Author: Craig Taylor
I got started nearly 35 years ago in Cybersecurity working for a firewall company. Back then the WWW did not exist, email was a text based tool that was opening communications like never before. My psychology degree didn’t help me much initially, but those O’Reilly books – well they became my bible. TCP/IP, DNS & Bind, SMTP, does anyone reading this remember passive FTP?
Back to firewalls, we spent too much time convincing companies connecting their internal networks (Token Ring, IPX/SPX, Vines, NetBeui, Appletalk) to the Internet. Firewalls were split into two camps – Proxy-based and Stateful Inspection (Checkpoint). They were the major security perimeter protecting most companies pre and post-WWW. When a firewall had a security issue, the highest priority in anyone’s world was patching or mitigating that risk.
With Frontier Models systematically testing software, including firewalls, with more capabilities than any human ever had, it’s no wonder we’re seeing a spate of vulnerability announcements and patches like never before witnessed in history! Across the major vendors, in the past 6 months, we’ve seen not a doubling or tripling of patches, but 10x to 25x more patches than ever before!
That’s the context with which I write about two recent zero-days found in SonicWall’s firewall. They are not the only Firewall vendor to have zero-days, rather, they are emblematic of a recent explosion in Frontier AI penetration testing and vulnerability identification. This is the early waves of a storm that’s coming. The storm could be a category 5 hurricane leading to more breaches than we’ve seen in recent history. According to this Five Eyes advisory, we have months to prepare, not years.
My advice to all of you? Get busy with an AI readiness assessment. Focus on these 6 things:
The article below covers a single vendor, but this will apply to every vendor you use. Their bug bounty programs are paused because they cannot keep up with submissions. Their developers are overwhelmed with bug fixes to be tested and deployed. Things are heating up and it’s all hands on deck… the time to prepare and batten down the hatches is now. Don’t wait until it’s too late.
Security AI researchers found two vulnerabilities in SonicWall firewalls, tracked as CVE-2026-15409 and CVE-2026-15410. Attackers exploited both flaws for about three weeks before SonicWall released a patch on July 14. During those three weeks, hackers chained the two vulnerabilities together to gain full access to affected devices, steal data, and lock networks down with ransomware.
A ransomware group named INC emerged as the most active attacker exploiting these flaws after the patch came out. INC has run a ransomware-for-hire business since 2023 and has claimed close to 900 victims across 71 countries. Security firm Rapid7 tracked the group’s activity and found INC moved from breaking in to deploying ransomware faster than earlier attackers who tested the same vulnerabilities before the public disclosure.
Rapid7 said it stopped data theft and encryption in most recent cases it responded to, though ransomware was deployed successfully in at least one incident. Another firm, Resecurity, found INC listed new victims from Australia, the United States, the United Arab Emirates, Colombia, and Switzerland on its dark web leak site. Some victims received calls and emails from people pressuring them to pay.
This is not the first security issue tied to SonicWall devices. Ten of the seventeen SonicWall vulnerabilities added to the federal government’s Known Exploited Vulnerabilities list since 2021 tie back to ransomware campaigns. Last week alone, researchers spotted an attack spree that hit 30 SonicWall customers in two days using stolen login credentials.
If your business runs a SonicWall firewall, or any internet-facing security device, this pattern applies to you too. Attackers target popular, widely deployed hardware because one working exploit affects thousands of organizations using the same equipment.
None of these steps require a big budget or a dedicated security team. A few focused hours protect your business from becoming the next name on a leak site.
Firewalls sometimes fail and when they do, it can be a big deal. Vendors patch more quickly today than ever before. Attackers adapt and attack more quickly too. Just when we didn’t think things could speed up any more, they do. Enabling daily firmware updates may sound risky, but the question to ask is this: Is a rare outage from a failed firmware install better than a breach?
Set aside an hour today to review your firewall’s setup. Enable automated windows for firmware updates (daily if possible). Close unneeded ports, confirm MFA on all remote access solutions, reduce data on your internal network, and deploy a honeypot.
Forward this article to whoever handles IT at your company, even if that person is you. A few proactive measures today will provide you peace of mind, a better chance against the attack speeds we see today, and some defensible proactive measures you can share with senior leadership in the face of growing concerns around AI frontier model attacks. Oh, and always remember to Hoot Up!
What Sonicwall Vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were announced recently? They are two zero-day vulnerabilities affecting SonicWall firewalls that were exploited in the wild for about three weeks before SonicWall disclosed and patched them on July 14, 2026. Attackers have been chaining the two flaws together to gain full access to affected devices.
Who is behind the attacks? Multiple actors probed the flaws before they were publicly disclosed, but INC ransomware, a ransomware-as-a-service group active since 2023, has become the most prominent and effective attacker exploiting the vulnerability chain since disclosure.
How many organizations have been affected? The exact number is unknown. Rapid7 has responded to several incidents and prevented data theft or encryption in most of them, but researchers say the full scope likely extends well beyond what any single security vendor can see. INC has listed new victims spanning several countries on its leak site.
Is this the first time SonicWall has faced this kind of issue? No. SonicWall has dealt with a string of security problems in recent years, including other actively exploited zero-days, a mass credential-based attack spree that hit 30 customers in two days, and a prior incident in which attackers stole firewall configuration files from every SonicWall customer.
What should SonicWall customers do now? Apply the available patches immediately, review logs for suspicious activity going back to late June, rotate any credentials associated with affected devices, and closely monitor internet-facing SonicWall appliances for unusual behavior.
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Author: Craig Taylor I got started nearly 35 years ago in Cybersecurity working for a firewall company. Back...
Read more
AI tools moved into our everyday work-life incredibly fast! Someone on your team writes an email with ChatGPT....
Read more
You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
