decrypted · 17 july 2026 · vulnerabilities and patching · ai and llm security · digital sovereignty
Two SonicWall flaws became one breach, and the cloud giants come under new watch
SonicWall's SMA1000 remote access gateways are meant to be the locked front door to a corporate network. This week two flaws in that gateway, chained together by attackers since late June, turned the door itself into the way in. The deadline for US federal agencies to patch or disconnect their SMA1000 boxes lands today, 17 July, but the lesson doesn't expire with it: a gateway that mixes an unauthenticated public interface with a privileged admin console on the same box is one bug away from being fully owned.
The chain: two flaws, one appliance
CVE-2026-15409 is a server-side request forgery flaw in the SMA1000's Workplace interface, reachable by anyone on the internet. It scores the maximum 10.0 on the CVSS scale because it lets an attacker force the appliance to make requests to places it should never reach, including its own internal Appliance Management Console. CVE-2026-15410 lives in that console: a post-authentication code injection bug that turns an administrator session into arbitrary operating system commands. Neither flaw alone is a full breach. Fed through the SSRF, an attacker no longer needs a password to reach the console that the second flaw turns into remote code execution.
Researchers at Rapid7 and Volexity, credited alongside SonicWall's own product security team, found the chain being used to harvest credentials and MFA seed material, then move laterally inside victim networks using direct, machine-level access that leaves no corresponding VPN tunnel in the logs, exactly where a defender would look first. SonicWall has shipped hotfixes, 12.4.3-03453 and 12.5.0-02835, for the affected 6210, 7210 and 8200v models, and CISA added both CVEs to its Known Exploited Vulnerabilities catalogue on 14 July.
The Secure by Design lesson
The design flaw isn't really the SSRF or the code injection on their own; both are common bug classes. It's the architecture that put an unauthenticated public interface and a privileged management console within reach of each other on the same box. A remote access gateway's job is to be the segmentation boundary between the open internet and everything sensitive behind it. When the management plane is reachable, even indirectly, from the surface the public touches, the appliance has quietly become both lock and key. UK organisations running SMA1000, or evaluating any remote access product, should ask vendors whether the admin interface is reachable from the internet-facing service, not just whether it sits behind a password. Segmentation by network path, not by login screen, is what stops one bug becoming two.
Also this week
The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority began formally overseeing Amazon Web Services, Google Cloud, Microsoft and Oracle as Critical Third Parties on 13 July, following designation by HM Treasury under the Financial Services and Markets Act 2023. The regime doesn't set data residency rules and isn't approval of the providers' security. What it does is give regulators power to inspect, commission independent reviews of, and direct fixes at the infrastructure that most of the UK's banks, insurers and payment firms now depend on simultaneously. It's a tacit admission that resilience planning across the sector had, for years, treated four American cloud providers as background rather than the shared points of failure they've become. Boards outside financial services should read it as a preview: the same argument about concentrated dependency applies wherever a sector has settled on the same three or four clouds.
Researchers at Manifold Security disclosed, and this month reconfirmed, that Anthropic's Claude for Chrome extension will trigger its own predefined actions, including reading Gmail, Google Docs and Calendar, if any other extension in the same browser fakes a mouse click. The flaw is mundane: the code never checks whether a click genuinely came from the user, so a handful of script lines from an unrelated extension can pull the trigger. A second issue lets the side panel be silently switched into a mode that skips permission checks altogether. Anthropic closed both reports, arguing the issue was already tracked elsewhere, and the bugs were still reproducible as of 7 July across eight subsequent releases. Treat this as a live example of why giving an AI agent access to your inbox is a permission decision, not a feature toggle.
Symantec's threat hunters documented a new ransomware family, Spirals, taking an IT services company from an exposed, internet-facing web server to full network encryption in under 24 hours, disabling Windows Defender and 23 backup, database and virtualisation services along the way before dropping a ransom note giving six days before stolen data went public. Only one victim has been seen so far, so it isn't yet clear whether Spirals is a one-off tool or a new commodity strain. What's consistent with every other ransomware run this year is the compressed timeline: detection measured in hours, not days, is now the design requirement for incident response, not an aspiration.
Sources
- SonicWall PSIRT Security Advisory SNWLID-2026-0008
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now - BleepingComputer
- UK financial regulators to begin overseeing Critical Third Parties announced by HMT - Bank of England
- Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads - The Hacker News
- ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail - Manifold Security
- New Spirals ransomware encrypts victim network in under 24 hours - BleepingComputer
If you'd like to talk through what any of this means for your own systems, get in touch.
More like this
- A mislabelled maintenance job, and the outage it exported to Britain 27 july 2026
- The Zimbra bug that needed no click, and the year it went unpatched 24 july 2026
- The National Risk Register grows seven cyber scenarios, one borrowed from CrowdStrike 16 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.