AI-generated content
Transcribed

Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes

Jul 21, 2026 · 5m 24s
Root Access Before the Patch: SonicWall, INC Ransomware & 570 Microsoft Fixes
Chapters

01 · INC Ransomware Weaponizes SonicWall

1m 4s

02 · Microsoft's 570-Fix Patch Tuesday

1m 33s

03 · Craneware Healthcare Breach

2m 41s

04 · Paidwork Data Exposure and 7-Zip Patch

3m 20s

05 · What to Watch Next

3m 56s

Description

Pre-disclosure exploitation is no longer an edge case — it's a playbook. In this episode, we break down how threat actor UTA0533 chained two SonicWall zero-days, CVE-2026-15409 and CVE-2026-15410, against...

show more
Pre-disclosure exploitation is no longer an edge case — it's a playbook. In this episode, we break down how threat actor UTA0533 chained two SonicWall zero-days, CVE-2026-15409 and CVE-2026-15410, against SMA 1000 series appliances to achieve root access via a WebSocket authentication bypass, CouchDB pivot, and privilege escalation — deploying custom web shell ORANGETAIL before any patch or advisory existed. INC Ransomware then weaponised the same chain, marking a significant shift: zero-days once reserved for nation-state actors are now being handed off to ransomware groups at scale.

Microsoft's July Patch Tuesday delivered a record 570 fixes — a 316% year-over-year increase in vulnerability discovery driven by the company's AI-powered MDASH system. Two of those fixes cover zero-days already under active exploitation: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server. Dell systems face an additional complication: a hardware compatibility block means they cannot yet receive the update.

In healthcare, the Craneware breach exposed customer, employee, and partner data across thousands of US hospitals and pharmacies that rely on its billing software — a textbook supply chain attack delivering leverage across an entire fragmented ecosystem.

Also covered: 23.3 million Paidwork user records — including bank account details and bcrypt-hashed passwords — surfaced on cybercrime forums following a March intrusion, and a quietly patched heap overflow in 7-Zip's XZ archive handler is now public knowledge, narrowing the exploitation window fast.

A YesWee production. Built using AI technology.

This episode includes AI-generated content.
show less
Information
Author Yes Oui
Organization YesOui
Website -
Tags

Looks like you don't have any active episode

Browse Spreaker Catalogue to discover great new content

Current

Podcast Cover

Looks like you don't have any episodes in your queue

Browse Spreaker Catalogue to discover great new content

Next Up

Episode Cover Episode Cover

It's so quiet here...

Time to discover new episodes!

Discover
Your Library
Search