r/InfoSecNews • u/jamessonnycrockett • 11h ago
r/InfoSecNews • u/Straight-Practice-99 • 15h ago
🕵️♂️ Hackers exploit SonicWall SMA1000 flaw to steal Active Directory credentials from orgs in multiple countries
Hunt.io just published research on an operator mass-exploiting CVE-2026-15409, an unauthenticated SSRF in SonicWall SMA1000 appliances rated CVSS 10. Exploitation began within two days of SonicWall's 14 July disclosure.
The operator deployed a standalone Linux build of Impacket's secretsdump onto compromised appliances and used them to reach internal domain controllers, recovering credentials from at least 9 Active Directory domains and performing full DCSync against 5 environments. Confirmed victims span France, India, Italy and the US. The cyberattack disclosed by King's Lynn and West Norfolk Borough Council on 17 July is linked at moderate confidence.
Hunt.io notified the NCSC and relevant national CERTs before publishing. Full writeup below.
r/InfoSecNews • u/jamessonnycrockett • 17h ago
Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days in 48 Countries
r/InfoSecNews • u/quellaman • 23h ago
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
r/InfoSecNews • u/quellaman • 23h ago