Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
ID: 07e451dc-59b5-5815-ba6c-5fde77afb743
STIX ID: report--07e451dc-59b5-5815-ba6c-5fde77afb743
Feed Name: Volexity Blog
Volexity investigated compromises of SonicWall SMA 1000-series appliances (earliest observed June 22, 2026) where threat actor UTA0533 abused multiple zero-day flaws — including a wsproxy bypass and a sysCtrl path-traversal leading to execution — to gain root, deploy a setuid privilege escalation binary and Java-based webshells (Suo5/ORANGETAIL), and capture credentials and network traffic; the report provides timelines, IOCs (logs, file hashes, IPs), exploitation chain reconstruction, and mitigation/detection recommendations including hotfix versions and YARA signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
