View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

INC Ransomware Exploits Two SonicWall SMA1000 Zero-Days

๐Ÿšจ ACTIVE EXPLOITATION

  • INC Ransomware Exploits Two SonicWall SMA1000 Zero-Days INC Ransomware is exploiting two SonicWall SMA1000 zero-days.

    • SonicWall SMA1000 appliances, including models 6210, 7210, 8200v and CMS, are affected.
    • CVE-2026-15409 enables unauthenticated WebSocket tunneling; CVE-2026-15410 escalates privileges to root.
    • Attackers chain the flaws to compromise VPN appliances and pivot into internal networks.
    • Observed tooling includes the KNUCKLEBALL Python script, Suo5 HTTP proxy and ORANGETAIL web shell.
    • Post-compromise activity includes theft of credentials, session databases and TOTP MFA seeds. ๐Ÿ“„ Source: resecurity.com ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via BleepingComputer
  • UPDATE: Attackers Exploit Critical Progress LoadMaster Command-Injection Flaw CVE-2026-8037 Attackers are exploiting CVE-2026-8037 in Progress LoadMaster appliances.

    • Progress Kemp LoadMaster and ADC products, plus affected MOVEit WAF deployments, are impacted.
    • CVE-2026-8037 is a critical OS command-injection flaw affecting GA 7.2.63.1 and earlier and LTSF 7.2.54.17 and earlier.
    • Unauthenticated attackers exploit unsanitized API input in multiple command endpoints to execute arbitrary commands as root.
    • Exploitation targets the apiuser parameter at the /accessv2 endpoint through the vulnerable escape_quotes() function.
    • KEVIntel recorded 792 attempts from 65 IP addresses across 18 countries; observed IPs include 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154. ๐Ÿ“„ Source: kevintel.com ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

(no items)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-10090 โ€” CVSS 9.9 โ€” Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access
  • CVE-2026-72761 โ€” CVSS 6.9 โ€” Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo p...
  • CVE-2026-72759 โ€” CVSS 6.9 โ€” cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data...
  • CVE-2026-71959 โ€” CVSS 6.9 โ€” Bitwarden Server before 2026.7.2 Audit Log Injection via POST /collectBitwarden Se...
  • CVE-2026-16742 โ€” CVSS 6.7 โ€” systemd-homed: local privilege escalation via missing home-record signature v...

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • UPDATE: Kimsuky Builds Local AI Toolkit for Phishing and Malware Development Kimsuky has built local AI tooling to support phishing and malware development.

    • Kimsuky targets diplomatic missions and military, security, and virtual asset sectors.
    • The group uses local Ollama, GPT4All, and Msty LLM environments with RAG and Cursor for stolen-data analysis, malware development, and attack automation.
    • AI-generated finance and cryptocurrency decoys imitate legitimate investment and workplace documents.
    • Spear-phishing emails deliver ZIP archives containing malicious LNK files that launch obfuscated PowerShell loaders.
    • GitHub and GitLab repositories provide C2 and distribution for encrypted AsyncRAT payloads. ๐Ÿ“„ Source: beritaharian.sg ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News, @metacurity@infosec.exchange
  • Windows WalletService flaw enables SYSTEM escalation; public PoC released CVE-2026-49176 A Windows WalletService flaw allows local attackers to gain SYSTEM privileges.

    • Windows endpoints and servers using WalletService are affected by CVE-2026-49176.
    • The flaw is an elevation-of-privilege issue caused by improper privilege management.
    • A local authenticated attacker can manipulate the user-controlled Wallet database path.
    • ESE processes attacker-controlled callback data, enabling WalletService to load a malicious DLL as LocalSystem.
    • The PoC was tested on Windows 11 25H2 build 26200.8737. ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Fake GoogleTranslate Chrome Extension Enables Hidden Browser Takeover A malicious Chrome extension can let attackers remotely control victims' browsers.

    • Chrome users who install the fraudulent GoogleTranslate extension are affected.
    • The extension steals browsing history, bookmarks, cookies, credentials, and extension details.
    • Attackers can live-stream Chrome sessions and remotely click, type, and submit forms in hidden windows.
    • A suspected Rust-based loader drops the extension and an AutoIt script that deploys Stealcv2.
    • The extension supports proxy configuration and JavaScript injection into selected websites. ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ“‹ ADVISORIES

  • Cisco Warns of High-Severity ClamAV Flaws With Public PoC Cisco disclosed high-severity ClamAV vulnerabilities with public proof-of-concept code.
    • Cisco Secure Endpoint Connectors for Windows, Linux, and Mac are affected.
    • Seven ClamAV vulnerabilities can disrupt malware scanning and cause denial-of-service conditions.
    • Remote unauthenticated attackers can submit specially crafted files to vulnerable ZIP, PESpin, GPT, PDF, Mach-O, and XAR parsers.
    • Public proof-of-concept code exists for CVE-2026-20337 and CVE-2026-20338; no in-the-wild exploitation is known. ๐Ÿ“„ Source: sec.cloudapps.cisco.com ยท ๐Ÿ“Ž [Coverage: securityweek.com](https://www.securityweek.com/cisco-warns-of-high-severity

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check