SonicWall patched two SMA 1000 zero-days on September 1 that let attackers with zero credentials chain into full remote code execution, and researchers say stolen MFA seeds survive the patch entirely.
Read the full story: SonicWall's SMA1000 Hit by Third Zero-Day Chain in a Year →
Transcript
SonicWall just patched two zero day bugs in its SMA one thousand appliances, the boxes companies use to gatekeep VPN access. One bug needs zero credentials. Chain it with the second, and an attacker gets full remote code execution without ever logging in. It's the third separate attack chain against this same product line in under a year. But here's the part that should worry security teams most: researchers found that MFA codes attackers stole before the patch still work after it. Patching alone doesn't kick out an attacker who already grabbed a login code. You have to rotate those separately. If your team just applied the update and called it done, you might still have an open door.