CyberSecurity News
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
AI summary
A threat actor known as UTA0533 exploited two SonicWall zero-days to deliver custom malware. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were targeted by the actor for weeks before a patch was released. The threat actor was tracked by Volexity, a security firm. The exploitation resulted in the delivery of custom malware. The vulnerabilities were eventually patched, but not before being exploited for an extended period.
Vulnerabilities mentioned
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to SecurityWeek.

