SonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17

SonicWall SMA1000 CVE-2026-15409 RCE

SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…

Read More

Top 5 Cybersecurity News Stories July 17, 2026

Cybersecurity News Stories July 17, 2026 image showing five enterprise infrastructure layers simultaneously under threat including perimeter gateway identity platform endpoint protection ERP and cloud hypervisor

The five stories in this week’s Cybersecurity News Stories July 17, 2026 share a structural property that distinguishes them from the opportunistic exploitation patterns that characterised earlier months of this year: in each case, the compromised or exposed component is one the organisation has placed into a category other than “security risk.” A remote-access appliance…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More

Microsoft July 2026 Patch Tuesday Zero-Day Hits SharePoint

Microsoft July 2026 Patch Tuesday zero-day

The Microsoft July 2026 Patch Tuesday zero-day count is the largest disclosure on record — trackers put the total at 570 to 622 CVEs depending on methodology — and two of the fixed flaws were already being exploited before the patch shipped: one in Active Directory Federation Services, one in SharePoint Server. A separate, publicly…

Read More

Nightmare Eclipse Windows Zero-Day Trilogy

Nightmare Eclipse Windows zero-day

The Nightmare Eclipse Windows zero-day trilogy has moved from proof-of-concept code on GitHub to a confirmed, real-world intrusion: Huntress found BlueHammer, RedSun, and UnDefend deployed together in one attack chain that started with a compromised FortiGate VPN appliance. What Happened A researcher operating under the handle “Nightmare Eclipse” (also seen as “Chaotic Eclipse”) has published…

Read More