Skip to finding
important · Edge — SonicWall

Compromised SMA1000 appliances are becoming paths into Active Directory secrets and DCSync.

Affects

SonicWall SMA1000 remote-access appliances deployed at enterprise network edges.

The unauthenticated WorkPlace proxy reaches a localhost Erlang service, after which attackers recover directory material and deploy secretsdump.

Detail and 2 sources

The downstream chain included SAM and LSA collection and DCSync from domain controllers.

SonicWall identifies fixed SMA1000 builds.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026