Synthesized by Clarity (Claude) from 35 sources · May contain errors — spot one? [email protected] · Methodology →
SonicWall SMA1000 CVSS 10 Zero-Day Under Active Exploitation
- Sources
- 35
- Words
- 1,091
- Read
- 5min
◆ The signal
Unauthenticated, internet-facing SSRF. No workaround. Patch before EOD and hunt logs for requests to /api/login and /wsproxy. Microsoft's Patch Tuesday runs to 622 CVEs, a record. Two are active zero-days, in ADFS and SharePoint. Triage those two ahead of the other 620.
◆ INTELLIGENCE MAP
Intelligence map
01 Active Exploitation Fires — Patch Before EOD
act nowSonicWall SMA1000 (CVSS 10, unauth SSRF) is being exploited; hotfix-only. Microsoft's record 622-CVE Patch Tuesday hides two exploited zero-days — ADFS (CVE-2026-56155) and SharePoint (CVE-2026-56164). ServiceNow shipped a pre-auth RCE fix (CVE-2026-6875); a LegacyHive PoC dropped within hours.
- SonicWall severity
- Active zero-days
- Patch-to-PoC
02 AI Industrializes Offense and Floods the CVE Queue
monitorCato Networks drove GPT-5.5 in a custom harness to domain admin in 40 minutes — collapsing detection windows to a lunch break. AI bug-finding tripled Microsoft CVEs (206→622), burying real zero-days in noise. Immunefi logged a record 207 DeFi incidents in H1 2026 as AI-tooled attackers carpet-bomb under-resourced targets.
- Time-to-DA
- CVE spike
- DeFi incidents H1
03 M365 Takeover Beats Your Containment Playbook
monitorForg365, a Telegram-sold PhaaS kit, chains AI lures + device-code phishing + attacker-side session refresh — so a password reset won't evict the intruder. Entra ID makes passkeys the default Sept 1 2026 and retires Microsoft SMS/voice MFA Feb 1 2027, a hard deadline for every SMS-dependent service account and break-glass path.
- Passkey default
- SMS/voice killed
- Sep 1 2026Passkeys become the Entra ID default
- Feb 1 2027Microsoft-provided SMS/voice MFA retired
04 Threat-Landscape & Vendor-Concentration Shifts
backgroundUS kinetic strikes on Iran plus a Hormuz blockade historically precede Iranian APT retaliation (APT33/34/35, CyberAv3ngers) against banks, energy, and exposed OT within days. Stripe's $53B bid for PayPal would concentrate $3.69T in annual payment volume under one entity — a vendor SPOF and PCI-DSS integration event. Bland AI raised $100M to industrialize synthetic voice calls.
- Combined volume
- Bland AI raise
- Brent crude
◆ DEEP DIVES
Deep dives
01 Three Active Fires, One 'Triage by Exploitability' Rule
act now evidence: highTriage by exploitability, not headline volume. This ledger leaves no other option. The SonicWall SMA1000 flaw is the sharpest: an unauthenticated, internet-facing SSRF scored CVSS 10, confirmed in multiple incidents, with no workaround but the hotfix. SonicWall published log-based IOCs. Watch for unexpected requests to /__api__/login and /wsproxy. That lets you tell whether you were breached before patching. Assume breach. Hunt first.
The two Microsoft zero-days matter for where they live. CVE-2026-56155 (AD FS) sits on the federated-identity layer. Treat active exploitation as a possible Golden SAML token-forgery event and review token-issuance logs for the prior two weeks after applying the KB. CVE-2026-56164 (SharePoint Server) is a network-reachable auth bypass. Hunt for webshells and anomalous file access. Both landed inside a record 622-CVE release. A working PoC, LegacyHive, for a User Profile Service EoP dropped within hours of the patch. The monthly-cadence assumption is dead.
