Key Findings Threat actor UTA0533 exploited a critical zero-day chain in SonicWall SMA 1000 VPN appliances to gain root access Two flaws chained together: CVE-2026-15409 (SSRF in Workplace interface) and CVE-2026-15410 (command injection in management console) Attacker deployed custom malware toolkit including KNUCKLEBALL loader, ORANGETAIL webshell, and Suo5 proxy tool At least two appliances confirmed compromised; exploitation originating from over 200 IP addresses using VP