SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk

SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk

•

Episode description

SonicWall Zero-Days, Teams Vishing Campaign, and Third-Party Identity Risk

On 2 September 2026, SonicWall disclosed two vulnerabilities in the SMA1000 remote access appliance series being actively chained together for remote code execution at the time of public disclosure. This episode provides immediate guidance for organisations running SonicWall perimeter devices, including patch verification and compromise auditing procedures. The briefing examines the Spring Ring campaign, a sustained Microsoft Teams vishing operation documented by Unit 42 that successfully targeted over 150 employees across ten companies between January and April 2026, using impersonated IT helpdesk calls to deploy remote monitoring tools and credential theft techniques including PetitPotam. Coverage includes Dropbox account compromises resulting from a Lenovo email verification flaw, illustrating third-party identity risk in business service authentication. Additional notes cover the multi-agency Sality botnet takedown after 23 years of operation, and emerging UK cyber legislation placing regulatory responsibility for AI deployment risk on end-user organisations rather than vendors.

Chapters

  • Introduction Overview of three critical threat developments requiring immediate action, particularly a SonicWall zero-day exploitation event disclosed whilst under active attack.
  • SonicWall SMA1000: Two Chained Zero-Days Under Active Exploitation Detailed analysis of actively exploited server-side request forgery and command injection vulnerabilities in SonicWall SMA1000 remote access appliances, with specific guidance on patch verification and compromise auditing for affected organisations.
  • Call to Action Listener engagement prompt encouraging subscription and peer sharing of threat intelligence briefings.
  • Microsoft Teams Vishing: Spring Ring Targeted 150+ Employees Across 10 Companies Comprehensive examination of the Spring Ring social engineering campaign using Microsoft Teams voice calls to impersonate IT helpdesk staff, including technical details of PetitPotam credential theft and practical staff briefing guidance.
  • Dropbox Accounts Breached via Lenovo Email Verification Flaw Case study in third-party identity risk, covering Dropbox account compromises resulting from a vulnerability in Lenovo’s email verification process, with recommendations for identity provider auditing and multi-factor authentication.
  • In Brief: The Sality Botnet Is Down Multi-agency disruption of the Sality botnet after 23 years of operation, including context on infected system remediation.
  • A Note on the UK Cyber Bill Policy development update on UK cyber legislation framing regulatory responsibility for AI deployment risk on end users rather than vendors.
  • Closing Summary of priority actions and episode conclusion.

Links