vpn

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.