PrivacySignal
Breach

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity · · International · Data Breaches

Security firm Volexity discovered in early July 2026 that threat actors had exploited a zero-day vulnerability in SonicWall Secure Mobile Access VPN appliances, compromising the devices during an active incident response investigation. The attack targeted the remote access hardware that organizations rely on to connect employees securely to corporate networks.

Why this matters: VPN appliances are supposed to be the lock on the door. When attackers find a zero-day in one, they do not just get in — they get in through the thing designed to keep them out. SonicWall SMA devices are widely used by businesses and government agencies. If your organization uses one, this is not an abstract threat. Patch cycles for network hardware are slow, and these devices are often trusted more than they should be. The incident also came to light through a breach investigation, which means real organizations were already hit before a fix existed.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
BleepingComputer · · International

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has flagged a new attack technique called TerminalFix, a variant of ClickFix, that presents users with fake Cloudflare CAPTCHA prompts on compromised websites. The prompts trick people into manually running malicious PowerShell commands in Windows Terminal, which can establish reverse tunnels on the victim's machine.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A rough day at the extortion office and a botched attack on Blossom Health.

An apparent extortionist targeted Blossom Health, a US telehealth and psychiatry platform, by compromising either the platform itself or an individual provider's account and sending what appears to be a ransom demand. The incident came to light after a patient contacted DataBreaches directly to report it.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

A ransomware group called Orova claims to have stolen more than 150,000 patient records from Cardiology Associates of Port Huron, a Michigan cardiology practice operating across nine locations. Journalists have reviewed the data, which reportedly contains personally identifiable and protected health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →