Volexity discovered threat actor UTA0533 exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to achieve root-level remote code execution. CVE-2026-15409 enables pre-auth SSRF via /wsproxy to tunnel to localhost services, while CVE-2026-15410 enables command injection via path traversal in the sysCtrl.execRemoveHotfix endpoint. The actor deployed custom malware including KNUCKLEBALL (Java agent injector), ORANGETAIL (webshell), and ROOTRUN (privilege escalation binary), then used tcpdump to capture LDAP credentials and attempted lateral movement from over 200 IP addresses.
NGINX
8 posts
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation Cyber Centre Daily Advisory Digest — 2026-07-15 (5 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-07-15 containing five security advisories covering HPE, Google Chrome, Citrix, Notepad++, and F5 products. The Citrix advisory explicitly references CVE-2026-53565 and CVE-2026-53566 affecting Citrix Secure Access Client and Citrix Endpoint Analysis Client for Windows. The F5 advisory covers a wide range of NGINX and BIG-IP products. All advisories recommend reviewing vendor publications and applying updates or mitigations promptly.
Cyber Centre Daily Advisory Digest — 2026-05-25 (7 advisories) The Canadian Centre for Cyber Security released a daily advisory digest summarizing security updates from IBM, Roundcube, Dell, Ubuntu, CISA (ICS), Red Hat, and cPanel. Organizations are strongly encouraged to review the respective vendor advisories and apply available patches to mitigate potential vulnerabilities across enterprise, cloud, and industrial control systems.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.
Cyber Centre Daily Advisory Digest — 2026-05-22 (6 advisories) The Canadian Centre for Cyber Security released a daily digest of six security advisories. Notably, a highly critical SQL injection vulnerability in Drupal Core (CVE-2026-9082) is currently being exploited in the wild, and F5 has disclosed a critical vulnerability (CVE-2026-9256) affecting multiple NGINX products.
Cyber Centre Daily Advisory Digest — 2026-05-20 (5 advisories) The Canadian Centre for Cyber Security released a daily digest of five security advisories on May 20, 2026. The advisories highlight critical and high-severity vulnerabilities across FreePBX, F5 NGINX, Google Chrome, HPE Aruba Networking products, and cPanel, urging administrators to apply vendor-supplied patches immediately to prevent potential exploitation.
CVE-2026-42945: Mitigating a Critical Heap Buffer Overflow Vulnerability in NGINX CVE-2026-42945, dubbed 'NGINX Rift', is a critical heap buffer overflow vulnerability in the NGINX HTTP rewrite module (ngxhttprewrite_module). It allows unauthenticated attackers to cause a Denial of Service (DoS) or potentially achieve Remote Code Execution (RCE) by sending crafted HTTP requests to servers configured with specific rewrite directives containing unnamed PCRE captures and a question mark.
April 2026 CVE Landscape In April 2026, 37 high-impact vulnerabilities were actively exploited, heavily impacting enterprise systems and edge infrastructure. Notable exploitation includes the delivery of the Nexcorium botnet via CVE-2024-3721 in TBK DVR devices and complete service takeovers of Nginx UI instances via CVE-2026-33032, a missing authentication flaw.