Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

Posted on October 13, 2025October 13, 2025 By CWS

A surge in assaults concentrating on SonicWall SSLVPN units, affecting quite a few buyer networks, simply weeks after a serious breach uncovered delicate firewall knowledge.

Beginning October 4, 2025, menace actors have quickly authenticated into over 100 accounts throughout 16 environments, utilizing what seem like stolen legitimate credentials fairly than brute-force strategies.

This coordinated assault highlights the rising dangers to distant entry instruments in enterprise settings, doubtlessly stemming from a latest cloud storage incident at SonicWall.

The compromises unfolded shortly, with clustered login makes an attempt peaking over the subsequent two days. In lots of circumstances, attackers related briefly from the IP handle 202.155.8[.]73 earlier than disconnecting with out additional motion.

Nevertheless, in additional extreme cases, they carried out community scans and tried to entry native Home windows accounts, indicating deeper reconnaissance or lateral motion efforts.

Huntress famous the dimensions and velocity counsel attackers possess insider information of credentials, elevating alarms for organizations counting on SonicWall for safe distant entry.

SonicWall SSLVPN Beneath Assault

SonicWall’s latest safety advisory has escalated issues by confirming that hackers accessed encrypted configuration backups for each buyer utilizing its MySonicWall cloud service.

These information comprise essential knowledge like credentials and settings, which, even encrypted, may allow focused exploits if decrypted. The corporate initially reported in mid-September that fewer than 5% of firewalls have been impacted, however the replace on October 10 revealed the breach affected all customers of the backup characteristic.

Whereas Huntress has not confirmed a direct connection between the breach and the SSLVPN assaults, the timing and nature of the incidents align suspiciously.

The agency is sharing indicators of compromise, together with the suspicious IP, to assist defenders establish comparable exercise. SonicWall urges clients to log into MySonicWall.com instantly to examine for affected units and observe detailed remediation steps, comparable to resetting all uncovered credentials.

Mitigations

To mitigate dangers, companies ought to act swiftly by proscribing wide-area community administration and distant entry the place possible. Quickly disable HTTP, HTTPS, SSH, SSL VPN, and inbound administration interfaces till credentials are totally reset.

This contains revoking native admin passwords, VPN pre-shared keys, LDAP or RADIUS bind credentials, wi-fi passphrases, and SNMP settings on impacted firewalls.

Additional, organizations should roll over exterior API keys, dynamic DNS configurations, SMTP or FTP accounts, and any automation secrets and techniques linked to administration techniques.

Enhanced logging is essential for reviewing latest logins and modifications for anomalies, retaining data for forensic evaluation. As soon as resets are full, re-enable companies regularly whereas monitoring for unauthorized re-entry.

Imposing multi-factor authentication on all admin and distant accounts, alongside making use of least-privilege ideas, will bolster defenses long-term.

Huntress continues monitoring these threats and provides steering by its assist assets, emphasizing proactive vigilance in an period of credential-based assaults.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attack, Backups, Breach, Customers, Firewall, SonicWall, SSLVPN

Post navigation

Previous Post: Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication
Next Post: RealBlindingEDR Tool That Permanently Turn off AV/EDR Using Kernel Callbacks

Related Posts

Critical NGINX Flaw Risks Remote Code Execution Critical NGINX Flaw Risks Remote Code Execution Cyber Security News
New Business Email Protection Technique Blocks the Phishing Email Behind NPM Breach New Business Email Protection Technique Blocks the Phishing Email Behind NPM Breach Cyber Security News
10 Best Malware Analysis Tools 10 Best Malware Analysis Tools Cyber Security News
IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands Cyber Security News
Burger King Uses DMCA Complaint to Take Down Blog Post Detailing Security Flaws on Drive-Thru Systems Burger King Uses DMCA Complaint to Take Down Blog Post Detailing Security Flaws on Drive-Thru Systems Cyber Security News
Akira Ransomware Uses Windows Drivers to Bypass AV/EDR in SonicWall Attacks Akira Ransomware Uses Windows Drivers to Bypass AV/EDR in SonicWall Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark