched verification gaps
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News, Cyber Security News
๐ CVEs & KEV
- Other: 21 CVEs reported with the worst scoring 8.8 in CVSS.