Tag: SonicWall

SonicWall Confirms State-Sponsored Hackers Behind September Cloud Backup Breach
News

SonicWall Confirms State-Sponsored Hackers Behind September Cloud Backup Breach

SonicWall has officially accused state-sponsored threat actors of being responsible for the September security breach that resulted in the unapproved release of firewall configuration backup files. The company claimed in a statement this week that the malicious activity, which was carried out by a state-sponsored threat actor, was limited to the unapproved access to cloud backup files from a particular cloud environment via an API request. The ongoing worldwide Akira ransomware assaults targeting firewalls and other edge devices are unconnected to the incident. The announcement was made about a month after the business claimed that all users of the cloud backup service had firewall configuration backup data read by an unauthorized party. It stated in September that less than 5% of i...
SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers
News

SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers

Following a security compromise that affected MySonicWall accounts and exposed their firewall configuration backup files, SonicWall is advising users to reset their login credentials. Less than 5% of its customers' backup firewall preference files were read by unidentified threat actors, according to the company, which recently discovered unusual behavior directed at the cloud backup service for firewalls. The company claimed that although the credentials in the files were encrypted, they also contained information that would have made it simpler for attackers to perhaps take advantage of the associated firewall. The network security firm clarified that it was not a ransomware incident that targeted its network and stated that it is not aware of any of these data being made public b...
SonicWall Investigating Potential SSL VPN Zero- Day After 20+ Targeted Attacks Reported
News

SonicWall Investigating Potential SSL VPN Zero- Day After 20+ Targeted Attacks Reported

According to SonicWall, it is currently looking into claims of an increase in Akira ransomware actors in late July 2025 to see whether there is a new zero-day vulnerability. Cyber incidents utilizing Gen 7 SonicWall firewalls with SSLVPN enabled have significantly increased during the last 72 hours, according to a statement from the network security provider. To find out if these instances are related to a previously revealed vulnerability or if a new vulnerability could be to blame, we are actively looking into them. Until further notice, enterprises utilizing Gen 7 SonicWall firewalls are encouraged to take the actions listed below while SonicWall conducts further research read more about SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported. ...
SonicWall warns of trojanized NetExtender stealing VPN logins
News

SonicWall warns of trojanized NetExtender stealing VPN logins

Customers are being alerted by SonicWall that threat actors are disseminating a trojanized version of its NetExtender SSL VPN client, which is used to steal VPN credentials. Researchers from SonicWall and Microsoft Threat Intelligence (MSTIC) found the fraudulent programme, which imitates the most recent version of NetExtender, v10.3.2.27. By posing as an official website, the malicious installation file deceives users into believing they are installing software from SonicWall. Despite not being digitally signed by SonicWall, the installer file is signed by "CITYLIGHT MEDIA PRIVATE LIMITED," which enables it to get past basic security measures. The trojanized application aims to exfiltrate account credentials and VPN configuration to the attacker. With the help of the remote a...
Fog ransomware targets SonicWall VPNs to breach corporate networks
News

Fog ransomware targets SonicWall VPNs to breach corporate networks

Using SonicWall VPN accounts, operators of the Fog and Akira ransomware are progressively breaking into business networks. It is thought that the threat actors are taking use of a critical SSL VPN access control vulnerability called CVE-2024-40766. After patching the SonicOS vulnerability in late August 2024, SonicWall issued a warning about active exploitation around a week later. Security experts from Arctic Wolf also noted that affiliates of the Akira ransomware were using the vulnerability to obtain early access to victim networks. According to a recent Arctic Wolf investigation, at least 30 attacks have been carried out by Akira and the Fog ransomware operation read more about Fog ransomware targets SonicWall VPNs to breach corporate networks Get up to date on the latest ...