Threat ID / Severity Vector Action SonicWall SMA1000 CVSS 10.0 Unauth internet-facing SSRF Hotfix now + hunt IOCs Microsoft AD FS CVE-2026-56155 Federated identity, exploited Patch + Golden SAML hunt Microsoft SharePoint CVE-2026-56164 Network auth bypass, exploited Patch + webshell hunt ServiceNow CVE-2026-6875 Pre-auth RCE, Rhino escape Verify fix + retro-hunt ServiceNow rounds out the fires. CVE-2026-6875 abuses GlideRecord query filters to escape the Rhino sandbox and run unsandboxed code. Mitigated within 24 hours. That stops future exploitation and nothing else. Confirm your instance received the Guarded Script and retro-hunt for prior pre-auth GlideRecord activity, new admin accounts, and commands on connected proxy servers.
Patch SonicWall first and the two exploited Microsoft zero-days next — the other 620 CVEs can wait for your KEV feed.
Action items
- Patch or isolate every internet-facing SonicWall SMA1000 appliance immediately, then hunt logs for requests to /__api__/login and /wsproxy to confirm pre-patch compromise.
- Fast-track CVE-2026-56155 (ADFS) and CVE-2026-56164 (SharePoint) ahead of the other 620 CVEs, and retro-hunt ADFS token-issuance logs for Golden SAML before declaring the patch sufficient.
- Confirm your ServiceNow instance received the CVE-2026-6875 mitigation and hunt for anomalous pre-auth GlideRecord activity and new admin accounts.
Sources:TLDR InfoSec · Cyberpresso · The Hacker News · CyberScoop
02 40 Minutes to Domain Admin: Your Cadence Just Became Existential
monitor evidence: highThe number that matters is not the CVE count. It's the clock. Cato Networks wrapped GPT-5.5 in a custom harness that ran a full attack chain to domain administrator in 40 minutes. Tenable, Proofpoint, and SpecterOps have built model-agnostic harnesses that swap the underlying LLM and hold results steady. The capability lives in the harness, in operational context and system integration, not the model. AI-speed attacks are now portable and commoditizing. An hourly SOC rhythm does not survive a 40-minute time-to-DA.
The same efficiency explains the 622-CVE flood. June's prior record was 206. Researchers attribute the 3x spike to AI bug-finding tooling, not a real surge in risk. That puts Microsoft on pace for 2,000–3,000 CVEs this year against 2020's record of 1,245. Hand-triaging by CVSS is finished. Automate against CISA KEV and EPSS so genuine zero-days surface above the noise.
Crypto is the leading indicator. Immunefi logged a record 207 DeFi incidents in H1 2026 while aggregate losses fell below $1B, down more than 50% year over year. This is a bifurcated economy. Well-resourced targets deploy AI-hardening. Attackers use GLM 5.2/GPT 5.6-class tooling to carpet-bomb the long tail. The pattern generalizes past crypto. LLM tooling collapses the cost of recon and exploit generation. That makes a forgotten subsidiary app, an orphaned integration, or an unmaintained service worth attacking at machine speed.
Defenders who monitor only crown jewels are defending the wrong perimeter. The economics inverted the risk model. The weakest, least-watched asset is now the most probable entry point. Detection tuned for human-paced recon will miss the campaign.
When an AI harness reaches domain admin in 40 minutes, exploitation evidence is the only triage key that still matters. Vulnerability volume is not.
Action items
- Re-architect patch prioritization around CISA KEV and EPSS automation this quarter, treating 500+ monthly Microsoft CVEs as the new baseline instead of hand-triaging by CVSS.
- Purple-team a 40-minute time-to-domain-admin scenario this sprint and validate automated containment on Tier-0 privilege anomalies and lateral movement.
- Extend detection coverage to long-tail assets — orphaned integrations, unmaintained apps, low-traffic subsidiaries — this sprint, not just high-value systems.
Sources:CyberScoop · TLDR InfoSec · TLDR Crypto
03 Forg365 Survives Your Reset — and the Entra SMS Cliff Is Dated
monitor evidence: highThe mechanism worth watching in Forg365 is persistence, not delivery. Device-code phishing abuses a legitimate OAuth flow. The victim authenticates on a genuine Microsoft page, so there's no lookalike domain for URL filters to catch. Once tokens are captured, attacker-side session refresh keeps the adversary authenticated indefinitely. A password reset evicts nobody. It's sold as-a-service over Telegram with AI-generated lures. That commoditizes full M365 tenant takeover, which puts it a step past a one-off exploit.
The containment runbook is the gap. On takeover you have to revoke refresh tokens, force global sign-out, invalidate all sessions, and rotate every credential the account touched. Then verify no new tokens mint. Highest-value prevention is an Entra Conditional Access policy blocking the device-code flow for populations that don't need it. Run report-only first to confirm no legitimate onboarding breaks.
Microsoft is pushing the same direction from the platform side, with dates attached. Entra ID makes passkeys the default on September 1, 2026, auto-prompts SMS/voice users to enroll at next MFA, and retires Microsoft-provided SMS/voice MFA entirely on February 1, 2027. Continued SMS then requires paid telecom partners via the Microsoft Security Store. SMS OTP is phishable and SIM-swappable, so the hygiene is net-positive. It will also silently break any workflow secretly dependent on SMS, including service accounts and break-glass paths.
Treat the two dates as one project. Inventory every SMS/voice dependency and decide the paid telecom fallback before the September default flip, not the February cliff. The migration surfaces exactly the undocumented automation and recovery paths an attacker would look for first.
A password reset no longer evicts a phished M365 attacker — without device-code auth disabled and session revocation forced, breached accounts stay breached.
Action items
- Deploy an Entra Conditional Access policy blocking device-code authentication for populations that don't need it (report-only first), and enforce FIDO2/passkeys for privileged users this sprint.
- Rewrite the M365 takeover runbook to revoke refresh tokens, force global sign-out, and rotate touched app credentials — do not rely on password reset alone.
- Charter the Entra SMS/voice-to-passkey migration this quarter, inventorying every service account and break-glass path before the Sept 1 2026 default flip.
Sources:CSO First Look · CSO Security Leadership · TLDR IT
04 Iran Escalation Resets Your Threat Model
monitor evidence: mediumIranian retaliation follows US escalation on a predictable lag. After the 2020 Soleimani strike, CISA issued Shields-Up warnings. Iranian actors ran the Ababil DDoS campaign against US banks in 2012–13. CyberAv3ngers hit exposed water-utility PLCs in 2023. The current trigger is a seven-hour overnight strike on Iranian missile, drone, and coastal-defense sites, plus a reimposed naval blockade near the Strait of Hormuz. The prior ceasefire is broken. Brent is back above $85.
The expected pattern is the Iranian-nexus playbook, not novel zero-days. Opportunistic, high-volume tactics against exposure. The likely TTPs map cleanly to monitoring:
Actor Typical target Primary TTPs APT33 / Peach Sandstorm Energy, aerospace Password spraying (T1110.003), spearphishing (T1566) APT34 / OilRig Financial, gov, energy Public-facing app exploitation (T1190) APT35 / Charming Kitten Broad, incl. individuals Credential harvesting, social engineering CyberAv3ngers Exposed OT/ICS Default-cred access to internet-facing PLCs/HMIs Financial services, energy, and internet-facing OT are the historical target set. Defenders in those sectors typically move pre-incident: loading Iran-nexus IOCs, deploying detections for password spraying and public-facing-app exploitation, validating DDoS scrubbing capacity, and hunting exposed HMIs/PLCs with default credentials. The market signal is noise. CrowdStrike (+12%) and Okta (+11%) rallied on CPI-driven risk-on sentiment. The escalation is the actual indicator.
US strikes on Iran are a reliable leading indicator of cyber retaliation against banks, energy, and exposed OT. The window to prepare closes when the first DDoS lands, not before.
Action items
- Pull current CISA advisories on Iranian APTs, load Iran-nexus IOCs, and deploy detections for password spraying (T1110.003) and public-facing-app exploitation (T1190) now — pre-incident.
- Audit internet-exposed OT/ICS for default-credential HMIs/PLCs and validate DDoS scrubbing capacity for customer-facing financial services this sprint.
Sources:Finpresso
◆ QUICK HITS
Quick hits
ESET found Secure Boot trivially bypassable for 13 of its 14 years via 11 defective signed shims (one from 2013) Microsoft never revoked — exploitation plants firmware malware surviving OS reinstall and drive replacement, on Windows and Linux.
