<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sonicwall on CuraSec</title><link>https://curasec.metacog.co.kr/tags/sonicwall/</link><description>Recent content in Sonicwall on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/sonicwall/index.xml" rel="self" type="application/rss+xml"/><item><title>SonicWall SMA 1000 Two Zero-Days Actively Exploited, May Chain</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-may/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-may/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Pre-authentication SSRF (CVSS 10.0) with a public PoC and confirmed active exploitation on SonicWall SMA 1000 series VPN appliances — patch to the vendor-released update immediately and isolate appliances from untrusted networks while patching proceeds.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active zero-day exploitation of an edge VPN device means assume-breach posture: sweep SMA 1000 access and authentication logs for anomalous pre-auth requests and unusual outbound SSRF-originated connections since disclosure, and tune detections for chained exploit behavior from the appliance.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether the organization runs SonicWall SMA 1000 appliances and, if so, brief leadership this week — a CVSS 10.0 pre-auth zero-day under active exploitation on a perimeter VPN is a material risk event that may generate customer or board questions.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-83548 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA1000 zero-days chained in active RCE attacks</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Actively exploited RCE zero-days on an edge appliance demand immediate response: apply SonicWall&amp;rsquo;s emergency mitigations or patches as soon as available, and treat any internet-exposed SMA1000 as potentially compromised pending confirmation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge SSL VPN device means compromise may predate any patch; sweep SMA1000 appliances for anomalous outbound connections and lateral movement indicators from the appliance&amp;rsquo;s IP, and initiate assume-breach review of adjacent segments.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If SonicWall SMA1000 is in the estate, confirm remediation is underway this week and request a vendor statement on exposure scope; actively exploited RCE on a remote-access gateway is the kind of incident that surfaces in board and customer conversations.&lt;/li>
&lt;/ul></description></item><item><title>CISA: SonicWall SMA1000 SSRF flaws actively exploited by ransomware</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gan/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gan/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SonicWall SMA1000 is a common enterprise remote-access appliance; CISA confirmation of active ransomware exploitation effectively means KEV-listed. Patch SMA1000 to the vendor-released fixed version immediately and audit device logs for signs of pre-patch compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Edge-device exploitation by ransomware gangs requires an assume-breach posture: sweep SMA1000 logs for exploitation indicators, hunt for anomalous outbound SSRF traffic or lateral movement originating from the appliance segment since the vulnerability window opened, and tune EDR/SIEM alerts on hosts reachable from those devices.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Maximum-severity flaw on a remote-access appliance with confirmed ransomware exploitation is a board-question-level event; confirm whether SonicWall SMA1000 is in your estate and demand an immediate patch status report from engineering — delay creates material incident exposure under SEC disclosure timelines.&lt;/li>
&lt;/ul></description></item><item><title>INC Ransomware Actively Exploiting SonicWall SMA 1000 VPN Flaws</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-inc-ransomware-emerges-as-dominant-actor-exploiting-sonicwal/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-inc-ransomware-emerges-as-dominant-actor-exploiting-sonicwal/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> INC Ransomware is actively exploiting SonicWall SMA 1000 series appliances with confirmed victims emerging since early August 2026; patch SMA 1000 firmware to the latest available release immediately or isolate the appliance from the internet if patching is delayed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active ransomware exploitation of a perimeter VPN appliance warrants an assume-breach posture for any SMA 1000 in the estate — hunt for lateral movement or data staging activity originating from those IPs since August 1, and correlate against INC Ransomware TTPs (double-extortion, data exfiltration before encryption).&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A named ransomware group is actively listing victims from a widely deployed enterprise VPN product; confirm this week whether SonicWall SMA 1000 is in use anywhere in the environment, request a patch-status update from the engineering team, and prepare a short leadership brief given the ransomware and data-leak exposure.&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA1000 zero-days exploited to deploy custom malware</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custo/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SonicWall SMA1000 is widely deployed enterprise VPN/remote-access infrastructure; active zero-day exploitation with custom malware implants is confirmed. Patch SMA1000 appliances to the latest firmware immediately and inspect filesystem and running processes for signs of persistent malware.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Zero-day compromise of edge VPN appliances with custom malware warrants an assume-breach posture for any environment running SMA1000. Hunt for anomalous outbound connections, credential-harvest activity, or lateral movement originating from these appliances, and check for unknown binaries or modified configs on the devices.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirmed zero-day exploitation of a common enterprise VPN product deploying custom malware is a board-visible risk. Verify this week whether your organization runs SonicWall SMA1000, and if so direct engineering and SOC to assess exposure and report status before it becomes a customer or leadership question.&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA 1000 Zero-Days Exploited for Root Access Pre-Disclosure</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-sonicwall-sma-zero-days-exploited-before-disclosure-to-gain/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-sonicwall-sma-zero-days-exploited-before-disclosure-to-gain/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SonicWall SMA 1000 series VPN appliances were exploited for root access as zero-days since at least June 22, 2026; if this appliance is in your environment, treat it as potentially compromised — isolate it, review for signs of intrusion, and apply any vendor patches immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Threat actor UTA0533 actively exploited SonicWall SMA 1000 appliances before disclosure, meaning some estates may already be rooted; sweep for Volexity-published IOCs and hunt for lateral movement originating from SMA appliance IP addresses since June 22.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A named threat actor achieved root access on widely-deployed SonicWall SMA 1000 VPN appliances before the vulnerability was public — confirm whether your organization uses this product and, if so, direct your team to assess exposure and obtain SonicWall&amp;rsquo;s official incident guidance this week.&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA 1000 Zero-Days Exploited, CVSS 10.0 Enables RCE</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-two-sonicwall-sma-1000-zero-days-exploited-one-could-enable/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-two-sonicwall-sma-1000-zero-days-exploited-one-could-enable/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two actively exploited zero-days in SonicWall SMA 1000 — CISA KEV listed, public PoC on GitHub, CVSS 10.0 SSRF enabling unauthenticated RCE. Apply SonicWall&amp;rsquo;s emergency patch immediately and restrict management access to SMA 1000 appliances while remediating.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge VPN appliance with unauthenticated RCE — treat as assume-breach: sweep logs for anomalous SMA 1000 admin activity and lateral movement indicators since before the disclosure date, and escalate any SMA 1000 in the estate to incident response review.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A CVSS 10.0 zero-day pair on a widely deployed enterprise VPN appliance is being actively exploited — confirm whether SonicWall SMA 1000 is in your environment, and if so brief leadership and prepare customer communications in case compromise is discovered during the sweep.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-15409 — CISA KEV: listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources&lt;/li>
&lt;/ul></description></item></channel></rss>