#0001VVolexity23 days ago14 min▣LLM reportcritical Volexity discovered threat actor UTA0533 exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to achieve root-level remote code execution. CVE-2026-15409 enables pre-auth SSRF via /wsproxy to tunnel to localhost services, while CVE-2026-15410 enables command injection via path traversal in the sysCtrl.execRemoveHotfix endpoint. The actor deployed custom malware including KNUCKLEBALL (Java agent injector), ORANGETAIL (webshell), and ROOTRUN (privilege escalation binary), then used tcpdump to capture LDAP credentials and attempted lateral movement from over 200 IP addresses.
#0002VVolexity2 months ago6 min▣LLM reporthigh VerdantBamboo, a Chinese threat actor, compromised edge appliances including Egnyte Storage Sync, pfSense firewalls, and Synology NAS devices to deploy custom malware (BRICKSTORM, PLENET, AGENTPSD). The attackers exploited a compromised MSP and local privilege escalation misconfigurations to maintain long-term persistence, using the compromised devices to proxy traffic and bypass Microsoft 365 Conditional Access policies.
#0003VVolexity3 months ago3 min▣LLM reportlow Volexity has released updates to its Golang reverse engineering tooling to address the growing trend of Go-based malware and obfuscation techniques like Garble. The release introduces GoStringExtractor, a plugin for IDA Pro and Ghidra that organizes unterminated Go string tables, and updates GoResolver to recover runtime type information (RTTI), significantly enhancing static analysis capabilities.
#0004VVolexity3 months ago7 min▣LLM reporthigh The China-aligned threat actor UTA0388 is leveraging Large Language Models (LLMs) to conduct highly tailored, rapport-building spear-phishing campaigns targeting organizations in North America, Asia, and Europe. These campaigns deliver GOVERSHELL, a custom backdoor deployed via DLL search order hijacking, which has undergone rapid, non-iterative development across five variants to evade detection and establish persistent C2.
#0005VVolexity3 months ago6 min▣LLM reporthigh Russian threat actor UTA0355 is conducting targeted phishing campaigns against foreign policy and government professionals by spoofing European security conferences. The attackers use rapport-building techniques and out-of-band messaging to trick victims into authorizing malicious Microsoft 365 OAuth applications and Device Code workflows, granting unauthorized access to their accounts.