daily cyber × ai intelligence

index

tagged

[CVE-2026-15409]

4 editions · 4 items

July 18, 2026

  • SonicWall SMA exploitation attributed to UTA0533 and Inc ransomware — Volexity details root access, staged scripts, and webshell implants via chained zero-days; Horizon3 maps CVE-2026-15409/CVE-2026-15410 (SSRF + post-auth code injection) on SMA1000 (Volexity, Horizon3), with Inc Ransomware named as an exploiting actor (Dark Reading). Continues this week's SonicWall thread with fresh attribution. · Threat Activity

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

July 17, 2026

  • SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr's honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr's advice: patch immediately and hunt logs for successful exploitation. · Vulnerabilities & Exploits

in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands