Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.

Volexity links UTA0533 to two SonicWall SMA 1000 zero-days used before disclosure to gain root, plant malware, and capture LDAP credentials.