CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3462

As cited

Copy frozen at (site build).

threat intel

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Huntress detected a credential stuffing campaign targeting SonicWall VPN and firewall accounts that compromised 30 organizations and 92 unique user accounts over a 41-hour period starting Saturday. The attacks used authorized logins to access remote portals and may represent pre-positioning for future intrusions, with no post-compromise activity observed yet. SonicWall is investigating and the attacks have paused, though the actual victim count may exceed Huntress' visibility.

Why it matters: Organizations running SonicWall edge devices face immediate risk from this active attack pattern; security teams should verify remote access credentials, review login activity for suspicious authorized sessions, and implement network segmentation to limit attacker movement if compromise occurs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Huntress identified a credential stuffing campaign targeting SonicWall virtual private network (VPN) and firewall accounts that compromised 30 organizations and 92 unique user accounts over 41 hours starting July 27, 2026. Attackers used authorized logins, likely sourced from stealer malware logs or previously compromised credentials, but did not conduct post-compromise activity, suggesting potential pre-positioning for future attacks. SonicWall has not yet released a security advisory regarding the intrusions.

Why it matters: SonicWall customers and organizations with edge devices face ongoing risk from credential-based attacks; immediate credential review and post-authentication monitoring are required to detect lateral movement before adversaries escalate access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

Huntress identified a credential stuffing campaign targeting SonicWall virtual private network (VPN) and firewall accounts that compromised 30 organizations and 92 unique user accounts over 41 hours starting July 27, 2026. Attackers used authorized logins, likely sourced from stealer malware logs or previously compromised credentials, but did not conduct post-compromise activity, suggesting potential pre-positioning for future attacks. SonicWall has not yet released a security advisory regarding the intrusions.

Why it matters: SonicWall customers and organizations with edge devices face ongoing risk from credential-based attacks; immediate credential review and post-authentication monitoring are required to detect lateral movement before adversaries escalate access.

VendorsSonicWall
Actorsakira
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary