Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
6 articles · Updated July 22, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms
A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a…
5 articles · Updated July 25, 2026 -
INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly
The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began…
3 articles · Updated August 6, 2026 -
Attackers Exploit AI Brand Trust to Distribute Malware
Sophos X-Ops reported that attackers are impersonating popular AI brands like Claude, ChatGPT, and Copilot to distribute malware, including information stealers and backdoors. Over a year, they reviewed 86 Managed…
3 articles · Updated August 21, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
ICS Advisories for Yokogawa FAST/TOOLS and AVEVA PI to CONNECT Agent
On February 10, 2026, CISA issued advisories for vulnerabilities in Yokogawa FAST/TOOLS and AVEVA PI to CONNECT Agent. These advisories highlight potential security risks affecting industrial control systems, urging…
640 articles · Updated February 10, 2026
Recent Intelligence Reports
- Critical SonicWall SMA 1000 Zero-Day Vulnerabilities (CVE-2026-83548 & CVE-2026-83549) — Triskelelabs · September 3, 2026
- SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity — Thecyberexpress · September 3, 2026
- Known Exploited Vulnerabilities Catalog — www.cisa.gov · September 2, 2026
- SonicWall SMA 1000 Zero — Darkreading · September 2, 2026
- SonicWall advises customers to patch two new SMA1000 zero-days | news — Scmagazine · September 2, 2026
- SonicWall SMA1000 Hacked Third Time; MFA Seeds Stolen in July Outlast September Patches — Techtimes · September 2, 2026
- SonicWall Patches Two New Actively Exploited Zero — Securityaffairs.Co · September 2, 2026
- Fake AI, real malware: Attackers impersonating AI brands — News.Sophos · August 19, 2026