<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vpn-Appliances on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vpn-appliances/</link><description>Recent content in Vpn-Appliances on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 21 Jul 2026 12:43:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vpn-appliances/index.xml" rel="self" type="application/rss+xml"/><item><title>SonicWall SMA1000 zero-days exploited to deploy custom malware</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custo/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SonicWall SMA1000 is widely deployed enterprise VPN/remote-access infrastructure; active zero-day exploitation with custom malware implants is confirmed. Patch SMA1000 appliances to the latest firmware immediately and inspect filesystem and running processes for signs of persistent malware.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Zero-day compromise of edge VPN appliances with custom malware warrants an assume-breach posture for any environment running SMA1000. Hunt for anomalous outbound connections, credential-harvest activity, or lateral movement originating from these appliances, and check for unknown binaries or modified configs on the devices.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirmed zero-day exploitation of a common enterprise VPN product deploying custom malware is a board-visible risk. Verify this week whether your organization runs SonicWall SMA1000, and if so direct engineering and SOC to assess exposure and report status before it becomes a customer or leadership question.&lt;/li>
&lt;/ul></description></item></channel></rss>