SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

SonicWall, a leading name in enterprise security, has issued an urgent recommendation for its customers to disable the SSLVPN feature on its latest firewall models. This advisory comes in response to increasing reports of ransomware attacks specifically targeting users of SonicWall's Generation 7 firewalls. The company highlighted a significant rise in security incidents associated with these devices when VPN access is enabled. In a recent statement, SonicWall confirmed that it is actively investigating these cases to determine whether they are linked to a previously known vulnerability or if a new, unreported flaw might be at play. The warning arrives as cybersecurity experts report that hackers are increasingly exploiting SonicWall devices to gain initial access to compromised networks. These devices, which are designed to act as digital gatekeepers for legitimate users, can become entry points for malicious actors if security vulnerabilities are present. Research from Arctic Wolf indicates that intrusions targeting SonicWall customers have been occurring since mid-July. The firm noted that evidence suggests the presence of a zero-day vulnerability, a flaw that has been exploited before it could be patched by the vendor. The timeline of attacks reveals a concerning correlation between the exploitation of the firewall and the deployment of ransomware, which locks users out of their data. Huntress Labs echoed these concerns, suggesting that a zero-day vulnerability in SonicWall firewalls is likely responsible for the recent attacks. They warned that the hackers exploiting this flaw have been able to access critical network components, such as domain controllers, which oversee devices and user access within a network. Furthermore, Huntress has pointed to the Akira ransomware group as a potential perpetrator of these attacks, noting their history of targeting enterprise-level security products to infiltrate large networks. This situation represents a severe and ongoing threat, and SonicWall's advisory underscores the importance of immediate action to safeguard network security.

Sources : TechCrunch

Published On : Aug 05, 2025, 14:31

Science
Surprising Outcome at CDC Vaccine Meeting: COVID-19 Shot Access Maintained

A tumultuous two-day advisory meeting on vaccines concluded with a surprising unanimous decision to uphold widespread ac...

Ars Technica | Sep 19, 2025, 21:45
Surprising Outcome at CDC Vaccine Meeting: COVID-19 Shot Access Maintained
AI
Anthropic's Dario Amodei Discusses AI's Dual Edge: Risks and Rewards

Dario Amodei, the CEO of Anthropic, recently addressed the complex landscape of artificial intelligence at the Axios AI ...

Mint | Sep 20, 2025, 04:05
Anthropic's Dario Amodei Discusses AI's Dual Edge: Risks and Rewards
Science
NASA Navigates Budget Turmoil with Positive Developments from House Funding

The fiscal landscape for the United States in 2026 is proving to be quite tumultuous. Earlier this year, the White House...

Ars Technica | Sep 19, 2025, 22:40
NASA Navigates Budget Turmoil with Positive Developments from House Funding
Aerospace
Europe's Reusable Rocket Initiative Gains Momentum with Themis Prototype

The European Space Agency (ESA) and its contractors have often faced criticism for their slow pace in developing reusabl...

Ars Technica | Sep 19, 2025, 22:10
Europe's Reusable Rocket Initiative Gains Momentum with Themis Prototype
Cybersecurity
Critical Security Flaw in Microsoft Azure's Entra ID Exposed: A Potential Catastrophe Averted

As organizations globally transition from traditional self-hosted servers to cloud-based infrastructures, they often rel...

Ars Technica | Sep 20, 2025, 11:20
Critical Security Flaw in Microsoft Azure's Entra ID Exposed: A Potential Catastrophe Averted
View All News