Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the SonicWall Vulnerability Exploitation Campaign: A Case Study of Mass Exploitation and Operation Secrecy



A critical SonicWall flaw, CVE-2026-15409, was rapidly weaponized to carry out a mass exploitation campaign, exposing credentials and enabling Active Directory theft. The attack, which took place on July 17, 2026, was linked to a wider campaign that targeted organizations across the globe, including those in the UK, Canada, Germany, and the United States. The vulnerability was discovered by Rapid7 researchers on July 15, 2026, and was operationalized quickly by the threat actor. The attack highlights the importance of maintaining up-to-date firmware and patching vulnerabilities as soon as they are discovered.

  • The recent cyberattack on the Borough Council of King’s Lynn and West Norfolk revealed a critical SonicWall flaw, CVE-2026-15409, which was rapidly weaponized.
  • The vulnerability, affecting the WorkPlace portal’s WebSocket proxy, was first discovered by Rapid7 researchers on July 15, 2026.
  • The attack was carried out by a threat actor who deployed a standalone Linux build of Impacket's secretsdump onto selected SonicWall appliances, enabling remote credential theft.
  • The attack highlights the importance of maintaining up-to-date firmware, patching vulnerabilities, and improving operational security.
  • The incident demonstrates the need for organizations to stay informed with the latest security patches and best practices to prevent similar attacks.



  • The recent cyberattack on the Borough Council of King’s Lynn and West Norfolk has shed light on a critical SonicWall flaw, CVE-2026-15409, which was rapidly weaponized to carry out a mass exploitation campaign. The attack, which took place on July 17, 2026, was linked to a wider campaign that exposed credentials and enabled Active Directory theft.

    The vulnerability, which affects the WorkPlace portal’s WebSocket proxy, was first discovered by Rapid7 researchers on July 15, 2026. The researchers published a proof-of-concept on the same day, which was adapted into a 50-thread mass scanner by July 16. The SonicWall advisory was issued on July 14, 2026, but the gap between zero-day exploitation and mass-scale automated campaigns was effectively less than three days.

    The attack was carried out by a threat actor who deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems. The attacker used a hardcoded cookie found in the appliance firmware to complete the Erlang connection and access the email address node. From there, they could send commands that executed operating system commands with the privileges of the couchdb account.

    The attack was technically capable, but the operational security was lacking. The attacker ran their entire post-exploitation framework from an open HTTP server on port 80 without authentication. The exploitation was operationalized quickly, with the threat actor using modified, multithreaded tooling to identify vulnerable SMA 1000 appliances, extract and decrypt LDAP credentials, and automate follow-on credential theft against internal Active Directory environments.

    The retained evidence shows how quickly public vulnerability research can be operationalized. The attack highlights the importance of maintaining up-to-date firmware and patching vulnerabilities as soon as they are discovered. The SonicWall recommendation is to re-image affected appliances, rotate all user and administrator credentials, and reset TOTP tokens.

    The attack also demonstrates the importance of operational security and the need for organizations to have more visibility into the underlying operating systems of security appliances than they have through EDR on managed Windows and Linux hosts.

    In conclusion, the SonicWall vulnerability exploitation campaign highlights the importance of cybersecurity awareness and the need for organizations to stay up-to-date with the latest security patches and best practices. The attack also shows how quickly public vulnerability research can be operationalized, and the importance of operational security in preventing such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-SonicWall-Vulnerability-Exploitation-Campaign-A-Case-Study-of-Mass-Exploitation-and-Operation-Secrecy-ehn.shtml

  • https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-15409

  • https://www.cvedetails.com/cve/CVE-2026-15409/


  • Published: Fri Sep 11 03:44:06 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us