{"id":2210,"date":"2025-08-10T13:57:01","date_gmt":"2025-08-10T13:57:01","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/08\/10\/sonicwall-attacks-linked-to-legacy-bug-and-password-use\/"},"modified":"2025-08-10T13:57:01","modified_gmt":"2025-08-10T13:57:01","slug":"sonicwall-attacks-linked-to-legacy-bug-and-password-use","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/08\/10\/sonicwall-attacks-linked-to-legacy-bug-and-password-use\/","title":{"rendered":"SonicWall: Attacks Linked to Legacy Bug and Password Use"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>A leading security vendor has dismissed claims of a zero-day vulnerability in its products, stating that a surge in ransomware attacks against customers is due to poor password management.<\/p>\n<p>As\u00a0reported by <em>Infosecurity<\/em> earlier this week, researchers from multiple threat detection providers observed an increase in Akira ransomware intrusions against SonicWall customers in late July.<\/p>\n<p>\u201cIn some instances, fully patched SonicWall devices were affected following credential rotation. Despite TOTP [time-based one-time password] MFA being enabled, accounts were still compromised in some instances,\u201d Arctic Wolf claimed.<\/p>\n<p>However, in an updated statement today, SonicWall posited another cause of the successful attacks on its Gen 7 and newer firewalls with SSLVPN enabled.<\/p>\n<p>\u201cWe now have high confidence that the recent SSLVPN activity is not connected to a zero-day vulnerability. Instead, there is a significant correlation with threat activity related to CVE-2024-40766, which was previously disclosed and documented in our public advisory SNWLID-2024-0015,\u201d it explained.<\/p>\n<p>\u201cWe are currently investigating less than 40 incidents related to this cyber activity. Many of the incidents relate to migrations from Gen 6 to Gen 7 firewalls, where local user passwords were carried over during the migration and not reset. Resetting passwords was a critical step outlined in the original advisory.\u201d<\/p>\n<p><em>Read more on threats to SonicWall customers: Critical SonicWall SSLVPN Bug Exploited by Ransomware Actors<\/em><\/p>\n<h2>Updated Advice for Customers<\/h2>\n<p>The security vendor strongly urged all customers who imported configuration settings from Gen 6 to newer firewalls to update to SonicOS 7.3, which has built-in protection against brute-force password and multi-factor authentication (MFA) attacks.<\/p>\n<p>\u201cWithout these additional protections, password and MFA brute-force attacks are more feasible,\u201d it warned.<\/p>\n<p>SonicWall also urged customers to reset all local user account passwords for any accounts with SSLVPN access, especially if they were carried over during migration from Gen 6 to Gen 7.<\/p>\n<p>It added that previous advice still applies, that is:<\/p>\n<ul>\n<li>Enable Botnet Protection and Geo-IP Filtering<\/li>\n<li>Remove unused or inactive user accounts<\/li>\n<li>Enforce MFA and strong password policies<\/li>\n<\/ul>\n<p>The security vendor also thanked the research community \u2013 including Arctic Wolf, Google Mandiant, Huntress\u00a0and Field Effect \u2013 for their vigilance.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A leading security vendor has dismissed claims of a zero-day vulnerability in its products, stating that a surge in ransomware attacks against customers is due to poor password management. As\u00a0reported by Infosecurity earlier this week, researchers from multiple threat detection providers observed an increase in Akira ransomware intrusions against SonicWall customers in late July. \u201cIn<\/p>\n","protected":false},"author":2,"featured_media":2211,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2210","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2210-4d04d0f4-8d06-4d78-a0d7-27d695e153f4-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=2210"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/2211"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=2210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=2210"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=2210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}