1. Two SonicWall SMA 1000 zero-days were exploited for root access before any patch existed. If you run these appliances, patching alone does not evict an actor who already has root.
2. Accenture has confirmed an intrusion. The 35GB source-code-and-keys figure is the attacker's claim, not verified fact. Treat any secrets Accenture holds for you as potentially exposed.
3. This briefing exists to give 100 percent practical value to CISOs and CISO teams. No speculation, no vendor pitch.
Below are the most significant confirmed developments in the current reporting cycle, each with two independent sources we verified by hand. Where a detail is a threat actor's claim or is still under investigation, it is labeled as such. Reporting dates are shown so you can judge recency yourself.
SonicWall SMA 1000 zero-days exploited for root access [Confirmed]
Reported July 19, 2026. Vendor disclosure July 14, 2026.
Key facts. Affected: SonicWall SMA 1000 series (models 6210, 7210, 8200v). Vulnerabilities: CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (post-authentication command injection, CVSS 7.2). Impact: chained for arbitrary command execution and full appliance takeover, with root access. Actor: previously undocumented, tracked by Volexity as UTA0533. Earliest activity: June 22, 2026. Fixed in appliance versions 12.4.3-03453 and 12.5.0-02835.
What happened. Volexity investigated an intrusion in early July 2026 and found a threat actor had compromised SonicWall SMA 1000 series VPN appliances by chaining multiple zero-day exploits. The chain uses a pre-authentication request bypass (CVE-2026-15409) to reach localhost-only services, then a path-traversal command injection (CVE-2026-15410) to execute commands as root. SonicWall disclosed the flaws publicly on July 14, 2026, and shipped fixes in the versions listed above.
Evidence. After gaining root, the actor deployed a privilege-escalation binary Volexity calls ROOTRUN and a Python dropper called KNUCKLEBALL, which injected two payloads into a legitimate appliance process: the open-source proxy Suo5 and a custom web shell Volexity calls ORANGETAIL. On a second appliance, the actor ran tcpdump to capture unencrypted LDAP traffic and harvest credentials. The earliest sign of compromise was June 22, 2026, well before public disclosure.
What this means for your team. Internet-facing VPN appliances remain a primary entry point, and this actor had root before a patch existed. If you operate SMA 1000 series devices, confirm you are on a fixed version, rotate every credential the appliance handled including LDAP, and hunt for compromise back to late June rather than assuming a patch closed the door.
Attribution note: some secondary outlets have floated a nation-state link for UTA0533. Volexity's own analysis does not establish attribution. Brief on what is confirmed, not what is speculated.
Sources (2, verified): Volexity, "Proxying to Compromise: SonicWall SMA 0-day Exploitation" (Jul 17, 2026) · The Hacker News, "SonicWall SMA Zero-Days Exploited Before Disclosure" (Jul 19, 2026)
Accenture confirms an intrusion; 35GB scope remains the attacker's claim [Confirmed / Scope claimed]
Reported July 7 to 8, 2026. Included as a still-developing major item.
Key facts. Organization: Accenture. Confirmed: Accenture acknowledged the incident and said it remediated the source, with no impact to operations or service delivery. Claimed by actor: a forum actor ("888") claims 35GB including source code, RSA and SSH keys, Azure access tokens and storage keys, and configuration files, offered for sale. Independently verified: no. Scope and contents are unverified, and it is unclear how access was gained or whether personal data was involved.
What happened. A threat actor posted on a cybercrime forum claiming to have stolen roughly 35GB of internal data from Accenture and offered it for sale, sharing a screenshot of what appeared to be a private Azure DevOps repository on an accenture.com domain. Accenture confirmed the incident, calling it an isolated matter that it had remediated, with no impact to operations or service delivery.
Evidence. The confirmed fact is the intrusion itself, acknowledged by Accenture. The 35GB volume and the specific data types are the attacker's claims and have not been independently verified. Accenture did not say how the data was taken, whether customer data was affected, or how the attacker gained access.
What this means for your team. The risk here is service-provider exposure. If Accenture holds source code, credentials, or infrastructure details for your environment, treat any shared secrets as potentially compromised until confirmed otherwise. Rotate shared access tokens, review repository and cloud access logs from early July, and ask for written confirmation of which systems were affected.
Sources (2, verified): SecurityWeek, "Accenture Confirms Data Breach After Hacker Claims Source Code Theft" (Jul 8, 2026) · BleepingComputer, "Accenture confirms breach after hacker offers stolen data for sale" (Jul 7, 2026)
On the watchlist, not yet confirmed [Unverified]
Several organizations appeared on ransomware leak sites during this cycle. Leak-site listings are third-party claims and do not by themselves confirm that a breach occurred or that specific data was exposed, so we do not name them or repeat specifics here. We will report on any such item only once it is corroborated by credible reporting or an official notification, with two verified sources, in a future edition.
Breach Watch is one way the CISO Platform community turns daily noise into decisions. Members compare incident playbooks, checklists, and frameworks, and share what actually worked. Joining is free.
Frequently asked questions
Which SonicWall vulnerabilities are being exploited?
CVE-2026-15409, a pre-authentication server-side request forgery flaw rated CVSS 10.0, and CVE-2026-15410, a post-authentication command injection flaw rated CVSS 7.2, in SMA 1000 series appliances. Chained, they enable arbitrary command execution and full appliance takeover.
Did Accenture confirm the 35GB data theft?
Accenture confirmed an intrusion and said it was contained with no operational impact. The 35GB figure and the list of stolen data are the attacker's claims and have not been independently verified.
What should a CISO do first?
Confirm exposure in your own environment before acting on external claims: get affected appliances onto fixed versions and hunt for prior compromise, rotate potentially exposed credentials, and review service-provider and third-party access.
Methodology: every breach above was corroborated against two independent sources, each fetched and checked before publication. Threat-actor claims are labeled and are not presented as confirmed fact. Figures reflect reporting available as of July 20, 2026 and should be reverified before republication.

Comments