🚨 ACTIVE EXPLOITATION
-
SonicWall SMA 1000 VPN Zero-Days Exploited Pre-Disclosure for Root Access — The Hacker News
A threat actor exploited multiple zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances before public disclosure.- Applies to SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
- Exploited vulnerabilities CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) enable arbitrary command execution and root access
- Attack involves unauthenticated WebSocket tunnel creation via /wsproxy, CouchDB exploitation, and privilege escalation through path traversal
- Threat actor UTA0533 deployed custom malware including ROOTRUN setuid binary, KNUCKLEBALL Python script, Suo5 HTTP proxy, and ORANGETAIL Java web shell
- Exploitation discovered by Volexity during incident response; patches released by SonicWall after June 22, 2026
-
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware — The Hacker News
Russian group UAC-0145 uses ClickFix CAPTCHAs to deliver malware to Ukrainian devices.- Targets Ukrainian users via compromised websites with fake CAPTCHA prompts
- Instructs victims to run PowerShell commands that download malware like GHETTOVIBE
- Uses PowerShell script SCOUTCURL for reconnaissance and loaders FLUIDLEECH, LOADLOOP
- Deploys backdoors such as FREAKYPOLL (Python) and Android backdoor COWARDDUCK via APKs
- Employs traffic filtering and dynamic page content tools Cloaking.House and SMARTAXE