incident response2 articles
Unknown Threat Actor Chained SonicWall Zero-Days to Root Before Anyone Knew They Existed
A previously unknown threat actor (UTA0533) exploited two zero-day vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — in SonicWall SMA 1000 series VPN appliances before patches were publicly released, chaining them together to achieve root-level access on compromised devices. The attacker deployed custom malware, including a web shell and HTTP proxy tool, modified startup scripts for persistence, and used packet capture utilities to steal LDAP credentials. While UTA0533 demonstrated advanced capability in compromising the appliances, evidence suggests they had limited success in moving laterally to other systems on the network.
Why Cyber Resilience Has Swallowed Business Continuity Planning
Modern business disruption increasingly originates from cyber threats such as ransomware, identity compromises, and supplier or cloud failures, making cyber resilience the new foundation of business continuity planning. Effective continuity requires organisations to map critical processes and dependencies, integrate governance, incident response, and supplier management into a unified framework, and ensure systems can recover within agreed timeframes. Crucially, continuity plans must be regularly tested against realistic scenarios to verify they hold up under real pressure, not just on paper.