CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Active Exploitation of SonicWall VPNs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 831

As cited

Copy frozen at (site build).

ransomware

Active Exploitation of SonicWall VPNs

A zero-day vulnerability in SonicWall VPNs is being actively exploited by threat actors to bypass multi-factor authentication (MFA) and deploy ransomware. Attackers are rapidly moving to domain controllers after initial compromise. Huntress recommends immediately disabling the VPN service or restricting access through IP allow-listing.

Why it matters: Organizations running SonicWall VPNs face immediate risk of unauthorized access, lateral movement, and ransomware deployment; urgent mitigation or service restriction is required today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Active Exploitation of SonicWall VPNs

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Active Exploitation of SonicWall VPNs

A likely zero-day vulnerability in SonicWall virtual private networks (VPNs) is being actively exploited to bypass multifactor authentication (MFA) and deploy ransomware. Threat actors are gaining access to domain controllers within hours of initial breach. Huntress recommends disabling the VPN service immediately or restricting access through Internet Protocol (IP) allow-listing.

Why it matters: Organizations running SonicWall VPNs face immediate risk of ransomware deployment and domain controller compromise; administrators should disable or severely restrict the service until a patch is available.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Active Exploitation of SonicWall VPNs

A likely zero-day vulnerability in SonicWall virtual private networks (VPNs) is being actively exploited to bypass multifactor authentication (MFA) and deploy ransomware. Threat actors are gaining access to domain controllers within hours of initial breach. Huntress recommends disabling the VPN service immediately or restricting access through Internet Protocol (IP) allow-listing.

Why it matters: Organizations running SonicWall VPNs face immediate risk of ransomware deployment and domain controller compromise; administrators should disable or severely restrict the service until a patch is available.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary