Security daily

Synthesized by Clarity (Claude) from 35 sources · May contain errors — spot one? [email protected] · Methodology →

SonicWall SMA1000 CVSS 10 Zero-Day Under Active Exploitation

Sources
35
Words
1,091
Read
5min

Topics AI Regulation AI Capital Data Infrastructure

◆ The signal

Unauthenticated, internet-facing SSRF. No workaround. Patch before EOD and hunt logs for requests to /api/login and /wsproxy. Microsoft's Patch Tuesday runs to 622 CVEs, a record. Two are active zero-days, in ADFS and SharePoint. Triage those two ahead of the other 620.

◆ INTELLIGENCE MAP

Intelligence map

  1. 01

    Active Exploitation Fires — Patch Before EOD

    act now

    SonicWall SMA1000 (CVSS 10, unauth SSRF) is being exploited; hotfix-only. Microsoft's record 622-CVE Patch Tuesday hides two exploited zero-days — ADFS (CVE-2026-56155) and SharePoint (CVE-2026-56164). ServiceNow shipped a pre-auth RCE fix (CVE-2026-6875); a LegacyHive PoC dropped within hours.

    622
    CVEs in one Patch Tuesday
    4
    sources
    • SonicWall severity
    • Active zero-days
    • Patch-to-PoC
  2. 02

    AI Industrializes Offense and Floods the CVE Queue

    monitor

    Cato Networks drove GPT-5.5 in a custom harness to domain admin in 40 minutes — collapsing detection windows to a lunch break. AI bug-finding tripled Microsoft CVEs (206→622), burying real zero-days in noise. Immunefi logged a record 207 DeFi incidents in H1 2026 as AI-tooled attackers carpet-bomb under-resourced targets.

    40 min
    AI harness to domain admin
    3
    sources
    • Time-to-DA
    • CVE spike
    • DeFi incidents H1
  3. 03

    M365 Takeover Beats Your Containment Playbook

    monitor

    Forg365, a Telegram-sold PhaaS kit, chains AI lures + device-code phishing + attacker-side session refresh — so a password reset won't evict the intruder. Entra ID makes passkeys the default Sept 1 2026 and retires Microsoft SMS/voice MFA Feb 1 2027, a hard deadline for every SMS-dependent service account and break-glass path.

    Feb 1 2027
    Microsoft SMS MFA retirement
    3
    sources
    • Passkey default
    • SMS/voice killed
    1. Sep 1 2026Passkeys become the Entra ID default
    2. Feb 1 2027Microsoft-provided SMS/voice MFA retired
  4. 04

    Threat-Landscape & Vendor-Concentration Shifts

    background

    US kinetic strikes on Iran plus a Hormuz blockade historically precede Iranian APT retaliation (APT33/34/35, CyberAv3ngers) against banks, energy, and exposed OT within days. Stripe's $53B bid for PayPal would concentrate $3.69T in annual payment volume under one entity — a vendor SPOF and PCI-DSS integration event. Bland AI raised $100M to industrialize synthetic voice calls.

    $3.69T
    payment volume in one entity
    3
    sources
    • Combined volume
    • Bland AI raise
    • Brent crude
    1. Stripe$1.9T
    2. PayPal$1.79T

◆ DEEP DIVES

Deep dives

  1. 01

    Three Active Fires, One 'Triage by Exploitability' Rule

    act now evidence: high

    Triage by exploitability, not headline volume. This ledger leaves no other option. The SonicWall SMA1000 flaw is the sharpest: an unauthenticated, internet-facing SSRF scored CVSS 10, confirmed in multiple incidents, with no workaround but the hotfix. SonicWall published log-based IOCs. Watch for unexpected requests to /__api__/login and /wsproxy. That lets you tell whether you were breached before patching. Assume breach. Hunt first.

    The two Microsoft zero-days matter for where they live. CVE-2026-56155 (AD FS) sits on the federated-identity layer. Treat active exploitation as a possible Golden SAML token-forgery event and review token-issuance logs for the prior two weeks after applying the KB. CVE-2026-56164 (SharePoint Server) is a network-reachable auth bypass. Hunt for webshells and anomalous file access. Both landed inside a record 622-CVE release. A working PoC, LegacyHive, for a User Profile Service EoP dropped within hours of the patch. The monthly-cadence assumption is dead.

    ThreatID / SeverityVectorAction
    SonicWall SMA1000CVSS 10.0Unauth internet-facing SSRFHotfix now + hunt IOCs
    Microsoft AD FSCVE-2026-56155Federated identity, exploitedPatch + Golden SAML hunt
    Microsoft SharePointCVE-2026-56164Network auth bypass, exploitedPatch + webshell hunt
    ServiceNowCVE-2026-6875Pre-auth RCE, Rhino escapeVerify fix + retro-hunt

    ServiceNow rounds out the fires. CVE-2026-6875 abuses GlideRecord query filters to escape the Rhino sandbox and run unsandboxed code. Mitigated within 24 hours. That stops future exploitation and nothing else. Confirm your instance received the Guarded Script and retro-hunt for prior pre-auth GlideRecord activity, new admin accounts, and commands on connected proxy servers.

    Patch SonicWall first and the two exploited Microsoft zero-days next — the other 620 CVEs can wait for your KEV feed.

    Action items

    • Patch or isolate every internet-facing SonicWall SMA1000 appliance immediately, then hunt logs for requests to /__api__/login and /wsproxy to confirm pre-patch compromise.
    • Fast-track CVE-2026-56155 (ADFS) and CVE-2026-56164 (SharePoint) ahead of the other 620 CVEs, and retro-hunt ADFS token-issuance logs for Golden SAML before declaring the patch sufficient.
    • Confirm your ServiceNow instance received the CVE-2026-6875 mitigation and hunt for anomalous pre-auth GlideRecord activity and new admin accounts.

    Sources:TLDR InfoSec · Cyberpresso · The Hacker News · CyberScoop

  2. 02

    40 Minutes to Domain Admin: Your Cadence Just Became Existential

    monitor evidence: high

    The number that matters is not the CVE count. It's the clock. Cato Networks wrapped GPT-5.5 in a custom harness that ran a full attack chain to domain administrator in 40 minutes. Tenable, Proofpoint, and SpecterOps have built model-agnostic harnesses that swap the underlying LLM and hold results steady. The capability lives in the harness, in operational context and system integration, not the model. AI-speed attacks are now portable and commoditizing. An hourly SOC rhythm does not survive a 40-minute time-to-DA.

    The same efficiency explains the 622-CVE flood. June's prior record was 206. Researchers attribute the 3x spike to AI bug-finding tooling, not a real surge in risk. That puts Microsoft on pace for 2,000–3,000 CVEs this year against 2020's record of 1,245. Hand-triaging by CVSS is finished. Automate against CISA KEV and EPSS so genuine zero-days surface above the noise.

    Crypto is the leading indicator. Immunefi logged a record 207 DeFi incidents in H1 2026 while aggregate losses fell below $1B, down more than 50% year over year. This is a bifurcated economy. Well-resourced targets deploy AI-hardening. Attackers use GLM 5.2/GPT 5.6-class tooling to carpet-bomb the long tail. The pattern generalizes past crypto. LLM tooling collapses the cost of recon and exploit generation. That makes a forgotten subsidiary app, an orphaned integration, or an unmaintained service worth attacking at machine speed.

    Defenders who monitor only crown jewels are defending the wrong perimeter. The economics inverted the risk model. The weakest, least-watched asset is now the most probable entry point. Detection tuned for human-paced recon will miss the campaign.

    When an AI harness reaches domain admin in 40 minutes, exploitation evidence is the only triage key that still matters. Vulnerability volume is not.

    Action items

    • Re-architect patch prioritization around CISA KEV and EPSS automation this quarter, treating 500+ monthly Microsoft CVEs as the new baseline instead of hand-triaging by CVSS.
    • Purple-team a 40-minute time-to-domain-admin scenario this sprint and validate automated containment on Tier-0 privilege anomalies and lateral movement.
    • Extend detection coverage to long-tail assets — orphaned integrations, unmaintained apps, low-traffic subsidiaries — this sprint, not just high-value systems.

    Sources:CyberScoop · TLDR InfoSec · TLDR Crypto

  3. 03

    Forg365 Survives Your Reset — and the Entra SMS Cliff Is Dated

    monitor evidence: high

    The mechanism worth watching in Forg365 is persistence, not delivery. Device-code phishing abuses a legitimate OAuth flow. The victim authenticates on a genuine Microsoft page, so there's no lookalike domain for URL filters to catch. Once tokens are captured, attacker-side session refresh keeps the adversary authenticated indefinitely. A password reset evicts nobody. It's sold as-a-service over Telegram with AI-generated lures. That commoditizes full M365 tenant takeover, which puts it a step past a one-off exploit.

    The containment runbook is the gap. On takeover you have to revoke refresh tokens, force global sign-out, invalidate all sessions, and rotate every credential the account touched. Then verify no new tokens mint. Highest-value prevention is an Entra Conditional Access policy blocking the device-code flow for populations that don't need it. Run report-only first to confirm no legitimate onboarding breaks.

    Microsoft is pushing the same direction from the platform side, with dates attached. Entra ID makes passkeys the default on September 1, 2026, auto-prompts SMS/voice users to enroll at next MFA, and retires Microsoft-provided SMS/voice MFA entirely on February 1, 2027. Continued SMS then requires paid telecom partners via the Microsoft Security Store. SMS OTP is phishable and SIM-swappable, so the hygiene is net-positive. It will also silently break any workflow secretly dependent on SMS, including service accounts and break-glass paths.

    Treat the two dates as one project. Inventory every SMS/voice dependency and decide the paid telecom fallback before the September default flip, not the February cliff. The migration surfaces exactly the undocumented automation and recovery paths an attacker would look for first.

    A password reset no longer evicts a phished M365 attacker — without device-code auth disabled and session revocation forced, breached accounts stay breached.

    Action items

    • Deploy an Entra Conditional Access policy blocking device-code authentication for populations that don't need it (report-only first), and enforce FIDO2/passkeys for privileged users this sprint.
    • Rewrite the M365 takeover runbook to revoke refresh tokens, force global sign-out, and rotate touched app credentials — do not rely on password reset alone.
    • Charter the Entra SMS/voice-to-passkey migration this quarter, inventorying every service account and break-glass path before the Sept 1 2026 default flip.

    Sources:CSO First Look · CSO Security Leadership · TLDR IT

  4. 04

    Iran Escalation Resets Your Threat Model

    monitor evidence: medium

    Iranian retaliation follows US escalation on a predictable lag. After the 2020 Soleimani strike, CISA issued Shields-Up warnings. Iranian actors ran the Ababil DDoS campaign against US banks in 2012–13. CyberAv3ngers hit exposed water-utility PLCs in 2023. The current trigger is a seven-hour overnight strike on Iranian missile, drone, and coastal-defense sites, plus a reimposed naval blockade near the Strait of Hormuz. The prior ceasefire is broken. Brent is back above $85.

    The expected pattern is the Iranian-nexus playbook, not novel zero-days. Opportunistic, high-volume tactics against exposure. The likely TTPs map cleanly to monitoring:

    ActorTypical targetPrimary TTPs
    APT33 / Peach SandstormEnergy, aerospacePassword spraying (T1110.003), spearphishing (T1566)
    APT34 / OilRigFinancial, gov, energyPublic-facing app exploitation (T1190)
    APT35 / Charming KittenBroad, incl. individualsCredential harvesting, social engineering
    CyberAv3ngersExposed OT/ICSDefault-cred access to internet-facing PLCs/HMIs

    Financial services, energy, and internet-facing OT are the historical target set. Defenders in those sectors typically move pre-incident: loading Iran-nexus IOCs, deploying detections for password spraying and public-facing-app exploitation, validating DDoS scrubbing capacity, and hunting exposed HMIs/PLCs with default credentials. The market signal is noise. CrowdStrike (+12%) and Okta (+11%) rallied on CPI-driven risk-on sentiment. The escalation is the actual indicator.

    US strikes on Iran are a reliable leading indicator of cyber retaliation against banks, energy, and exposed OT. The window to prepare closes when the first DDoS lands, not before.

    Action items

    • Pull current CISA advisories on Iranian APTs, load Iran-nexus IOCs, and deploy detections for password spraying (T1110.003) and public-facing-app exploitation (T1190) now — pre-incident.
    • Audit internet-exposed OT/ICS for default-credential HMIs/PLCs and validate DDoS scrubbing capacity for customer-facing financial services this sprint.

    Sources:Finpresso

◆ QUICK HITS

Quick hits

  • ESET found Secure Boot trivially bypassable for 13 of its 14 years via 11 defective signed shims (one from 2013) Microsoft never revoked — exploitation plants firmware malware surviving OS reinstall and drive replacement, on Windows and Linux.

  • A new Qilin ransomware variant abuses Active Directory replication via DCSync (DRSUAPI/GetNCChanges) to harvest the credential store — alert on replication requests from non-domain-controller hosts.

  • Treasury, with the UK and Europol, sanctioned 1VPNS and a cryptor vendor tied to 'virtually every recent Europol investigation' — TRM Labs traced subscription payments of $58–$723; expect IOC churn as operators migrate anonymization infrastructure.

  • The White House's 'Gold Eagle' clearinghouse is live, using Anthropic's Mythos model to dedupe and rank cross-industry vulnerability reports — a new federal disclosure channel worth evaluating for feed access.

  • Microsoft's new security chief is replacing top executives to force an AI overhaul — leadership churn inside the Defender/Entra/Sentinel/Purview stack enterprises depend on; watch for default-config changes.

  • A $292M exploit rooted in misconfigured LayerZero OFT deployments — not a zero-day — drove $7.2B in capital to Chainlink CCIP, a live case study in dependency/config risk propagating across every org running the same standard with defaults.

  • The White House imposed export controls on Anthropic's 'Fable' model over cybersecurity fears — the first time a frontier model itself was restricted as a national-security artifact, setting precedent that models can become suddenly unavailable.

◆ Bottom line

The take.

Treat exploitation evidence — not vulnerability volume — as your triage key, invest detection engineering where containment already fails, and raise your posture ahead of predictable retaliation.

— Promit, reading as Security ·

Frequently asked

What log entries indicate pre-patch compromise of a SonicWall SMA1000?
Hunt for unexpected requests to /__api__/login and /wsproxy in appliance logs — SonicWall published these as IOCs for the unauthenticated SSRF (CVSS 10.0) in the Appliance Work Place interface. Any hits mean assume-compromise: rotate every credential reachable through the gateway, since the hotfix closes the door but does not evict a resident attacker.
Why does patching AD FS and SharePoint not end the incident?
Both zero-days (CVE-2026-56155 and CVE-2026-56164) were exploited before fixes shipped, and patching evicts nothing already resident. For AD FS, treat it as a potential Golden SAML event and review token-issuance logs for the prior two weeks. For SharePoint, hunt webshells and anomalous file access. Declare the patch sufficient only after the retro-hunt clears.
Should the 622-CVE Patch Tuesday change how we triage?
Yes — manual CVSS ranking cannot scale to a 2,000–3,000 CVE annual pace, and the volume is largely an artifact of AI bug-finding tooling rather than a genuine risk surge. Rebuild prioritization around KEV and EPSS so actively exploited flaws float above the AI-generated noise, and assume 500+ Microsoft CVEs per month is the new baseline.
Does reimaging still evict a compromised host?
Not reliably. ESET disclosed 11 unrevoked signed shims enabling Secure Boot bypass on Windows and Linux, and exploitation plants firmware-resident malware that survives OS reinstallation and drive replacement. Until Microsoft ships full DBX revocations, IR runbooks need firmware/UEFI verification steps — otherwise 'nuke and reimage' returns a still-compromised host to production.
What cyber activity should we expect after the US strikes on Iran?
Based on prior patterns — Soleimani 2020, Ababil 2012–13, CyberAv3ngers 2023 — Iranian-nexus retaliation against US financial services, energy, and exposed OT typically arrives within days to weeks. Expected TTPs are password spraying, spearphishing, public-facing-app exploitation, DDoS against banks, and default-credential access to internet-exposed PLCs and HMIs. Treat this as a precautionary shields-up window.

◆ Same day, different angle

Read this day as…

◆ Recent in security

Keep reading.

Spot an error? [email protected]