Lead story
Someone Was Inside SonicWall VPNs for Weeks Before the Vulnerabilities Were Even Public
Zero-days are bad. Zero-days that were actively exploited before the vendor even knew they existed are worse. That's the situation with SonicWall's Secure Mobile Access (SMA) 1000 series — a line of VPN appliances widely used by enterprises to manage remote access — where a previously unknown threat actor was quietly gaining root-level access to devices as far back as 22 June 2026, weeks before SonicWall disclosed the vulnerabilities publicly.
The findings come from Volexity, the incident response firm that first spotted the intrusions. They're tracking the attacker under the temporary label UTA0533 — a naming convention that signals they don't yet have enough evidence to pin the activity to a known group. What they do know is that whoever this is had working exploits for the SMA 1000 series before any public proof-of-concept existed, which means either independent discovery or access to private research. Neither option is particularly comforting.
What the bugs actually do is let an unauthenticated attacker escalate their way to root on the device — the highest level of system access possible. From there, an attacker can intercept VPN traffic, harvest credentials, pivot into the internal network the VPN was supposed to be protecting, and maintain persistent access long after any initial compromise is cleaned up. VPN appliances are a particularly attractive target because they sit at the perimeter, handle authentication for the entire organisation, and are often treated as trusted infrastructure rather than scrutinised as attack surfaces.
SonicWall has since released patches, but the pre-disclosure exploitation window is the key detail here. Organisations that patched promptly after the public advisory may still have been compromised before they knew there was anything to patch. That's what makes this class of incident so damaging — the disclosure timeline itself becomes a gap in the defence.
For Australian organisations, SonicWall SMA appliances are deployed across a range of enterprise and government environments. The ACSC has previously flagged SonicWall products in its advisories, and given the SOCI Act's requirements around critical infrastructure asset protection, any operator running these appliances should treat a retrospective incident review as mandatory rather than optional — not just a patch check.
What to watch: Volexity is likely to release more technical detail as their investigation matures. Attribution is the open question — the zero-day tradecraft and pre-disclosure exploitation suggest a well-resourced actor, possibly state-affiliated, but that's not confirmed. Watch for follow-up advisories from CISA and the ACSC, and check your SMA 1000 logs for activity dating back to late June even if you've already patched. The attacker had a head start. Make sure your forensics do too.
