Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall Zero-Days Exploited Before Patch Release

SonicWall Zero-Days Exploited Before Patch Release

Posted on July 20, 2026 By CWS

Recently, cybersecurity firm Volexity revealed that two zero-day vulnerabilities in SonicWall appliances were actively exploited by malicious actors weeks before security patches were made available. These vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were officially acknowledged by SonicWall in a public advisory released on July 14. The advisory alerted users to the risks associated with the flaws, which allowed remote attackers to compromise SMA1000 secure remote access devices.

SonicWall’s Response and Vulnerability Patch

SonicWall responded promptly by issuing hotfix updates to mitigate the security risks posed by the vulnerabilities. The company worked closely with Volexity during the investigation of these incidents. According to Volexity, the exploitation of these zero-days was attributed to a threat group they track as UTA0533, with evidence suggesting that the attacks began as early as June 22.

While the specific motives of the threat actors remain ambiguous, Volexity’s analysis suggests that their actions align more closely with state-sponsored advanced persistent threat (APT) activities rather than financially motivated cybercrime.

Technical Details of the Attack

Upon gaining access to the SonicWall appliances, the attackers deployed a custom malware named KnuckleBall. This malware facilitated the injection of additional tools into legitimate processes, including a specialized Java webshell called OrangeTail and an open-source proxy named Suo5. With root access, the attackers could potentially capture network traffic and access cached credentials.

Despite the significant capabilities demonstrated by UTA0533 in compromising the SonicWall devices, Volexity noted that the threat group struggled to move laterally within networks or access other systems.

Implications and Future Outlook

In response to these events, the Cybersecurity and Infrastructure Security Agency (CISA) has included the identified vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, which now features 17 flaws affecting SonicWall products. This underscores the critical need for organizations to remain vigilant and ensure timely application of security patches to protect against emerging threats.

The ongoing investigation and the release of technical details by Volexity highlight the importance of collaboration between cybersecurity firms and vendors in identifying and mitigating advanced threats. As the landscape of cyber threats continues to evolve, maintaining robust security measures and staying informed about potential vulnerabilities is crucial for safeguarding sensitive information.

Security Week News Tags:APT, CVE-2026-15409, CVE-2026-15410, Cybersecurity, KnuckleBall, Malware, SMA1000, SonicWall, Volexity, zero-day vulnerabilities

Post navigation

Previous Post: HollowGraph Malware Exploits Microsoft 365 Calendars
Next Post: AI Discovers WordPress Flaw, Potentially Worth $500,000

Related Posts

ArmorCode Secures M to Enhance AI Exposure Management ArmorCode Secures $16M to Enhance AI Exposure Management Security Week News
Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers Organizations Warned of Vulnerability Exploited Against Discontinued TP-Link Routers Security Week News
Macron Advocates Global AI Regulation at G7 Summit Macron Advocates Global AI Regulation at G7 Summit Security Week News
Runlayer Emerges From Stealth Mode With  Million in Funding Runlayer Emerges From Stealth Mode With $11 Million in Funding Security Week News
All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher Security Week News
SonicWall Urges Patching of Critical SMA1000 Vulnerabilities SonicWall Urges Patching of Critical SMA1000 Vulnerabilities Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark