SonicWall warns of active exploitation of two SMA 1000 zero-days
2026-07-15T08:51:47Z•bf6eed893518cd34009cfcc0cb4fc0e5aa2ff41ef004f0efe9288ae3c8a8b021
AI-generated malwareCISA KEVCVE-2008-4128CVEsCrashStealerGatekeeper bypassMicrosoft Patch TuesdayNihon KotsuOdidoPowerShellSMA 1000SonicWallVPNcryptordata breachmacOSransomware infrastructuresanctionssupply-chainzero-day
What happened
Multiple high-impact security developments: SonicWall confirmed active exploitation of two zero-days in SMA 1000 appliances (one enables arbitrary command execution). Microsoft released a record July Patch Tuesday with 621 CVEs, including two exploited zero-days and multiple critical fixes. Other notable items: U.S. Treasury sanctioned a VPN provider and a cryptor seller linked to ransomware operations; CISA added Cisco IOS CVE-2008-4128 to its KEV catalog; a new macOS infostealer (CrashStealer) uses signed apps to bypass Gatekeeper; attackers are using AI to generate custom PowerShell AD-reck
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- bf6eed893518cd34009cfcc0cb4fc0e5aa2ff41ef004f0efe9288ae3c8a8b021
- Enrichment time
- 2026-07-15T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.