Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Zero-Days Exploited Before Patch Release

SonicWall Zero-Days Exploited Before Patch Release

Posted on July 20, 2026 By CWS

Recently, cybersecurity firm Volexity revealed that two zero-day vulnerabilities in SonicWall appliances were actively exploited by malicious actors weeks before security patches were made available. These vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were officially acknowledged by SonicWall in a public advisory released on July 14. The advisory alerted users to the risks associated with the flaws, which allowed remote attackers to compromise SMA1000 secure remote access devices.

SonicWall’s Response and Vulnerability Patch

SonicWall responded promptly by issuing hotfix updates to mitigate the security risks posed by the vulnerabilities. The company worked closely with Volexity during the investigation of these incidents. According to Volexity, the exploitation of these zero-days was attributed to a threat group they track as UTA0533, with evidence suggesting that the attacks began as early as June 22.

While the specific motives of the threat actors remain ambiguous, Volexity’s analysis suggests that their actions align more closely with state-sponsored advanced persistent threat (APT) activities rather than financially motivated cybercrime.

Technical Details of the Attack

Upon gaining access to the SonicWall appliances, the attackers deployed a custom malware named KnuckleBall. This malware facilitated the injection of additional tools into legitimate processes, including a specialized Java webshell called OrangeTail and an open-source proxy named Suo5. With root access, the attackers could potentially capture network traffic and access cached credentials.

Despite the significant capabilities demonstrated by UTA0533 in compromising the SonicWall devices, Volexity noted that the threat group struggled to move laterally within networks or access other systems.

Implications and Future Outlook

In response to these events, the Cybersecurity and Infrastructure Security Agency (CISA) has included the identified vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, which now features 17 flaws affecting SonicWall products. This underscores the critical need for organizations to remain vigilant and ensure timely application of security patches to protect against emerging threats.

The ongoing investigation and the release of technical details by Volexity highlight the importance of collaboration between cybersecurity firms and vendors in identifying and mitigating advanced threats. As the landscape of cyber threats continues to evolve, maintaining robust security measures and staying informed about potential vulnerabilities is crucial for safeguarding sensitive information.

Security Week News Tags:APT, CVE-2026-15409, CVE-2026-15410, Cybersecurity, KnuckleBall, Malware, SMA1000, SonicWall, Volexity, zero-day vulnerabilities

Post navigation

Previous Post: HollowGraph Malware Exploits Microsoft 365 Calendars
Next Post: AI Discovers WordPress Flaw, Potentially Worth $500,000

Related Posts

Critical Vulnerabilities Patched in TP-Link’s Omada Gateways Critical Vulnerabilities Patched in TP-Link’s Omada Gateways Security Week News
Intel and AMD Patch Over 80 Vulnerabilities in February Intel and AMD Patch Over 80 Vulnerabilities in February Security Week News
Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm Security Week News
Checkout.com Discloses Data Breach After Extortion Attempt Checkout.com Discloses Data Breach After Extortion Attempt Security Week News
Password Managers Vulnerable to Data Theft via Clickjacking Password Managers Vulnerable to Data Theft via Clickjacking Security Week News
Security Flaws in Perforce Servers Risk Sensitive Data Security Flaws in Perforce Servers Risk Sensitive Data Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark