Daily Security Intel

Archives
Log in
Subscribe
July 20, 2026

[SecurityIntel] 20 Jul | SonicWall VPN Zero-Days and Critical NGINX RCE

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, July 20, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

SonicWall VPN Zero-Days and Critical NGINX RCE

CRITICAL

5

C2 IPs

120

OTX IOCs

6

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by critical vulnerabilities in edge infrastructure and active exploitation campaigns. Organizations must immediately address a critical remote code execution vulnerability in F5 NGINX (CVE-2026-42533) and the active zero-day exploitation of SonicWall SMA 1000 series VPN appliances. Concurrently, state-sponsored threat actors like UAC-0145 are leveraging sophisticated "ClickFix" CAPTCHA social engineering tactics to deliver malware, while other advanced adversaries are compromising software update mechanisms and scanning for vulnerable Hikvision IoT devices.

■ CRITICAL STORIES

CRITICAL#1

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

An undocumented threat actor has been actively exploiting SonicWall SMA 1000 series VPN appliances as zero-days since June 2026 to gain root access, posing an immediate threat to enterprise perimeter security.

CRITICAL#2

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has patched CVE-2026-42533, a critical heap buffer overflow vulnerability in NGINX that allows unauthenticated remote attackers to crash workers or potentially execute arbitrary code via crafted HTTP requests.

HIGH#3

Hackers abuse ViPNet software to target Russian govt agencies

Advanced threat actors are abusing the update mechanism of the ViPNet private networking product suite to deliver malicious payloads to Russian government agencies, highlighting a sophisticated supply-chain trust abuse.

HIGH#4

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

Russian state-sponsored threat group UAC-0145 is utilizing ClickFix fake CAPTCHA prompts to trick Ukrainian targets into executing malicious commands, leading to data-stealing malware infections.

■ CVEs IDENTIFIED

CVE-2026-42533

F5 NGINX — Heap buffer overflow leading to worker crash or Remote Code Execution (RCE)

Critical

[CVE-TBD]

SonicWall SMA 1000 Series VPN — Zero-day vulnerability exploited to gain unauthorized root access

Critical

[CVE-TBD]

Infotecs ViPNet — Abuse of update mechanism to deliver unauthorized malicious payloads

High

[CVE-TBD]

Hikvision Intelligent Security API (ISAPI) — Vulnerability targeted by internet-wide scans for potential exploitation

High

■ THREAT ACTORS

UAC-0145

Nation-State (Russian)

Leveraging ClickFix fake CAPTCHA pages to deliver data-stealing malware to Ukrainian targets.

Undocumented Threat Actor

Advanced Persistent Threat (APT)

Exploiting SonicWall SMA 1000 series VPN zero-days to gain root access.

Advanced Threat Actor

Advanced Persistent Threat (APT)

Abusing the update mechanism of ViPNet private networking software to target Russian government agencies.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of NGINX (CVE-2026-42533) and Hikvision ISAPI vulnerabilities.
T1203
Exploitation for Client Execution | Zero-day exploitation of SonicWall SMA 1000 series VPN appliances to gain root access.
T1204.001
User Execution: Malicious Link | ClickFix CAPTCHA pages tricking users into executing malicious commands.
T1195.002
Supply Chain Compromise: Compromise of Software Updates | Abuse of the ViPNet private networking software update mechanism.
T1043
Commonly Used Port | Internet-wide scanning of Hikvision cameras and security APIs.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

F5 NGINX — CVE-2026-42533 allows unauthenticated remote code execution (RCE) via heap buffer overflow — THN

[P1 PATCH NOW]≤24h

SonicWall SMA 1000 Series VPN — Active zero-day exploitation resulting in root access — THN

[P2 PATCH NOW]≤72h

Infotecs ViPNet — Abuse of software update mechanism to target government agencies — BC

[P2 PATCH NOW]≤72h

Hikvision Intelligent Security API — Active internet-wide scanning targeting known vulnerabilities — SANS

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch F5 NGINX immediately to version 1.30.4 (stable) or 1.31.3 (mainline) to mitigate the critical CVE-2026-42533 heap buffer overflow vulnerability.
2[P1] Apply latest security patches and firmware updates to SonicWall SMA 1000 series VPN appliances to prevent unauthorized root access from zero-day exploits.
3[P2] Restrict external access to Hikvision Intelligent Security API (ISAPI) interfaces and ensure cameras are behind a firewall or VPN to prevent exploitation from active scans.
4[P2] Implement endpoint detection rules to block PowerShell or command-line execution initiated by browser processes to defend against ClickFix CAPTCHA social engineering tactics used by UAC-0145.
5[P2] Audit and monitor update mechanisms and network traffic associated with Infotecs ViPNet private networking software for anomalous update payloads.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 19 Jul | Public Exploits Released For WordPress wp2shell RCE
Powered by Buttondown, the easiest way to start and grow your newsletter.