Skip to finding
important · Edge — SonicWall

SMA1000 compromise is being converted into Active Directory credential theft and DCSync.

Affects

SonicWall SMA1000, an enterprise VPN and secure-access appliance deployed physically or virtually at the network edge.

The public proxy reaches localhost Erlang; its hard-coded cookie yields appliance commands, stored LDAP credentials and access to internal directory services.

Detail and 4 sources

Campaign artifacts show SAM and LSA extraction and DCSync, while working public code covers the initial unauthenticated entry chain.

After appliance compromise, containment has to include the directory credentials and systems reached from the appliance.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026