SonicWall Zero-Days Exploited Before Disclosure & AI Agent Risk (07/19/2026)
- › A previously undocumented actor was exploiting the SonicWall SMA 1000 zero-days as far back as June, before their public disclosure.
- › Security researchers warn that connecting AI agents to outside services multiplies the blast radius of a single compromise.
- › An advanced actor is abusing the update mechanism of the ViPNet networking suite to target Russian government agencies.
- › Russia-linked UAC-0145 is using ClickFix CAPTCHA lures to get Ukrainian targets to infect their own machines.
- › Internet-wide scans for the Hikvision Intelligent Security API are probing a product line with a long history of flaws.
The SonicWall story got worse today, and it is the one to sit up for. The two SMA zero-days that drove last week’s alerts were not caught the day they went public, they were being exploited quietly since June by an actor nobody had documented. Around it, researchers are warning that wiring AI agents into outside services multiplies the blast radius of any single compromise, and two more campaigns are abusing the update channels and security prompts people are trained to trust.
Top 5 Critical Security Alerts
1. SonicWall SMA Zero-Days Were Exploited Before Anyone Disclosed Them
A previously undocumented threat actor has been tied to exploitation of the SonicWall SMA 1000 zero-days as zero-days, going back to June, before the flaws were publicly disclosed (The Hacker News). We covered the chained root exploit last week, and this is the part that reframes it: by the time you heard about the bug, someone had already been living on the appliance for weeks. Patching closes the door, and it does not tell you who was already inside.
Operator Note: Treat a disclosed edge-appliance zero-day as an incident, not a maintenance ticket. If you ran a vulnerable SonicWall SMA before this month, assume compromise and hunt for it, because the exploitation predates the advisory.
2. Connecting AI Agents to Outside Services Explodes the Risk Radius
Researchers are warning that the rush to connect AI agents to external services and tools sharply expands the blast radius of any single compromise, since each connection is a new path the agent can be steered down (The Register). An agent wired to your email, your files, and your payment tools is only as trustworthy as the least trustworthy input it reads, which is the same lesson behind why blind trust in an AI agent is the real risk.
3. Attackers Abuse the ViPNet Update Mechanism to Hit Russian Agencies
An advanced actor is abusing the update mechanism of the ViPNet secure networking suite to reach Russian organizations, including government agencies (BleepingComputer). The update channel is the perfect delivery route because it is trusted, signed, and automatic by design, which is exactly why an attacker who gets into it inherits all of that trust for free.
4. UAC-0145 Uses ClickFix CAPTCHAs Against Ukrainian Targets
Russia-linked UAC-0145 is running ClickFix CAPTCHA lures to trick Ukrainian users into pasting and running commands that infect their own machines with data-stealing malware (The Hacker News). ClickFix has fully crossed from criminal commodity into state tradecraft, and the fake CAPTCHA works because clicking to prove you are human is a motion nobody stops to question.
5. Internet-Wide Scans Hunt the Hikvision Security API
The SANS Internet Storm Center reported scans probing the Hikvision Intelligent Security API, a camera product line with a long history of vulnerabilities and a favorite of internet-wide scanning (SANS ISC). Internet-exposed cameras are the physical security devices most likely to be quietly conscripted, and a scan today is a foothold attempt tomorrow.
Operator Note: Your cameras are computers on the internet. Put them behind the same patching and network segmentation you give any other exposed server, and get the management interface off the public internet.
Additional Security Alerts
Emerging Security Technologies
- AI Radiology Models Are Confidently Wrong: The RadLE 2.0 benchmark found many AI models deliver incorrect X-ray findings with full confidence and cannot tell when to defer to a human, while radiologists still outperform them. The Decoder
- AI Text Detectors Falter Against Style Mimicry: New testing shows AI-text detectors struggle when a language model is prompted to imitate a specific author’s style, another crack in tools sold as reliable authenticity checks. The Decoder
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.