CISOOnline

SonicWall reports two major security holes under active exploit

Repeats a June attack chain

What makes this issue especially significant is the timing and the pattern, he pointed out. “This is essentially a rerun of what happened with the same appliance line just weeks ago,” he said, citing the July disclosure of a “nearly identical” SSRF-plus-command-injection chain in SMA1000 that researchers at Volexity traced to exploitation starting June 22, weeks before a patch existed.

“That earlier chain was picked up by a threat cluster tracked as UTA0533 and then weaponized at scale by the INC ransomware operation, which has claimed roughly 900 victims globally since,” he noted. In those operations, attackers were harvesting local credentials, session databases, and TOTP MFA seeds to gain persistent, hard-to-evict access before moving laterally into victim networks.

And, Wilkes pointed out, that hasn’t been the only reported vulnerability; there have been 18 – 22 publicly disclosed CVEs impacting SonicWall products over the past 12 months, resulting in other cybersecurity issues which have included ransomware attacks.



Source link