SECURITYCYBERSCOOP
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Huntress researchers identified a credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in two days and 92 accounts in 41 hours. The attacks, which ceased abruptly, may involve pre-positioning for future intrusions, with attackers using valid credentials obtained through unknown means. SonicWall is investigating, while CISA has cataloged 17 exploited vulnerabilities in its products since 2021, including those linked to ransomware campaigns.
Mentioned
Related Signal
Adjacent reporting
- SonicWall customers under threat as attackers exploit 2 zero-days
- Hackers bypass SonicWall VPN MFA due to incomplete patching
- Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware
- Inc Ransomware Exploits SonicWall SMA Zero-Days