Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

SonicWall SSL VPN Accounts in Attacker Crosshairs

Posted on October 13, 2025October 13, 2025 By CWS

Within the wake of the current compromise of SonicWall firewall configuration information, Huntress warns of a widespread marketing campaign concentrating on SonicWall SSL VPN accounts throughout a number of companies.

The attackers, the cybersecurity outfit says, are quickly logging into a number of SSL VPN accounts throughout compromised units, doubtless utilizing legitimate credentials relatively than brute-forcing them.

Many of the exercise occurred on October 4, and continued in clusters over the next days. By October 10, greater than 100 SonicWall SSL VPN accounts throughout 16 environments have been compromised as a part of the marketing campaign.

The authentication makes an attempt got here from the identical IP tackle, and normally the attackers have been seen disconnecting from the compromised community with out performing extra actions.

“In different instances, there was proof of post-exploitation exercise, with the actors conducting community scanning exercise and trying to entry quite a few native Home windows accounts,” Huntress says.

The warning got here days after SonicWall introduced that every one customers who saved firewall configuration information utilizing its cloud backup service have been impacted by a September knowledge breach.

As a part of the assault, hackers accessed the desire information of all firewalls configured with MySonicWall because the cloud backup service. Provided that these information include encrypted credentials and configuration knowledge, the compromise poses a excessive danger to the affected organizations, SonicWall stated final week.

In response to Huntress, there isn’t a proof that the recent marketing campaign is said to the MySonicWall knowledge breach, however that doesn’t rule out a possible connection between the 2.Commercial. Scroll to proceed studying.

“Notably, we’ve no proof to hyperlink [the SonicWall] advisory to the current spike in compromises that we’ve seen. Nonetheless, none could exist permitting us to discern that exercise from our vantage level. We’re reporting the symptoms of compromise and knowledge relating to mass compromise that we’ve seen,” Huntress says.

The cybersecurity agency recommends proscribing WAN administration and distant entry, resetting credentials, disabling or limiting distant administration till credentials are rotated, and revoking and re-rolling exterior APIs and automation secrets and techniques.

Organizations must also overview logs for uncommon login makes an attempt, progressively reintroduce providers after credential rotation and monitor for unauthorized entry, and implement multi-factor authentication (MFA) for all administrator and distant entry accounts.

Associated: Cisco, Fortinet, Palo Alto Networks Gadgets Focused in Coordinated Marketing campaign

Associated: Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues

Associated: SonicWall Updates SMA 100 Home equipment to Take away Overstep Malware

Associated: Widespread Infostealer Marketing campaign Concentrating on macOS Customers

Security Week News Tags:Accounts, Attacker, Crosshairs, SonicWall, SSL, VPN

Post navigation

Previous Post: Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations
Next Post: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

Related Posts

Unpatched Ruckus Vulnerabilities Allow Wireless Environment Hacking Security Week News
Farmers Insurance Data Breach Impacts Over 1 Million People Security Week News
Scattered Spider Targeting VMware vSphere Environments Security Week News
AISLE Emerges From Stealth With AI-Based Reasoning System That Remediates Vulnerabilities on the Fly Security Week News
European Airport Cyberattack Linked to Obscure Ransomware, Suspect Arrested Security Week News
Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
  • New Research Uncovers 28 Unique IP Addresses and 85 Domains Hosting Carding Markets
  • New ‘Penguin’ Pig Butchering as a Service Selling PII, Stolen Accounts and Fraud Kits
  • New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender
  • Hackers Accessed University of Hawaii Cancer Center Patient Data; They Weren’t Immediately Notified

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
  • New Research Uncovers 28 Unique IP Addresses and 85 Domains Hosting Carding Markets
  • New ‘Penguin’ Pig Butchering as a Service Selling PII, Stolen Accounts and Fraud Kits
  • New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender
  • Hackers Accessed University of Hawaii Cancer Center Patient Data; They Weren’t Immediately Notified

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark