Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Critical SonicWall NSM Vulnerabilities Patched Do Son
    SonicWall patched critical SonicWall NSM vulnerabilities in on-prem software. Update now to protect your network against remote code execution. Related Posts: CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Apache Allura Security Vulnerabilities Patched in v1.21.0 CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation The post Critical SonicWall NSM Vulnerabilities Patched appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs Pierluigi Paganini
    SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthoriz
     

SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

2 de Setembro de 2026, 11:22

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation.

SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild.

  • CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthorized operations.
  • CVE-2026-83549 (CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). A remote attacker authenticated as an administrator could exploit it under specific conditions to execute arbitrary commands and achieve remote code execution. SonicWall’s investigation suggests attackers may be chaining the two flaws to compromise vulnerable appliances.

SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that the two SMA 1000 flaws are being exploited in the wild, with attackers likely chaining them to achive arbitrary code execution.

“SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.” reads the advisory.

The vulnerabilities affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier. 12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.

SonicWall recommends that customers first install the latest hotfix and check their systems for any signs of compromise. If they find indicators of compromise, they should re-image or redeploy the affected appliances, change all user and administrator passwords, and reset their time-based one-time passwords (TOTP).

SonicWall hasn’t disclosed technical details of the attack or said who is behind them. This is also the second recent security incident affecting the SMA product line in a month, recently the company patched two other flaws, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2).

In July, Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities to achieve root-level access on the devices before patches existed.

UTA0533 had exploited to deploy a malicious Python script named KNUCKLEBALL.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SMA 1000)

  • ✇Cybersecurity News
  • CVE-2026-83548 Exploited: SMA1000 SSRF Hits 10.0 Do Son
    CVE-2026-83548, a critical SonicWall SMA1000 vulnerability, is exploited in the wild. The pre-authentication SSRF flaw scores a maximum 10.0 CVSS. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post CVE-2026-83548 Exploited: SMA1000 SSRF Hits 10.0 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • SonicWall NetExtender Vulnerabilities Expose Linux Clients Do Son
    Two critical SonicWall NetExtender vulnerabilities (CVE-2026-66152, CVE-2026-66153) affect the NetExtender Linux Client. Update to version 10.3.6 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post SonicWall NetExtender Vulnerabilities Expose Linux Clients appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit Pierluigi Paganini
    INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since early August, targeting organizations across the United States, Australia, the United
     

INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

4 de Agosto de 2026, 10:46

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations.

Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since early August, targeting organizations across the United States, Australia, the United Arab Emirates, Colombia, Switzerland, and other countries.

Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities Catalog. Beyond exploiting the SonicWall flaws, Resecurity observed the ransomware operators using phone calls and emails as pressure tactics during extortion negotiations, highlighting the evolution of ransomware campaigns into coordinated multi-channel operations.

Organizations operating SonicWall SMA 1000 appliances remain at immediate risk if vulnerable systems have not been patched or investigated for compromise. Enterprises that rely on VPN appliances for remote access should also be aware that compromised gateways can provide attackers with privileged access to credentials, session data, and internal networks before ransomware deployment.

For example, the domain name associated with one of these emails (used by threat actors to contact the victim organization) was registered shortly after the actual incident and the exploitation activity, which Resecurity believes began in June 2026, prior to the release of the official advisory and the availability of the patch. The domain name was registered through a Chinese domain registrar that accepts cryptocurrency payments.

  • Domain Name: HELPRANS[.]COM
  • Registry Domain ID: 3106477703_DOMAIN_COM-VRSN
  • Registrar WHOIS Server: whois.ordertld.com
  • Registrar URL: http://www.ordertld.com
  • Updated Date: 2026-06-02T11:54:59Z
  • Creation Date: 2026-06-02T10:48:13Z
  • Registry Expiry Date: 2027-06-02T10:48:13Z
  • Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED
  • Registrar IANA ID: 3254
  • Registrar Abuse Contact Email: abuse@ordertld.com
  • Registrar Abuse Contact Phone: +852.30501810
  • Domain Status: clientTransferProhibited https://lnkd.in/deefCcwu
  • Name Server: DENVER.NS.CLOUDFLARE.COM
  • Name Server: TESSA.NS.CLOUDFLARE.COM

The victims were also contacted by an individual who introduced himself as “Andrew” using the phone number +1 (304) 384-0401. He claimed to be calling “from a group of hackers” and stated that the victim’s network had been compromised. At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as “pressure tactics.”

Resecurity recommends immediately contacting law enforcement if your organization faces such extortion demands.

What CISOs should do:

  • Immediately patch SonicWall SMA 1000 appliances, verify that systems have not already been compromised, and conduct threat hunting for indicators of post-exploitation activity.
  • Rotate privileged credentials, invalidate active VPN sessions where appropriate, and review authentication logs for evidence of credential theft or unauthorized administrative access.
  • Prepare incident response teams for modern ransomware tactics that combine technical compromise with direct phone and email contact intended to pressure victims into paying ransoms.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, INC Ransomware)

  • ✇Security Affairs
  • Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Pierluigi Paganini
    Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) a
     

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

20 de Julho de 2026, 04:29

Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available.

Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.

SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.

SonicWall investigated multiple incidents indicating these vulnerabilities are being actively exploited in the wild.

The first vulnerability, tracked as CVE-2026-15409 (CVSS score of 10.0), is a Server-side request forgery (SSRF) issue that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.

“A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.” reads the advisory.

The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.

“Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.” continues the advisory. “SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.”

Volexity first analyzed logs and security telemetry from two compromised SonicWall appliances. After gaining administrative SSH access, the team collected RAM, selected files, and full disk images. Initial triage quickly confirmed both devices had been compromised, while memory analysis with Volexity Volcano uncovered additional evidence of the attackers’ activity.

“Volexity’s analysis of logs, disk images, and memory led to the discovery of a threat actor Volexity tracks as UTA0533. This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft.” reads the report published Volexity. “Volexity notes that June 22, 2026, was the earliest sign of compromise observed in the investigation.”

The customization of the malware for SonicWall’s specific environment, rather than repurposing generic tooling, suggest the threat actor was prepared specifically for this target before the campaign started.

CVE-2026-15409 is a pre-authentication bypass in the appliance’s /wsproxy endpoint. An attacker sends a request with a User-Agent string containing “SMA Connect Agent” and a bmID parameter starting with -3389, and the appliance opens a WebSocket tunnel to services that are normally only reachable from localhost. Nothing about that initial request requires credentials. Once the tunnel is open, the attacker can reach the internal CouchDB database that ships with the SMA appliance, reading and writing files as the CouchDB user.

The attacker then stages a file in /tmp through the CouchDB access, using it to read the product_uuid value from the hardware identifier file at /sys/class/dmi/id/product_uuid. That UUID is the basis for the Basic authentication password protecting the SMA’s internal ctrl-service. The file is world-readable, so anyone who can reach the filesystem can derive the password. CVE-2026-15410 then comes into play: a path traversal flaw in the ctrl-service’s remove_hotfix workflow allows command execution with elevated privileges. The full chain goes from unauthenticated external access to root in a series of steps that each rely on the previous one.

“UTA0533 combined multiple zero-day vulnerabilities to compromise SonicWall SMA VPN appliances and obtain root-level access.” reads the report. “With root access, the threat actor could access stored or cached credentials, capture network traffic, and potentially intercept credentials processed by the appliances.”

A VPN appliance that handles authentication for the rest of your network is a particularly high-value target for credential interception. The attacker understood that.

On the first appliance, UTA0533 wrote a setuid binary called ROOTRUN to /usr/bin/xzfind, which allows an unprivileged user to run arbitrary commands as root. A Python script named KNUCKLEBALL was written to a site-packages directory and embedded two JAR archives that were injected into a legitimate SonicWall process. One JAR is Suo5, an open-source HTTP proxy tool. The other is ORANGETAIL, a custom Java web shell modeled on the Behinder framework, reachable through the paths /workplace/error.jsp and /workplace/dialogs/errorDialog.jsp. Both the NGINX Unit configuration and the appliance startup script were modified to ensure these components survived reboots.

The second appliance had fewer artifacts because it was rebooted on July 2, which flushed memory-resident components. However, it still showed the same NGINX configuration modifications, and the /var/tmp directory contained a script called lib.sh that launched tcpdump to capture unencrypted LDAP traffic and extract credentials passing through the appliance in cleartext.

A separate authentication bypass also exists that Volexity flagged, but it wasn’t used in this specific incident. Because the ctrl-service password is derived from the hardware UUID, and because that UUID file is readable by any local user, any unprivileged process with filesystem access can compute the password independently.

“Volexity found the product_uuid file is world readable, so unprivileged users can obtain its value. On multiple appliances to which Volexity had access, the UUID was set to a common value seen across many different systems belonging to different customers. It is a default UUID that comes with various hardware providers. Volexity only observed this UUID in cases where the owner’s device was physical, meaning virtual appliances were unaffected. Using this known UUID, an attacker would likely succeed in breaching the appliances without any other exploitation.” the cybersecurity firm notes.

“It should be noted that this authentication bypass does not appear to have been used in the observed incident. Instead, the attacker abused a different vulnerability to read the product_uuid file.”

The bypass remains real and exploitable even if UTA0533 reached the same destination through a different path.

SonicWall

Rapid7 published a proof-of-concept that demonstrates non-root remote code execution by tunneling the Erlang protocol through the WebSocket to the service on localhost:1050, enabling file reads, file writes, and arbitrary code execution through RPC calls.

“This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploit in the wild.” states Rapid7. “With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188.”

Services running on localhost are often less hardened precisely because they’re expected to be unreachable from outside, and the /wsproxy bypass eliminates that assumption entirely.

SonicWall released patches this week. Virtual appliances aren’t affected by the hardware UUID-derived password issue because product_uuid values only exist on physical hardware, but they’re still vulnerable to the core exploitation chain involving CVE-2026-15409 and CVE-2026-15410. UTA0533 appears to have had more success on the VPN appliances themselves than in moving laterally into the broader network afterward, but credential interception through an appliance that processes every authentication session is a serious enough outcome on its own without needing to pivot further. Check both your appliances and your downstream authentication infrastructure for signs of unexpected access.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini
    U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulner
     

U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog

15 de Julho de 2026, 07:49

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog.

The flaws added to the catalog are:

  • CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
  • CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability
  • CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
  • CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

This week, SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.

The company investigated multiple incidents indicating these vulnerabilities are being actively exploited in the wild.

The first vulnerability, tracked as CVE-2026-15409 (CVSS score of 10.0), is a Server-side request forgery (SSRF) issue that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.

“A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.” reads the advisory.

The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.

“Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.” continues the advisory. “SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.”

Regarding the other two issues added to the KEV catalog this month, Microsoft’s July 2026 Patch Tuesday security updates fixed a record 621 CVEs, including two that are being actively exploited as zero-days.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to urgently fix the vulnerabilities by July 17, 2026, except CVE-2026-56155, which must be addressed by July 28, 2026

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

  • ✇Security Affairs
  • SonicWall warns of active exploitation of two SMA 1000 zero-days Pierluigi Paganini
    SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT. The company investigated multiple incidents indicating these vulnerabilities are being actively exploited in the wild. The first vulnerabi
     

SonicWall warns of active exploitation of two SMA 1000 zero-days

15 de Julho de 2026, 05:02

SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution.

SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.

The company investigated multiple incidents indicating these vulnerabilities are being actively exploited in the wild.

The first vulnerability, tracked as CVE-2026-15409 (CVSS score of 10.0), is a Server-side request forgery (SSRF) issue that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location.

“A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.” reads the advisory.

The second vulnerability, tracked as CVE-2026-15410 (CVSS score of 7.2), is a post-authentication code injection flaw in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions.

“Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.” continues the advisory. “SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.”

The vulnerabilities impact the following software and versions:

Affected ProductAffected Version(s)
SMA1000 Models – 6210, 7210, 8200v 12.4.3-03245, 12.4.3-03387 and 12.4.3-03434 (platform-hotfix)12.5.0-02283, 12.5.0-02624 and 12.5.0-02800 (platform-hotfix)

The company addressed the issue in the following versions:

  • 12.4.3-03453 (platform-hotfix) and higher versions.
  • 12.5.0-02835 (platform-hotfix) and higher versions.

Customers should review system logs for indicators of compromise, such as unusual requests to login or logout API endpoints, suspicious WebSocket proxy connections, evidence of hotfix rollbacks using path traversal techniques, or unauthorized API routes in the appliance configuration.

SonicWall strongly recommends upgrading to the latest hotfix, performing a full forensic investigation, and, if compromise is confirmed, re-imaging or redeploying the appliance, resetting all user and administrator passwords, and re-enrolling TOTP tokens.

Sean Koessel and Steven Adair of Volexity helped advance PSIRT investigation, leading to the identification of an additional IOC.

“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.” concludes the advisory.

