- SonicWall SMA1000 vulnerability allowing root access
- SonicWall SMA1000 vulnerability allowing privilege escalation
ThreatNoir Afternoon Brief — August 3
Afternoon Review in IT Security — August 3, 2026
The cybersecurity landscape continues to face escalating threats across multiple critical sectors on August 3, 2026. From ransomware campaigns exploiting known vulnerabilities to state-sponsored actors targeting essential infrastructure, organizations worldwide are grappling with both active exploitation and the urgent need for rapid patching. Today's briefing covers four significant security incidents affecting enterprise appliances, remote management platforms, hospitality networks, and critical water infrastructure.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been actively targeting vulnerable SonicWall SMA1000 appliances to gain root access and facilitate lateral movement within compromised networks. The campaign demonstrates how threat actors continue to weaponize known vulnerabilities for financial gain. Two critical CVEs, CVE-2026-15409 and CVE-2026-15410, are central to this exploitation effort. Source: Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
Organizations relying on SonicWall infrastructure should prioritize immediate vulnerability assessments and patching to prevent unauthorized access. The targeting of remote access appliances represents a particularly dangerous attack vector, as these devices often serve as gateways to sensitive internal systems.
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability affecting N-central, its flagship remote monitoring and management platform, is experiencing active exploitation in the wild. The flaw impacts all currently supported versions of N-central and prompted N-able to release an emergency hotfix on August 1–2. Source: Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
Managed service providers are being urged to apply the hotfix immediately, as the vulnerability poses significant risk to their client environments. The active exploitation of an RMM platform creates a supply-chain risk scenario where a single compromised MSP could affect hundreds of downstream organizations. Rapid deployment of the security update is critical to preventing widespread compromise.
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard, a Russian state-sponsored advanced persistent threat group, has been conducting credential theft operations through compromised Wi-Fi networks at hospitality organizations. The campaign specifically targets Microsoft account credentials from guests and employees connecting to public Wi-Fi gateways. The group has deployed multiple malware tools including ChocoShell, CornFlake RAT, and FruitStone to facilitate these attacks. Source: Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
This campaign highlights the vulnerability of traveling employees and the risks posed by public network infrastructure. Organizations should implement enhanced security controls for remote workers, including mandatory VPN usage and multi-factor authentication, to mitigate the risk of credential compromise through compromised Wi-Fi networks.
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Iran-linked hackers have expanded their targeting of US water infrastructure beyond Minnesota to at least six additional states, including Michigan, South Dakota, and Georgia. The attacks demonstrate a coordinated campaign against critical operational technology systems that support essential services. Source: US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
The geographic scope of this campaign underscores the persistent threat to critical infrastructure from state-sponsored actors. Water utilities and other essential service providers must prioritize the identification and remediation of vulnerable operational technology systems, implement network segmentation between IT and OT environments, and establish robust incident response protocols to detect and contain unauthorized access attempts.
Closing Perspective
Today's threat landscape demonstrates the ongoing exploitation of both known vulnerabilities and emerging attack vectors across enterprise, supply-chain, and critical infrastructure domains. Organizations must balance immediate patching efforts with long-term security architecture improvements to effectively counter these diverse and persistent threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- CornFlake RATGolang-based Windows remote access trojan used by Storm-2945 to target Windows users
- ChocoShellPowerShell-based infostealer implant deployed in CaptiveCrunch campaign
- FruitStoneWeb-based command-and-control panel used to manage CaptiveCrunch infrastructure and agents
- Iran-linked hackersThreat actor targeting US water sector OT systems via cellular-connected equipment