Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Huntress researchers reported an active credential-stuffing campaign against SonicWall VPN and firewall accounts that compromised 30 organizations and 92 user accounts in less than two days. The attacks appeared broad and opportunistic, with no post-compromise activity so far, while SonicWall continues to investigate and past issues have included stolen firewall configurations and exploited flaws. #SonicWall #Huntress #CISA #Akira

Keypoints

  • Huntress detected ongoing attacks against SonicWall VPN and firewall accounts.
  • The campaign compromised 30 organizations in under two days.
  • Attackers validated credentials through remote access portals in a credential-stuffing pattern.
  • No post-compromise activity has been observed, suggesting possible future use.
  • SonicWall devices remain exposed to repeated zero-day and known-vulnerability abuse.

Read More: https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/