Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data. These security challenges have affected multiple customer networks.

Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data. These security challenges have affected multiple customer networks.

Commencing on Tue, Oct 4, 2025, unauthorized access attempts were observed across more than 100 accounts in 16 environments. These attempts involved valid credentials, possibly obtained through non-brute-force methods.

The attacks, believed to be linked to a recent cloud storage incident at SonicWall, involved rapid authentication and brief connections from IP address 202.155.8[.]73. In certain cases, attackers conducted network scans and attempted to access local Windows accounts, suggesting deeper reconnaissance activities.

SonicWall has confirmed that attackers accessed encrypted configuration backups through its MySonicWall cloud service. These backups contain critical data, including credentials and settings. Although encrypted, this information could facilitate targeted exploits if decrypted. Initially, it was reported that less than 5% of firewalls were impacted, but a subsequent update on Tue, Oct 10, 2025, revealed that all users of the backup feature were affected.

Recent incidents have highlighted vulnerabilities in SonicWall SSLVPN devices, following a major breach that exposed sensitive firewall data.
Jason Ford · Thehackingpost

Organizations are advised to log into MySonicWall.com to verify device status and adhere to remediation protocols, including resetting exposed credentials.

Restrict WAN management and remote access where possible. Disable HTTP, HTTPS, SSH, SSL VPN, and inbound management interfaces until credentials are reset. Revoke and refresh local admin passwords, VPN pre-shared keys, LDAP or RADIUS bind credentials, wireless passphrases, and SNMP settings. Update external API keys, dynamic DNS configurations, SMTP or FTP accounts, and automation secrets linked to management systems. Implement enhanced logging for anomaly detection and forensic analysis. Gradually re-enable services post-resets while monitoring for unauthorized access. Enforce multi-factor authentication on all admin and remote accounts and apply least-privilege principles.

Advertisement

Huntress continues to monitor these threats and provides guidance through support resources, emphasizing the importance of proactive defense measures in the face of credential-based attacks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories