A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

Reports indicate that a sophisticated threat actor, identified as UTA0533, has been actively exploiting two zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits were reportedly chained together to achieve arbitrary command execution and subsequently gain root access on affected systems. The exploitation occurred prior to the public disclosure of these vulnerabilities, which are tracked as CVE-2026-15409 and CVE-2026-15410.
The technical mechanism behind this attack involved the sequential exploitation of both vulnerabilities. While the specific nature of CVE-2026-15409 and CVE-2026-15410 was not detailed, the chaining of zero-day flaws is a common tactic to bypass multiple security layers. One vulnerability might be used to achieve an initial foothold or information leak, which is then leveraged by the second to escalate privileges or execute arbitrary code. In this instance, the ultimate outcome was arbitrary command execution, a critical capability that allows an attacker to run their own code on the compromised device.
Upon gaining arbitrary command execution, the threat actor proceeded to achieve root access. Root access, or administrative privileges, provides an attacker with complete control over the operating system and its functions. This level of access is highly sought after by adversaries as it allows them to manipulate system configurations, install software, and access sensitive data without restriction.
With root access established, UTA0533 reportedly deployed custom malware. The deployment of custom malware suggests a tailored approach by the attacker, likely designed to evade standard security detections. This malware was then used to establish persistence on the compromised SMA appliances, ensuring continued access even after reboots or attempts to remediate the initial exploit. The ultimate objective of this persistent access and malware deployment was to potentially exfiltrate sensitive data, indicating a data theft or espionage motivation.
SonicWall SMA 1000 series VPN appliances are widely used by organizations to provide secure remote access to internal networks and resources. The exploitation of such devices is particularly concerning because they often serve as a gateway to an organization's critical infrastructure. Successful compromise can therefore lead to broader network intrusions.
Mitigation for this class of vulnerability typically involves applying vendor-supplied patches as soon as they become available. Given that these were zero-day exploits, organizations would have been vulnerable until patches were released. Beyond patching, best practices include implementing robust network segmentation, monitoring VPN appliance logs for anomalous activity, and deploying endpoint detection and response (EDR) solutions on systems accessible via VPN to detect post-exploitation activities. Regularly reviewing and hardening VPN configurations, along with strong authentication mechanisms, also helps reduce the attack surface.
This incident underscores the persistent threat posed by sophisticated actors targeting critical network infrastructure components with previously unknown vulnerabilities. The use of chained zero-days to achieve root access and establish persistence highlights the advanced capabilities of groups like UTA0533 and the continuous need for organizations to maintain a proactive and multi-layered security posture, focusing on rapid patching, continuous monitoring, and incident response capabilities.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed