hacker-news · Crawled Jul 19, 2026
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
6 IoCs
Read original article ↗
AI Summary
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances before their public disclosure. The actor chained CVE-2026-15409 and CVE-2026-15410 to achieve arbitrary command execution and root access, deploying custom malware and web shells for persistence. The exploitation chain involved WebSocket tunneling, authentication bypass via hardware UUID, and abuse of localhost services, enabling credential theft and network traffic interception, though lateral movement appears limited.
AI-extracted · verify before operational use