Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

SonicWall SSL VPN Accounts in Attacker Crosshairs

Posted on October 13, 2025October 13, 2025 By CWS

Within the wake of the current compromise of SonicWall firewall configuration information, Huntress warns of a widespread marketing campaign concentrating on SonicWall SSL VPN accounts throughout a number of companies.

The attackers, the cybersecurity outfit says, are quickly logging into a number of SSL VPN accounts throughout compromised units, doubtless utilizing legitimate credentials relatively than brute-forcing them.

Many of the exercise occurred on October 4, and continued in clusters over the next days. By October 10, greater than 100 SonicWall SSL VPN accounts throughout 16 environments have been compromised as a part of the marketing campaign.

The authentication makes an attempt got here from the identical IP tackle, and normally the attackers have been seen disconnecting from the compromised community with out performing extra actions.

“In different instances, there was proof of post-exploitation exercise, with the actors conducting community scanning exercise and trying to entry quite a few native Home windows accounts,” Huntress says.

The warning got here days after SonicWall introduced that every one customers who saved firewall configuration information utilizing its cloud backup service have been impacted by a September knowledge breach.

As a part of the assault, hackers accessed the desire information of all firewalls configured with MySonicWall because the cloud backup service. Provided that these information include encrypted credentials and configuration knowledge, the compromise poses a excessive danger to the affected organizations, SonicWall stated final week.

In response to Huntress, there isn’t a proof that the recent marketing campaign is said to the MySonicWall knowledge breach, however that doesn’t rule out a possible connection between the 2.Commercial. Scroll to proceed studying.

“Notably, we’ve no proof to hyperlink [the SonicWall] advisory to the current spike in compromises that we’ve seen. Nonetheless, none could exist permitting us to discern that exercise from our vantage level. We’re reporting the symptoms of compromise and knowledge relating to mass compromise that we’ve seen,” Huntress says.

The cybersecurity agency recommends proscribing WAN administration and distant entry, resetting credentials, disabling or limiting distant administration till credentials are rotated, and revoking and re-rolling exterior APIs and automation secrets and techniques.

Organizations must also overview logs for uncommon login makes an attempt, progressively reintroduce providers after credential rotation and monitor for unauthorized entry, and implement multi-factor authentication (MFA) for all administrator and distant entry accounts.

Associated: Cisco, Fortinet, Palo Alto Networks Gadgets Focused in Coordinated Marketing campaign

Associated: Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues

Associated: SonicWall Updates SMA 100 Home equipment to Take away Overstep Malware

Associated: Widespread Infostealer Marketing campaign Concentrating on macOS Customers

Security Week News Tags:Accounts, Attacker, Crosshairs, SonicWall, SSL, VPN

Post navigation

Previous Post: Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations
Next Post: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

Related Posts

Industry Reactions to Trump Cybersecurity Executive Order: Feedback Friday Security Week News
Top 25 MCP Vulnerabilities Reveal How AI Agents Can Be Exploited Security Week News
Black Hat USA 2025 – Summary of Vendor Announcements (Part 4) Security Week News
Malanta Emerges from Stealth With $10 Million Seed Funding Security Week News
High-Severity Vulnerabilities Patched in Tenable Nessus Agent Security Week News
Vulnerabilities Patched by Juniper, VMware and Zoom  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan
  • One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM
  • Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0
  • Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets
  • Asahi Data Breach Impacts 2 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan
  • One Identity Safeguard Named a Visionary in the 2025 Gartner Magic Quadrant for PAM
  • Quttera Launches “Evidence-as-Code” API to Automate Security Compliance for SOC 2 and PCI DSS v4.0
  • Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets
  • Asahi Data Breach Impacts 2 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark