INTEL_REPORT
SecurityWeek · published 7/20/2026, 2:11:05 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek . SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECU…
https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch
sha256:1a66216fe9bc278885576480681fcac0d9519e09ca7421d44c9a57aaa594b1b9
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.