SonicWall SMA1000 Flaws Exploited as Zero-Days to Push Custom Malware
ID: 33f51ca4-ad74-5b95-b0d4-42e9bf06f4b6
STIX ID: report--33f51ca4-ad74-5b95-b0d4-42e9bf06f4b6
Feed Name: CosmicBytez Labs
Threat Score
SonicWall confirmed active zero-day exploitation of two chained vulnerabilities in SMA1000 appliances that allowed attackers to install custom firmware-level implants which persist across resets, harvest VPN credentials, intercept TLS sessions, and maintain encrypted C2; patches and IOCs were released and organizations are advised to assume compromise, capture forensics before patching, rotate credentials, and verify firmware integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
