Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Flaws Exploited to Deploy Malware

SonicWall Flaws Exploited to Deploy Malware

Posted on July 21, 2026 By CWS

In a recent significant cybersecurity breach, attackers have successfully exploited two zero-day vulnerabilities found within SonicWall Secure Mobile Access (SMA) VPN appliances. These vulnerabilities allowed unauthorized access, leading to the deployment of custom malware.

Details of the Exploitation

Investigations conducted by the cybersecurity firm Volexity in early July 2026 uncovered that the threat actor, identified as UTA0533, strategically utilized these vulnerabilities. By chaining multiple zero-day flaws, the attackers were able to compromise SonicWall devices. This breach resulted in the deployment of custom malware, network traffic interception, and attempts to move laterally within the affected networks.

Evidence points to the exploitation commencing as early as June 22, 2026, with SonicWall later disclosing the vulnerabilities on July 14, 2026. These vulnerabilities impacted SMA 1000 series models, specifically 6210, 7210, and 8200v. SonicWall has since issued hotfixes to address these security gaps.

Technical Insights into the Vulnerabilities

The attackers exploited CVE-2026-15409, which involved a server-side request forgery (SSRF) flaw, enabling them to misuse the /wsproxy endpoint for establishing WebSocket tunnels. Furthermore, they used CVE-2026-15410, a command injection vulnerability, to execute unauthorized code.

This breach facilitated access to internal services such as CouchDB on port 1050 and the SMA control service on port 8188, enabling the attackers to upload files and engage in privileged functions. The path traversal exploit in the execRemoveHotfix function allowed files in /tmp to be executed with root privileges, as indicated by log entries referencing specific paths.

Malware Deployment and Recommendations

Among the compromised devices, the attackers installed a tool named xzfind, with internal references as ROOTRUN, and a Python-based implant called KNUCKLEBALL. These tools facilitated malware injection into SonicWall processes, utilizing Java payloads for persistence.

To counter these threats, organizations are urged to apply SonicWall’s security patches promptly. Additionally, it is crucial to review logs for unusual /wsproxy activity, inspect specific directories for unexpected files, and verify configuration files for unauthorized routes. Volexity has provided YARA rules to assist in detecting the presence of these malicious tools.

As cybersecurity threats evolve, staying informed and proactive in applying security measures is essential to safeguarding network infrastructures.

Cyber Security News Tags:CVE-2026-15409, CVE-2026-15410, Cybersecurity, KnuckleBall, Malware, network security, ROOTRUN, SMA 1000 series, SonicWall, SonicWall fixes, UTA0533, Volexity, VPN, YARA rules, zero-day vulnerabilities

Post navigation

Previous Post: Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
Next Post: HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Related Posts

YONO SBI Banking App Vulnerability Let Attackers Execute a Man-in-the-Middle Attack YONO SBI Banking App Vulnerability Let Attackers Execute a Man-in-the-Middle Attack Cyber Security News
Kimsuky Hackers Exploit LNK, JSE Lures Against Key Sectors Kimsuky Hackers Exploit LNK, JSE Lures Against Key Sectors Cyber Security News
Chinese Hackers Use AI Tools in Sophisticated Cyberattacks Chinese Hackers Use AI Tools in Sophisticated Cyberattacks Cyber Security News
Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System Cyber Security News
Hackers Exploiting Critical Langflow Vulnerability to Deploy Flodrix Botnet and Take System Control Hackers Exploiting Critical Langflow Vulnerability to Deploy Flodrix Botnet and Take System Control Cyber Security News
New Tool Analyzes LinkedIn Contacts with Epstein Files New Tool Analyzes LinkedIn Contacts with Epstein Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark