Ransomware operators are actively exploiting two recently patched SonicWall Secure Mobile Access 1000 vulnerabilities to obtain root-level control of internet-facing remote-access appliances, steal credentials and move deeper into corporate networks.