View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SonicWall SMA1000 zero-days exploited to deploy custom malware

🚨 ACTIVE EXPLOITATION

  • SonicWall SMA1000 zero-days exploited to deploy custom malware — bleepingcomputer.com
    Two zero-day vulnerabilities in SonicWall SMA1000 appliances were exploited to install custom malware.

    • Applies to SonicWall SMA1000 6210, 7210, and 8200v VPN appliances
    • Vulnerabilities: CVE-2026-15409 (critical SSRF) and CVE-2026-15410 (high-severity command injection)
    • Attackers exploited /wsproxy endpoint to create unauthenticated WebSocket tunnels exposing internal services
    • Used product_uuid from CouchDB to trigger command injection via sysCtrl.execRemoveHotfix RPC method
    • Installed custom malware: KNUCKLEBALL dropper deploying Sou5 reverse proxy and ORANGETAIL Java webshell
  • WP2Shell Exploit Enables Remote Takeover of Millions of WordPress Sites — darkreading.com
    Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to compromise WordPress sites.

    • Applies to millions of WordPress sites worldwide
    • Vulnerabilities CVE-2026-60137 and CVE-2026-63030 allow pre-auth remote code execution
    • Attackers chain both vulnerabilities to achieve remote takeover
    • Exploit attempts began within three days of public disclosure

💥 BREACHES & INCIDENTS

  • Hackers steal $23.7M from Ostium via off-chain price feed manipulation — bleepingcomputer.com
    Hackers stole $23.75 million from Ostium by manipulating off-chain price feeds.

    • Applies to Ostium decentralized trading platform on Arbitrum blockchain
    • Attack targeted off-chain infrastructure feeding price data into the protocol
    • Attackers submitted fake price reports to generate artificial profits
    • Stolen funds came from liquidity provider vault, not trader collateral
    • Exploiter swapped stolen USDC for Ethereum and laundered via TornadoCash
  • Estée Lauder suffers data breach via Oracle E-Business Suite vulnerability — bleepingcomputer.com
    Estée Lauder experienced a data breach through an Oracle E-Business Suite flaw.

    • Applies to Estée Lauder customers and HR data managed via Oracle E-Business Suite
    • Hackers exploited a vulnerability in Oracle E-Business Suite used for HR operations
    • Data breach involves unauthorized access to sensitive customer and employee information

🕵️ RESEARCH & DEEP DIVES

  • Sandbox escapes found in Cursor, Codex, Gemini CLI, and Antigravity AI coding agents — bleepingcomputer.com
    Researchers demonstrated sandbox escapes in four AI coding agents via file-based attacks.

    • Applies to Cursor, OpenAI Codex CLI, Google Gemini CLI, and Antigravity AI coding tools
    • Sandbox escapes occur by writing files inside the sandbox that trusted host tools later execute
    • Attack leverages prompt injection to craft malicious files triggering code execution outside sandbox
    • Multiple vulnerabilities patched including CVE-2026-48124 in Cursor 3.0.0 and Codex CLI v0.95.0
    • Google downgraded severity of Antigravity issues due to exploitation difficulty requiring social engineering
  • FreeRDP before 3.28.0 vulnerable to RCE via malicious CLI options in RDP files — cve.threatint.com
    FreeRDP before version 3.28.0 allows remote code execution via crafted RDP files.

    • Applies to FreeRDP versions before 3.28.0
    • Vulnerability in RDP file parser treating lines starting with '/' as CLI options
    • Attackers can craft malicious RDP files to execute arbitrary commands remotely
    • Exploits include bypassing certificate validation and exposing local filesystems
    • No user interaction required for exploitation

⚠️ LESSER-KNOWN / UNDER-REPORTED

  • JadePuffer ransomware targets AI model data with custom EncForge malware — bleepingcomputer.com
    JadePuffer ransomware now encrypts AI model data using the EncForge malware.
    • Targets AI and machine learning infrastructure including model checkpoints, vector databases, and training datasets
    • Uses Go-based EncForge ransomware targeting 180 file extensions specific to AI/ML formats
    • Attack exploits Langflow vulnerability CVE-2025-3248 and exposed Docker socket for root access
    • EncForge encrypts files with AES-256 and RSA-2048 hybrid scheme, appending .locked extension
    • No evidence of data exfiltration; attack automates payload delivery via Python scripts within minutes

🔓 CVEs & KEV

  • Other: 19 CVEs (worst 9.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check