In December, SonicWall urged customers to address another SMA1000 Appliance Management Console issue that was exploited as a zero-day in attacks in the wild.

The flaw is a local privilege escalation issue which is due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

“A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).” reads the advisory published by the company. “Please note that SonicWall Firewall products are not affected by this vulnerability.”

The vendor warned customers that the vulnerability was chained with CVE-2025-23006 (CVSS score 9.8) in zero-day attacks to escalate privileges. The vendor has not disclosed details about the attacks that exploited the flaw as a zero-day, nor the attackers’ motivations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SMA 1000)

  • ✇@BushidoToken Threat Intel
  • Ransomware Tool Matrix Project Updates: Three Groups To Track BushidoToken
     IntroductionThis blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them
     

Ransomware Tool Matrix Project Updates: Three Groups To Track

15 de Junho de 2026, 05:31

 


Introduction


This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.


Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation.


For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.


Why these three groups?


Each of the three groups added in this update represents a different slice of the current ransomware ecosystem:


TheGentlemen


TheGentlemen is a newer operation that has matured quickly, with a large and varied toolkit that reflects how cross-pollinated the affiliate ecosystem has become. The recent internal chat leak gave researchers a rare look into their tradecraft, and the profiles capture both the tooling and the exploited CVEs that have been observed across multiple intrusions. TheGentlemen’s RTM profile is here and RVM profile is here.


DragonForce


DragonForce has continued to escalate throughout 2025 and into 2026, branching into MSP-focused attacks and standing up its own "cartel" model that other affiliates can plug into. Its exploitation of edge devices (Ivanti, Fortinet, SonicWall) and SimpleHelp RMM make it a high-priority threat for any organisation using such systems. DragonForce’s RTM profile is here and RVM profile is here.


WarLock


WarLock jumped onto everyone's radar after the ToolShell SharePoint zero-day exploitation campaign, and has since been linked to a string of edge-application exploits including SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. It is a strong example of a likely China-based operator that lives on zero-day exploitation of internet-facing software. WarLock’s RTM profile is here and RVM profile is here.


Observations and Trends


A few themes are worth flagging across all three profiles:


  • BYOVD is now standard, not novel. All three groups have been observed bringing vulnerable drivers to disable or blind EDR. TheGentlemen with ThrottleStop driver, DragonForce with the TrueSight and Hangzhou Shunwang drivers, and WarLock with Antiy, NsecSoft, Rising, and VMTools drivers. If your detection stack is not yet hunting on or blocking suspicious driver loads and known-bad driver hashes, that is a high-priority gap to close.
  • Network edge devices and other internet-facing systems remain the front door to victim networks for these groups. Fortinet, Ivanti, SonicWall, SimpleHelp, Microsoft SharePoint, SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack all appear across these three profiles. Patch prioritisation that focuses on internet-exposed appliances and admin tooling continues to give defenders a valuable return on effort.
  • Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations. Defender should use these lists to begin baselining what should exist in their environment and start alerting on the rest.

Conclusion


My recommendation for defenders remains the same as in previous updates: take the tools and CVEs from the RTM and RVM profiles and start threat hunting for their presence, writing detection rules to alert on certain behaviours, and blocking what is not expected or permitted in your environment. These three new profiles should make that easier to scope by group when you need to brief leadership, prioritise a hunt, or map your exposure to a specific campaign.


Here's a few sites that can help with turning the threat intel in these new profiles into detections:


- https://rulehound.com/rules

- https://detection.fyi

- https://www.snapattack.com/community


As always, feedback and pull requests are very welcome on both repos. Thanks to everyone who has contributed reports, corrections, and ideas. These projects only stay useful because the community keeps feeding them one way or another.

  • ✇HACKMAGEDDON
  • CVEs Targeting Remote Access Technologies in 2025 Paolo Passeri
    The exploitation of vulnerabilities targeting remote access technologies to gain initial access is continuing relentlessly also during 2025, with initial access brokers, and in general opportunistic and targeted threat actors, quite active in leveraging software flaws to break into organizations.
     

CVEs Targeting Remote Access Technologies in 2025

7 de Outubro de 2025, 05:18
The exploitation of vulnerabilities targeting remote access technologies to gain initial access is continuing relentlessly also during 2025, with initial access brokers, and in general opportunistic and targeted threat actors, quite active in leveraging software flaws to break into organizations.
❌
❌