decrypted · 11 august 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

The SonicWall VPN flaw where patching wasn't the fix

SonicWall's SMA1000 remote access appliances have gone from zero-day to ransomware launchpad in under two months, and the vendor's own advisory tells you most of what you need to know about the underlying design problem: patching the hole doesn't undo what already walked out through it. CISA and multiple researchers reported this week that the INC ransomware group has become the dominant actor exploiting the pair of flaws, with victims still being listed on its leak site. For any UK organisation using SMA1000 boxes as its remote access gateway, this is a live incident, not a history lesson.

The flaw, in plain English

The first bug, CVE-2026-15409, is a maximum-severity (CVSS 10.0) server-side request forgery flaw in the appliance's Workplace interface. Think of it as a receptionist who, without checking anyone's identity, will place a call anywhere a visitor asks, including internal extensions the public was never meant to reach. Chained with CVE-2026-15410, a second flaw that lets an authenticated admin run arbitrary operating system commands, that misplaced trust becomes a route to full remote code execution on the box that is meant to be guarding the network's front door. SonicWall patched both on 14 July. Researchers have since traced exploitation back to 22 June, meaning attackers had free run of the flaw for three weeks before a fix existed.

Why patching wasn't the end of it

Here is the part worth reading twice. SonicWall's own advisory says plainly that "patching alone is not sufficient", because attackers who got in before the fix could harvest credentials, active session databases and the seed values behind time-based MFA tokens. A patch closes the door; it does not revoke keys that were copied while the door was open. SonicWall's actual remediation advice is to re-image affected hardware, redeploy virtual appliances from scratch, change every password and reset every MFA token, regardless of whether an organisation sees signs of compromise. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue in mid-July with a three-day remediation deadline for federal agencies. Since the start of August, researchers at Resecurity say INC ransomware has accelerated its use of the full exploit chain, deploying a toolkit that includes a Python dropper called KNUCKLEBALL and a Java web shell to take over unpatched boxes. No UK victims have been named publicly yet, but SMA1000 devices are a common remote access choice, and that silence is not the same as safety.

This is the same shape of failure that has shown up repeatedly on edge devices this year: a single flaw on an internet-facing box compromises the authentication apparatus behind it, not just the box itself. The Secure by Design lesson is specific and actionable. When evaluating any remote access product, ask the vendor whether session tokens and MFA seeds are stored in a way that a patch alone invalidates them, or whether, as here, a genuine compromise requires a full credential and token reset regardless of patch status. And treat "patch applied" as the start of an incident response, not the end of one.

Also this week

North Korea's Kimsuky group has built an offline AI stack for phishing and malware development, according to South Korean firm Genians, combining local language models, a document-retrieval database and coding tools so it no longer needs public AI services that might log or flag its activity. The tools have not yet been seen against live targets, but the intent is clear: the old tells of a phishing email, poor translation and clumsy formatting, become less reliable once AI is doing the writing. Genians recommends defenders correlate behaviour instead, such as script execution and unusual network traffic, rather than judging a lure by how polished it looks.

A WordPress plugin vendor, BdThemes, had its infrastructure compromised to poison a JSON feed used by its Element Pack, Prime Slider and other add-ons, silently creating hidden administrator accounts on sites running them. WordPress pulled all BdThemes plugins from its directory on 8 August pending investigation. Element Pack alone lists over 100,000 active installs, a reminder that a small plugin vendor's build pipeline can be as consequential as a large one's.

The Police National Legal Database, managed by West Yorkshire Police on behalf of all 43 forces in England and Wales, confirmed that a 26 July intrusion led to roughly 135,000 records of names, organisations and work email addresses appearing on the dark web, claimed by the same ExfilSquad group behind last week's Department for Education breach. PNLD says there is no evidence passwords or credentials were taken, but as one researcher noted, a verified name, role and official email address is enough on its own to build a convincing spear-phishing lure against police and justice staff.

Sources

If your organisation runs internet-facing remote access appliances and wants a second opinion on exposure, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.