July 18, 2026
- SonicWall SMA exploitation attributed to UTA0533 and Inc ransomware — Volexity details root access, staged scripts, and webshell implants via chained zero-days; Horizon3 maps CVE-2026-15409/CVE-2026-15410 (SSRF + post-auth code injection) on SMA1000 (Volexity, Horizon3), with Inc Ransomware named as an exploiting actor (Dark Reading). Continues this week's SonicWall thread with fresh attribution. · Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All