SonicWall warns of active exploitation of two SMA 1000 zero-days

2026-07-15T08:51:47Zbf6eed893518cd34009cfcc0cb4fc0e5aa2ff41ef004f0efe9288ae3c8a8b021
AI-generated malwareCISA KEVCVE-2008-4128CVEsCrashStealerGatekeeper bypassMicrosoft Patch TuesdayNihon KotsuOdidoPowerShellSMA 1000SonicWallVPNcryptordata breachmacOSransomware infrastructuresanctionssupply-chainzero-day

What happened

Multiple high-impact security developments: SonicWall confirmed active exploitation of two zero-days in SMA 1000 appliances (one enables arbitrary command execution). Microsoft released a record July Patch Tuesday with 621 CVEs, including two exploited zero-days and multiple critical fixes. Other notable items: U.S. Treasury sanctioned a VPN provider and a cryptor seller linked to ransomware operations; CISA added Cisco IOS CVE-2008-4128 to its KEV catalog; a new macOS infostealer (CrashStealer) uses signed apps to bypass Gatekeeper; attackers are using AI to generate custom PowerShell AD-reck

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
bf6eed893518cd34009cfcc0cb4fc0e5aa2ff41ef004f0efe9288ae3c8a8b021
Enrichment time
2026-07-15T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.