Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Flaws Exploited to Deploy Malware

SonicWall Flaws Exploited to Deploy Malware

Posted on July 21, 2026 By CWS

In a recent significant cybersecurity breach, attackers have successfully exploited two zero-day vulnerabilities found within SonicWall Secure Mobile Access (SMA) VPN appliances. These vulnerabilities allowed unauthorized access, leading to the deployment of custom malware.

Details of the Exploitation

Investigations conducted by the cybersecurity firm Volexity in early July 2026 uncovered that the threat actor, identified as UTA0533, strategically utilized these vulnerabilities. By chaining multiple zero-day flaws, the attackers were able to compromise SonicWall devices. This breach resulted in the deployment of custom malware, network traffic interception, and attempts to move laterally within the affected networks.

Evidence points to the exploitation commencing as early as June 22, 2026, with SonicWall later disclosing the vulnerabilities on July 14, 2026. These vulnerabilities impacted SMA 1000 series models, specifically 6210, 7210, and 8200v. SonicWall has since issued hotfixes to address these security gaps.

Technical Insights into the Vulnerabilities

The attackers exploited CVE-2026-15409, which involved a server-side request forgery (SSRF) flaw, enabling them to misuse the /wsproxy endpoint for establishing WebSocket tunnels. Furthermore, they used CVE-2026-15410, a command injection vulnerability, to execute unauthorized code.

This breach facilitated access to internal services such as CouchDB on port 1050 and the SMA control service on port 8188, enabling the attackers to upload files and engage in privileged functions. The path traversal exploit in the execRemoveHotfix function allowed files in /tmp to be executed with root privileges, as indicated by log entries referencing specific paths.

Malware Deployment and Recommendations

Among the compromised devices, the attackers installed a tool named xzfind, with internal references as ROOTRUN, and a Python-based implant called KNUCKLEBALL. These tools facilitated malware injection into SonicWall processes, utilizing Java payloads for persistence.

To counter these threats, organizations are urged to apply SonicWall’s security patches promptly. Additionally, it is crucial to review logs for unusual /wsproxy activity, inspect specific directories for unexpected files, and verify configuration files for unauthorized routes. Volexity has provided YARA rules to assist in detecting the presence of these malicious tools.

As cybersecurity threats evolve, staying informed and proactive in applying security measures is essential to safeguarding network infrastructures.

Cyber Security News Tags:CVE-2026-15409, CVE-2026-15410, Cybersecurity, KnuckleBall, Malware, network security, ROOTRUN, SMA 1000 series, SonicWall, SonicWall fixes, UTA0533, Volexity, VPN, YARA rules, zero-day vulnerabilities

Post navigation

Previous Post: Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
Next Post: HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Related Posts

Europol Dismantles Fraud Crypto Investment Ring That Tricked 5000+ Victims Worldwide Europol Dismantles Fraud Crypto Investment Ring That Tricked 5000+ Victims Worldwide Cyber Security News
Rising Cyber Threats Target Education Sector Globally Rising Cyber Threats Target Education Sector Globally Cyber Security News
Critical Squid Proxy Vulnerability Exposed with AI Assistance Critical Squid Proxy Vulnerability Exposed with AI Assistance Cyber Security News
CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability Cyber Security News
Microsoft To Mandate MFA for Accounts Signing In to the Azure Portal Microsoft To Mandate MFA for Accounts Signing In to the Azure Portal Cyber Security News
LangChainGo Vulnerability Let Attackers Access Sensitive Files LangChainGo Vulnerability Let Attackers Access Sensitive Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited
  • Craneware Confirms Cyberattack, Data Compromised
  • SecurityWeek Unveils Critical Impact Awards for Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited
  • Craneware Confirms Cyberattack, Data Compromised
  • SecurityWeek Unveils Critical Impact Awards for Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark