Daily brief at 7am Melbourne. Unsubscribe any time.

Monday 20 July 2026

Someone Was Inside SonicWall VPNs for Weeks Before the Vulnerabilities Were Even Public

SonicWall VPN appliances were silently owned for weeks before anyone knew there was a bug — and the unknown attacker behind it is still being traced.

Lead story

Someone Was Inside SonicWall VPNs for Weeks Before the Vulnerabilities Were Even Public

Zero-days are bad. Zero-days that were actively exploited before the vendor even knew they existed are worse. That's the situation with SonicWall's Secure Mobile Access (SMA) 1000 series — a line of VPN appliances widely used by enterprises to manage remote access — where a previously unknown threat actor was quietly gaining root-level access to devices as far back as 22 June 2026, weeks before SonicWall disclosed the vulnerabilities publicly.

The findings come from Volexity, the incident response firm that first spotted the intrusions. They're tracking the attacker under the temporary label UTA0533 — a naming convention that signals they don't yet have enough evidence to pin the activity to a known group. What they do know is that whoever this is had working exploits for the SMA 1000 series before any public proof-of-concept existed, which means either independent discovery or access to private research. Neither option is particularly comforting.

What the bugs actually do is let an unauthenticated attacker escalate their way to root on the device — the highest level of system access possible. From there, an attacker can intercept VPN traffic, harvest credentials, pivot into the internal network the VPN was supposed to be protecting, and maintain persistent access long after any initial compromise is cleaned up. VPN appliances are a particularly attractive target because they sit at the perimeter, handle authentication for the entire organisation, and are often treated as trusted infrastructure rather than scrutinised as attack surfaces.

SonicWall has since released patches, but the pre-disclosure exploitation window is the key detail here. Organisations that patched promptly after the public advisory may still have been compromised before they knew there was anything to patch. That's what makes this class of incident so damaging — the disclosure timeline itself becomes a gap in the defence.

For Australian organisations, SonicWall SMA appliances are deployed across a range of enterprise and government environments. The ACSC has previously flagged SonicWall products in its advisories, and given the SOCI Act's requirements around critical infrastructure asset protection, any operator running these appliances should treat a retrospective incident review as mandatory rather than optional — not just a patch check.

What to watch: Volexity is likely to release more technical detail as their investigation matures. Attribution is the open question — the zero-day tradecraft and pre-disclosure exploitation suggest a well-resourced actor, possibly state-affiliated, but that's not confirmed. Watch for follow-up advisories from CISA and the ACSC, and check your SMA 1000 logs for activity dating back to late June even if you've already patched. The attacker had a head start. Make sure your forensics do too.

Also today

Russia's Sandworm Is Now Using Fake CAPTCHAs to Make Ukrainians Hack Themselves

A sub-cluster of Russia's Sandworm hacking group — tracked by Ukraine's CERT as UAC-0145 — has been deploying the 'ClickFix' technique against Ukrainian targets. The method is deviously simple: fake CAPTCHA prompts instruct users to run a command on their own machine, which silently installs data-stealing malware. It's social engineering that bypasses most technical defences because the user is the attack vector. Sandworm is GRU's most aggressive cyber unit — responsible for attacks on Ukrainian power infrastructure — so the pivot to credential-theft tooling suggests a focus on intelligence collection alongside disruption.

The Hacker News

Connecting AI Agents to External Services Creates a Much Bigger Attack Surface Than Anyone's Admitting

A detailed analysis from The Register argues that as AI agents gain the ability to call external APIs, browse the web, send emails, and execute code, the security perimeter around any given organisation effectively dissolves. The 'risk radius' — the blast zone if something goes wrong — expands to include every service the agent can touch. Traditional security models were built around users taking actions; agents can take thousands of actions autonomously, often without a human reviewing each one. The piece is a useful read for anyone evaluating agentic AI deployments, which is increasingly every organisation building with AI in 2026.

The Register

Flight Centre Appoints a Chief AI Officer as It Bets Big on Agentic Travel

Australian travel giant Flight Centre has appointed a Chief AI Officer and is restructuring its ecommerce operations around AI agents — systems that can autonomously research, book, and manage travel itineraries on a customer's behalf. The company is consolidating its online brands as part of the shift. It's a meaningful signal from a major Australian consumer business: rather than bolting AI onto existing products, Flight Centre is treating it as a structural redesign of how travel commerce works. Whether that pays off depends heavily on how well the agents handle edge cases — which is where every agentic deployment eventually gets tested.

iTnews

AWS Sent Customers Bills That Were Astronomically Wrong — Then Had to Explain Itself

A bug in AWS's billing estimate engine caused customers to receive projected cost notifications that bore no resemblance to reality — in some cases orders of magnitude higher than actual usage. The issue appears to have been a display error in the estimation logic rather than actual charges, but that distinction didn't stop the panic. Cloud billing is already one of the leading sources of financial risk for engineering teams, and a false alarm at this scale erodes trust in the guardrails meant to prevent real runaway costs. AWS has since acknowledged the issue and is working on corrections. Australian AWS customers were among those affected.

iTnews

Apple Is Suing OpenAI. Could It Actually Derail the io Hardware Plans?

Apple has filed suit against OpenAI in a dispute that cuts right to the heart of OpenAI's next act: a line of dedicated AI hardware devices developed in partnership with Jony Ive's design firm io. The lawsuit's specifics aren't fully public, but the core concern appears to be around design and trade secret claims related to the hardware development process. OpenAI is also pushing toward an IPO, and litigation from one of the world's most litigious and cash-rich companies is exactly the kind of overhang that complicates that timeline. TechCrunch's Equity podcast breaks down the scenarios — from nuisance suit to genuine obstacle.

TechCrunch

Christopher Nolan on AI: 'Everybody Knows the Greeks Are Inside'

Promoting his new film Odyssey, director Christopher Nolan offered one of the more memorable AI takes of the year — calling it an 'obvious Trojan horse.' He's not wrong that the framing of AI as a productivity tool obscures harder questions about power and control, though he stopped short of a detailed argument. What makes the quote worth noting isn't the novelty of the critique — it's the source. Nolan is one of Hollywood's most commercially successful directors, a group that has so far been conspicuously quiet about an industry that is actively trying to replace large parts of their workforce. That may be starting to change.

TechCrunch

Current AI Wants to Build a Universal, Open AI Layer — Like the Web, But for Agents

Current AI, a nonprofit, is working on what it describes as the 'World Wide Web of AI': an open, interoperable infrastructure layer that allows AI agents and models to communicate across platforms regardless of who built them. The pitch is that today's AI ecosystem is fracturing into walled gardens — OpenAI's agents don't talk to Google's, which don't talk to Anthropic's — and that without an open standard, the benefits of AI will concentrate among whoever controls the dominant platform. Current AI's approach draws on open-web principles. Whether it gains traction depends on whether major players have any incentive to let it.

TechCrunch

Local Governments Want a Seat at the Table on Australia's Data Centre Expansion

The Australian Local Government Association (ALGA) has flagged a significant gap in the federal government's data centre strategy: local councils — who approve planning permits, manage water and power connections, and absorb the amenity impacts of large industrial facilities — have been left out of the consultation process entirely. Data centres are land-hungry, power-hungry, and water-hungry infrastructure. Siting them well requires exactly the kind of local knowledge that councils hold. ALGA is pushing for formal inclusion in the planning framework before the government locks in locations and contracts. Given the scale of investment the federal strategy envisions, this is a legitimate governance concern.

The Mandarin

The Robotaxi Rulebook Is Being Rewritten — and Nobody Agrees on the Author

TechCrunch Mobility's latest edition maps the accelerating conflict over who gets to regulate autonomous vehicles in the United States — federal agencies, state governments, or city councils — as Waymo expands its footprint and new entrants line up to compete. The core tension is that robotaxi operators want a single national framework to avoid a patchwork of fifty different rules, while states argue they've always regulated road safety and aren't giving that up. The stakes are high: whoever writes the rules effectively determines who can afford to operate at scale. Australia's own AV policy framework remains nascent, and the US outcome will likely influence it heavily.

TechCrunch

Claude Code Quietly Swapped Its JavaScript Runtime for Bun — Built in Rust

Anthropic's agentic coding tool Claude Code has migrated its underlying runtime from Node.js to Bun, a JavaScript runtime written in Rust that prioritises startup speed and lower memory overhead. Simon Willison flagged the change, which is the kind of infrastructure detail that won't make headlines but matters to developers who are running Claude Code in tight loops or resource-constrained environments. Bun has been steadily eating into Node's dominance in developer tooling, and Anthropic's adoption is a meaningful endorsement. It also reflects the broader trend of AI tooling being engineered for performance at the margins as inference costs and latency become competitive differentiators.

Simon Willison

GTA VI Is Disc-Free. The Physical Game Is Almost Dead.

Rockstar Games has confirmed that Grand Theft Auto VI will not be released on physical disc — a significant milestone given the franchise's historic sales volumes. Jay Peters at The Verge argues this is less a one-off decision and more a threshold moment: if GTA can skip physical media, any game can. The implications run downstream to retailers, collectors, game preservation archives, and players in regions with poor broadband who rely on physical copies. Australia has patchy rural internet coverage and a retail games market that has already contracted sharply — disc-free AAA releases will hit regional players hardest.

The Verge

Sources consulted