Cybersecurity Intelligence Report — 2026-07-15
CRITICAL SECTION
- [16] SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) (HelpNetSecurity) CVE-2026-15410, CVE-2026-15409
<p>SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlined indicators of compromise are present on the system, the company advises re-imaging (hardware) or re-deploying (virtual) appliances, changing user and administrator passwords, and resetting TOTP tokens
- [10] SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (BleepingComputer) CVE-2026-15410, CVE-2026-15409
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […]
- [10] [RANSOMWARE] dragonforce leaked Intron Technology Holdings (ransomware.live/dragonforce)
Victim: Intron Technology Holdings | Group: dragonforce | Website: www.intron-tech.com | Country: TW | Details: Intron Technology Holdings Limited is a fast-growing automotive electronics solutions provider in China focuses on providing solutions targeting critical automotive electronic components applied in New Energy, Body Control, Safety and Powertrain systems. The Group utilizes its research and developme
CISA KEV SECTION (Known Exploited Vulnerabilities)
| CVE |
Vendor/Product |
Score |
Required Action |
| CVE-2026-56164 |
[CISA KEV] CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server |
9 |
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server. Required action: Apply mitigations in accordance with vendor instructions, ensurin |
| CVE-2026-56155 |
[CISA KEV] CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services |
6 |
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services. Required action: Apply mitigations in accorda |
| CVE-2026-15409 |
[CISA KEV] CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances |
6 |
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance wi |
| CVE-2026-15410 |
[CISA KEV] CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances |
6 |
SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD |
RANSOMWARE VICTIMS (DLS Monitoring)
dragonforce: [RANSOMWARE] dragonforce leaked Intron Technology Holdings, [RANSOMWARE] dragonforce leaked Edison Global Networks Limited, [RANSOMWARE] dragonforce leaked SITAV SpA, [RANSOMWARE] dragonforce leaked Graphic International Centre, [RANSOMWARE] dragonforce leaked Road Ahead Technologies Consultant, [RANSOMWARE] dragonforce leaked Atcom, [RANSOMWARE] dragonforce leaked Midal Cables, [RANSOMWARE] dragonforce leaked Omax Autos, [RANSOMWARE] dragonforce leaked Ifage, [RANSOMWARE] dragonforce leaked asimar.com
chaos: [RANSOMWARE] chaos leaked aphenapharma.com, [RANSOMWARE] chaos leaked sleemanbreweries.ca, [RANSOMWARE] chaos leaked spectrumchemical.com
blacknevas: [RANSOMWARE] blacknevas leaked Arkın Group, [RANSOMWARE] blacknevas leaked L'azurde
incransom: [RANSOMWARE] incransom leaked VantagePoint Management & Autoclear, [RANSOMWARE] incransom leaked Golden Glasko & Associates
securotrop: [RANSOMWARE] securotrop leaked ProDirectional Drilling
shinyhunters: [RANSOMWARE] shinyhunters leaked Abbott owned Exact Sciences Corporation
coinbasecartel: [RANSOMWARE] coinbasecartel leaked Axiom GlobalNEW
arcusmedia: [RANSOMWARE] arcusmedia leaked Perpustam, [RANSOMWARE] arcusmedia leaked gemese.pt, [RANSOMWARE] arcusmedia leaked Distribox, [RANSOMWARE] arcusmedia leaked Be Travel, [RANSOMWARE] arcusmedia leaked COREBI(NowVertical), [RANSOMWARE] arcusmedia leaked I-FITNESS
qilin: [RANSOMWARE] qilin leaked THL, [RANSOMWARE] qilin leaked Sedemi
nightspire: [RANSOMWARE] nightspire leaked Cedar Crest College
payoutsking: [RANSOMWARE] payoutsking leaked Casta Diva Group
AiLock: [RANSOMWARE] AiLock leaked WBF Construction
cmdorganization: [RANSOMWARE] cmdorganization leaked Target Energy Solutions
NEWS SECTION
SUMMARY
Total new items: 84. Critical count: 3. Ransomware groups active: 13. Top CVEs to patch urgently: CVE-2026-15410, CVE-2026-15409, CVE-2026-56164, CVE-2026-56155, CVE-2026-44747.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Companion HTML report: HTML report