Cybersecurity Daily: News & Threats
(00:00:00) Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes (00:01:04) INC Ransomware Weaponizes SonicWall (00:01:33) Microsoft's 570-Fix Patch Tuesday (00:02:41) Craneware Healthcare Breach (00:03:20) Paidwork Data Exposure and 7-Zip Patch (00:03:56) What to Watch Next Pre-disclosure exploitation is no longer an edge case — it's a playbook. In this episode, we break down how threat actor UTA0533 chained two SonicWall zero-days, CVE-2026-15409 and CVE-2026-15410, against SMA 1000 series appliances to achieve root access via a WebSocket authentication bypass, CouchDB pivot, and privilege escalation — deploying custom web shell ORANGETAIL before any patch or advisory existed. INC Ransomware then weaponised the same chain, marking a significant shift: zero-days once reserved for nation-state actors are now being handed off to ransomware groups at scale. Microsoft's July Patch Tuesday delivered a record 570 fixes — a 316% year-over-year increase in vulnerability discovery driven by the company's AI-powered MDASH system. Two of those fixes cover zero-days already under active exploitation: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server. Dell systems face an additional complication: a hardware compatibility block means they cannot yet receive the update. In healthcare, the Craneware breach exposed customer, employee, and partner data across thousands of US hospitals and pharmacies that rely on its billing software — a textbook supply chain attack delivering leverage across an entire fragmented ecosystem. Also covered: 23.3 million Paidwork user records — including bank account details and bcrypt-hashed passwords — surfaced on cybercrime forums following a March intrusion, and a quietly patched heap overflow in 7-Zip's XZ archive handler is now public knowledge, narrowing the exploitation window fast. A YesWee production. Built using AI technology. This episode includes AI-generated content.
73 episoder
Kommentarer
0Vær den første til at kommentere
Tilmeld dig nu og bliv en del af Cybersecurity Daily: News & Threats-fællesskabet!