• Sources: primary, discussion
  • Summary: Hunt.io documents exploitation of SonicWall SMA1000 CVE-2026-15409 that reached DCSync in five Active Directory domains. SonicWall disclosed the flaw on 2026-07-14 with CVSS 10 and active exploitation, scanning began on 2026-07-16 using a refactored Rapid7 proof of concept, Hunt.io detected the council intrusion on 2026-07-17, and this report published on 2026-09-10. Hunt.io describes the chain as server-side request forgery leading to remote code execution in an Erlang component, states the operator ran Impacket secretsdump from the appliance itself, and does not name the affected SMA1000 firmware versions.
  • Why it matters: Running credential extraction from the appliance keeps the activity off the Windows and Linux hosts behind it, which is where most monitoring is placed.

send feedback on this story