Huntress researchers reported an active credential-stuffing campaign against SonicWall VPN and firewall accounts that compromised 30 organizations and 92 user accounts in less than two days. The attacks appeared broad and opportunistic, with no post-compromise activity so far, while SonicWall continues to investigate and past issues have included stolen firewall configurations and exploited flaws. #SonicWall #Huntress #CISA #Akira
Keypoints
- Huntress detected ongoing attacks against SonicWall VPN and firewall accounts.
- The campaign compromised 30 organizations in under two days.
- Attackers validated credentials through remote access portals in a credential-stuffing pattern.
- No post-compromise activity has been observed, suggesting possible future use.
- SonicWall devices remain exposed to repeated zero-day and known-vulnerability abuse.
Read More: https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/