SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, July 20, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY SonicWall VPN Zero-Days and Critical NGINX RCE | CRITICAL |
|
5 C2 IPs | 120 OTX IOCs | 6 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by critical vulnerabilities in edge infrastructure and active exploitation campaigns. Organizations must immediately address a critical remote code execution vulnerability in F5 NGINX (CVE-2026-42533) and the active zero-day exploitation of SonicWall SMA 1000 series VPN appliances. Concurrently, state-sponsored threat actors like UAC-0145 are leveraging sophisticated "ClickFix" CAPTCHA social engineering tactics to deliver malware, while other advanced adversaries are compromising software update mechanisms and scanning for vulnerable Hikvision IoT devices. |
|
■ CRITICAL STORIES SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access An undocumented threat actor has been actively exploiting SonicWall SMA 1000 series VPN appliances as zero-days since June 2026 to gain root access, posing an immediate threat to enterprise perimeter security. |
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has patched CVE-2026-42533, a critical heap buffer overflow vulnerability in NGINX that allows unauthenticated remote attackers to crash workers or potentially execute arbitrary code via crafted HTTP requests. |
Hackers abuse ViPNet software to target Russian govt agencies Advanced threat actors are abusing the update mechanism of the ViPNet private networking product suite to deliver malicious payloads to Russian government agencies, highlighting a sophisticated supply-chain trust abuse. |
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware Russian state-sponsored threat group UAC-0145 is utilizing ClickFix fake CAPTCHA prompts to trick Ukrainian targets into executing malicious commands, leading to data-stealing malware infections. |
|
■ CVEs IDENTIFIED CVE-2026-42533 F5 NGINX — Heap buffer overflow leading to worker crash or Remote Code Execution (RCE) |
[CVE-TBD] SonicWall SMA 1000 Series VPN — Zero-day vulnerability exploited to gain unauthorized root access |
[CVE-TBD] Infotecs ViPNet — Abuse of update mechanism to deliver unauthorized malicious payloads |
[CVE-TBD] Hikvision Intelligent Security API (ISAPI) — Vulnerability targeted by internet-wide scans for potential exploitation |
|
■ THREAT ACTORS UAC-0145 | Nation-State (Russian) |
Leveraging ClickFix fake CAPTCHA pages to deliver data-stealing malware to Ukrainian targets. |
Undocumented Threat Actor | Advanced Persistent Threat (APT) |
Exploiting SonicWall SMA 1000 series VPN zero-days to gain root access. |
Advanced Threat Actor | Advanced Persistent Threat (APT) |
Abusing the update mechanism of ViPNet private networking software to target Russian government agencies. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of NGINX (CVE-2026-42533) and Hikvision ISAPI vulnerabilities. |
| T1203 | | Exploitation for Client Execution | Zero-day exploitation of SonicWall SMA 1000 series VPN appliances to gain root access. |
| T1204.001 | | User Execution: Malicious Link | ClickFix CAPTCHA pages tricking users into executing malicious commands. |
| T1195.002 | | Supply Chain Compromise: Compromise of Software Updates | Abuse of the ViPNet private networking software update mechanism. |
| T1043 | | Commonly Used Port | Internet-wide scanning of Hikvision cameras and security APIs. |
|
■ PATCH PRIORITY F5 NGINX — CVE-2026-42533 allows unauthenticated remote code execution (RCE) via heap buffer overflow — THN |
SonicWall SMA 1000 Series VPN — Active zero-day exploitation resulting in root access — THN |
Infotecs ViPNet — Abuse of software update mechanism to target government agencies — BC |
Hikvision Intelligent Security API — Active internet-wide scanning targeting known vulnerabilities — SANS |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch F5 NGINX immediately to version 1.30.4 (stable) or 1.31.3 (mainline) to mitigate the critical CVE-2026-42533 heap buffer overflow vulnerability. |
| 2 | [P1] Apply latest security patches and firmware updates to SonicWall SMA 1000 series VPN appliances to prevent unauthorized root access from zero-day exploits. |
| 3 | [P2] Restrict external access to Hikvision Intelligent Security API (ISAPI) interfaces and ensure cameras are behind a firewall or VPN to prevent exploitation from active scans. |
| 4 | [P2] Implement endpoint detection rules to block PowerShell or command-line execution initiated by browser processes to defend against ClickFix CAPTCHA social engineering tactics used by UAC-0145. |
| 5 | [P2] Audit and monitor update mechanisms and network traffic associated with Infotecs ViPNet private networking software for anomalous update payloads. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |