Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts

Experts Warn of Widespread SonicWall VPN Compromise Impacting Over 100 Accounts

Posted on October 11, 2025October 11, 2025 By CWS

Oct 11, 2025Ravie LakshmananCloud Safety / Community Safety
Cybersecurity firm Huntress on Friday warned of “widespread compromise” of SonicWall SSL VPN gadgets to entry a number of buyer environments.
“Risk actors are authenticating into a number of accounts quickly throughout compromised gadgets,” it stated. “The pace and scale of those assaults indicate that the attackers seem to regulate legitimate credentials relatively than brute-forcing.”
A major chunk of the exercise is claimed to have commenced on October 4, 2025, with greater than 100 SonicWall SSL VPN accounts throughout 16 buyer accounts having been impacted. Within the instances investigated by Huntress, authentications on the SonicWall gadgets originated from the IP tackle 202.155.8[.]73.
The corporate famous that in some situations, the menace actors didn’t have interaction in additional adversarial actions within the community and disconnected after a brief time frame. Nevertheless, in different instances, the attackers have been discovered conducting community scanning exercise and making an attempt to entry quite a few native Home windows accounts.

The disclosure comes shortly after SonicWall acknowledged {that a} safety incident resulted within the unauthorized publicity of firewall configuration backup information saved in MySonicWall accounts. The breach, in keeping with the most recent replace, impacts all prospects who’ve used SonicWall’s cloud backup service.
“Firewall configuration information retailer delicate info that may be leveraged by menace actors to use and achieve entry to a corporation’s community,” Arctic Wolf stated. “These information can present menace actors with essential info corresponding to person, group, and area settings, DNS and log settings, and certificates.”
Huntress, nonetheless, famous that there isn’t a proof at this stage to hyperlink the breach to the current spike in compromises.
Contemplating that delicate credentials are saved inside firewall configurations, organizations utilizing the MySonicWall cloud configuration backup service are suggested to reset their credentials on stay firewall gadgets to keep away from unauthorized entry.
It is also advisable to limit WAN administration and distant entry the place potential, revoke any exterior API keys that contact the firewall or administration techniques, monitor logins for indicators of suspicious exercise, and implement multi-factor authentication (MFA) for all admin and distant accounts.
The disclosure comes amid a rise in ransomware exercise focusing on SonicWall firewall gadgets for preliminary entry, with the assaults leveraging recognized safety flaws (CVE-2024-40766) to breach goal networks for deploying Akira ransomware.

Darktrace, in a report revealed this week, stated it detected an intrusion focusing on an unnamed U.S. buyer in late August 2025 that concerned community scanning, reconnaissance, lateral motion, privilege escalation utilizing strategies like UnPAC the hash, and knowledge exfiltration.
“One of many compromised gadgets was later recognized as a SonicWall digital non-public community (VPN) server, suggesting that the incident was a part of the broader Akira ransomware marketing campaign focusing on SonicWall expertise,” it stated.
“This marketing campaign by Akira ransomware actors underscores the essential significance of sustaining up-to-date patching practices. Risk actors proceed to use beforehand disclosed vulnerabilities, not simply zero-days, highlighting the necessity for ongoing vigilance even after patches are launched.”

The Hacker News Tags:Accounts, Compromise, Experts, Impacting, SonicWall, VPN, Warn, Widespread

Post navigation

Previous Post: Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks
Next Post: Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files

Related Posts

HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks The Hacker News
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot The Hacker News
CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence The Hacker News
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens The Hacker News
Secure Vibe Coding: The Complete New Guide Secure Vibe Coding: The Complete New Guide The Hacker News
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News