Repeats a June assault chain
What makes this difficulty particularly important is the timing and the sample, he identified. “That is basically a rerun of what occurred with the identical equipment line simply weeks in the past,” he mentioned, citing the July disclosure of a “almost equivalent” SSRF-plus-command-injection chain in SMA1000 that researchers at Volexity traced to exploitation beginning June 22, weeks earlier than a patch existed.
“That earlier chain was picked up by a risk cluster tracked as UTA0533 after which weaponized at scale by the INC ransomware operation, which has claimed roughly 900 victims globally since,” he famous. In these operations, attackers have been harvesting native credentials, session databases, and TOTP MFA seeds to achieve persistent, hard-to-evict entry earlier than shifting laterally into sufferer networks.
And, Wilkes identified, that hasn’t been the one reported vulnerability; there have been 18 – 22 publicly disclosed CVEs impacting SonicWall merchandise over the previous 12 months, leading to different cybersecurity points which have included ransomware assaults.