A new Qilin ransomware variant abuses Active Directory replication via DCSync (DRSUAPI/GetNCChanges) to harvest the credential store — alert on replication requests from non-domain-controller hosts.
Treasury, with the UK and Europol, sanctioned 1VPNS and a cryptor vendor tied to 'virtually every recent Europol investigation' — TRM Labs traced subscription payments of $58–$723; expect IOC churn as operators migrate anonymization infrastructure.
The White House's 'Gold Eagle' clearinghouse is live, using Anthropic's Mythos model to dedupe and rank cross-industry vulnerability reports — a new federal disclosure channel worth evaluating for feed access.
Microsoft's new security chief is replacing top executives to force an AI overhaul — leadership churn inside the Defender/Entra/Sentinel/Purview stack enterprises depend on; watch for default-config changes.
A $292M exploit rooted in misconfigured LayerZero OFT deployments — not a zero-day — drove $7.2B in capital to Chainlink CCIP, a live case study in dependency/config risk propagating across every org running the same standard with defaults.
The White House imposed export controls on Anthropic's 'Fable' model over cybersecurity fears — the first time a frontier model itself was restricted as a national-security artifact, setting precedent that models can become suddenly unavailable.
◆ Bottom line
The take.
Treat exploitation evidence — not vulnerability volume — as your triage key, invest detection engineering where containment already fails, and raise your posture ahead of predictable retaliation.
Frequently asked
- What log entries indicate pre-patch compromise of a SonicWall SMA1000?
- Hunt for unexpected requests to /__api__/login and /wsproxy in appliance logs — SonicWall published these as IOCs for the unauthenticated SSRF (CVSS 10.0) in the Appliance Work Place interface. Any hits mean assume-compromise: rotate every credential reachable through the gateway, since the hotfix closes the door but does not evict a resident attacker.
- Why does patching AD FS and SharePoint not end the incident?
- Both zero-days (CVE-2026-56155 and CVE-2026-56164) were exploited before fixes shipped, and patching evicts nothing already resident. For AD FS, treat it as a potential Golden SAML event and review token-issuance logs for the prior two weeks. For SharePoint, hunt webshells and anomalous file access. Declare the patch sufficient only after the retro-hunt clears.
- Should the 622-CVE Patch Tuesday change how we triage?
- Yes — manual CVSS ranking cannot scale to a 2,000–3,000 CVE annual pace, and the volume is largely an artifact of AI bug-finding tooling rather than a genuine risk surge. Rebuild prioritization around KEV and EPSS so actively exploited flaws float above the AI-generated noise, and assume 500+ Microsoft CVEs per month is the new baseline.
- Does reimaging still evict a compromised host?
- Not reliably. ESET disclosed 11 unrevoked signed shims enabling Secure Boot bypass on Windows and Linux, and exploitation plants firmware-resident malware that survives OS reinstallation and drive replacement. Until Microsoft ships full DBX revocations, IR runbooks need firmware/UEFI verification steps — otherwise 'nuke and reimage' returns a still-compromised host to production.
- What cyber activity should we expect after the US strikes on Iran?
- Based on prior patterns — Soleimani 2020, Ababil 2012–13, CyberAv3ngers 2023 — Iranian-nexus retaliation against US financial services, energy, and exposed OT typically arrives within days to weeks. Expected TTPs are password spraying, spearphishing, public-facing-app exploitation, DDoS against banks, and default-credential access to internet-exposed PLCs and HMIs. Treat this as a precautionary shields-up window.
◆ Same day, different angle
Read this day as…
◆ Recent in security
Keep reading.
- GPT-Red Beats Human Red Teams 84% to 13% on Frontier LLMs
- Entra ID OAuth Client-ID Spoofing Sprays Hide in AADSTS Noise
- FSB Center 16 Exploits 18-Year-Old Cisco Flaw in Critical Infra
- Dormant GitHub Account Ships One-Click LoadMaster RCE Kit
- Progress Orders ShareFile Shutdown as MOVEit Pattern Returns
Spot an error? [email protected]