Cybersecurity · Wednesday, 22 July 2026
01 · Briefing · what happened
The break-in came through the box built to keep people out
SonicWall's remote-access appliances were exploited for three weeks before anyone knew — the latest sign that attackers are hammering the trusted gear that sits between a company and the internet, while a run of breaches spills millions of records.
The most dangerous door into a company right now is often the one sold as a lock.
Weeks inside before the alarm
Security researchers at Volexity found that attackers had been quietly exploiting two flaws in SonicWall’s remote-access appliances for about three weeks before the company disclosed them and shipped a fix on July 14
A zero-day is a flaw the maker doesn’t yet know about — so there is no patch, and anyone using it has a clear run until it’s found. Here the run lasted weeks
If your workplace uses SonicWall SMA remote access, the fix must be applied, not just available. For everyone else, this is the pattern worth carrying: the gear that faces the internet on your behalf — the login gateway, the VPN box — is exactly what attackers study hardest, because breaking it once puts them behind everyone’s walls at once.
A bad week for the boxes at the edge
SonicWall was not alone. America’s cyber-defence agency, CISA, added an actively exploited flaw in Microsoft SharePoint — the widely used document-and-collaboration server — to its must-patch list and urged administrators to fix it immediately
The through-line: attackers are concentrating fire on the shared plumbing — the appliances and servers that many organisations run and few people watch day to day.
Millions of records spilled
Several large data leaks surfaced this week. A breach at the AI music service Suno exposed more than 55 million user accounts, confirmed in scale by the breach-tracking service Have I Been Pwned; the dump was mostly email addresses
The reader’s move is the same each time: check whether your email appears in a known breach at haveibeenpwned.com, and if you reused a password anywhere, change it everywhere you used it. One leaked password is how a single breach quietly becomes five.
The suppliers you never see
Two quieter stories point at the same nerve. The White House ordered defence contractors to map the software and suppliers running through their critical supply chains — an admission that even the government can’t currently see everything its systems depend on
Neither is a dramatic breach. Both are about the same blind spot: the things your systems quietly rely on, chosen by someone else, further down than you can see.
One to watch: the app in your pocket
Away from the headline breaches, a Wired review of security research renewed a warning worth repeating: many period-tracking and health apps quietly share intimate data with third parties
02 · Lesson · why it matters
You inherit the trust of everything you lean on
When you depend on something, you quietly take on everything it depends on too — a chain you didn't choose and mostly can't see.
The gate wasn’t the target — it was the shortcut
When attackers spent three weeks inside SonicWall’s remote-access boxes, they weren’t after the box. They were after everyone standing behind it. A remote-access appliance exists so a company can trust one guarded gate instead of checking every person at every door. That is its whole value: it lets thousands of people, systems, and decisions ride on a single point of trust.
Which is also its whole danger. Break the gate once, and you don’t get one victim — you get everyone who agreed to trust it. The attacker didn’t have to earn each company’s confidence. The company had already handed it to a box, and the box handed it on.
Trust runs downhill, and it doesn’t stop
Here is the part that is easy to miss. You do not just trust the things you chose. You trust everything they chose, too.
Your company trusts the SonicWall gateway. The gateway’s makers trusted the code libraries they built it from. Those libraries were built from other people’s code, pulled off a public shelf, updated automatically overnight. When a developer this week ran a routine, trusted software package from the npm registry, they had no idea it had been quietly swapped for a tampered version carrying malware. They didn’t trust the attacker. They trusted a package — which trusted another — which had been turned.
Trust is not a wall you build once around your own things. It is a current that flows downhill through every layer you stand on, and it does not stop at the edge of what you can see.
Nobody has the full map — not even the people who should
The clearest sign of how deep this runs came from the government itself. The White House had to order its own defence contractors to go and map the software and suppliers inside their critical systems. Read that plainly: the people building the nation’s most sensitive machines were told to find out what their machines are actually made of, because right now they don’t fully know.
That is not carelessness. It is the normal state of anything complex. Every useful system is assembled from parts made by strangers, resting on parts made by other strangers, most of them invisible from the top. The arrangement is not a flaw someone introduced — it is the price of building anything modern. You get to stand on a mountain of other people’s work; the cost is that you can’t inspect the mountain.
Where you actually sit in this
It is tempting to file all of this under “big companies and their boxes.” But the current reaches all the way down to the phone in your hand.
The health app you installed shares your data with companies you never heard of. The website that leaked your password had bought its login system from a vendor who used a service run by someone else. When 55 million accounts spilled from a music app, the users hadn’t trusted the attacker — they had trusted the app, which trusted its plumbing, which had a hole. You are the last node in a chain that runs back through people and companies you’ll never meet, and you carry the risk of every weak link above you.
The one link you can actually hold
Almost none of this chain is yours to control. You can’t audit npm. You can’t inspect a vendor’s vendor. That is the humbling part: your safety depends heavily on strangers doing their jobs, and you will never see most of them.
But two things do sit in your hands, and they are the whole reason patching feels urgent even when it’s boring. The first is how much you depend on — fewer apps, fewer accounts, fewer boxes trusted with everything means fewer inherited weak links. The second is speed: the gap between “a fix exists” and “the fix is installed” is the one stretch of the chain you personally own. The Inc ransomware group didn’t need a new flaw after SonicWall’s was public. It just needed people slow to close the door.
The rest of the chain you can’t see. You only get to decide how long you leave your own link open — and how many links you agreed to carry in the first place.
03 · Lab · your turn
The Chain You Inherit
Rehearse how patch-speed and fewer dependencies each shift your odds against a break you can't choose or see.
04 · Hope · carry this
The same chain that carries a weakness downhill carries the fix down it too. Researchers surface the silent break-ins and agencies publish the patch for everyone — strangers you never chose, quietly closing the door before you knew it was open.
More from Cybersecurity