As cited
Copy frozen at (site build).
ransomware
Active Exploitation of SonicWall VPNs
A zero-day vulnerability in SonicWall VPNs is being actively exploited by threat actors to bypass multi-factor authentication (MFA) and deploy ransomware. Attackers are rapidly moving to domain controllers after initial compromise. Huntress recommends immediately disabling the VPN service or restricting access through IP allow-listing.
Why it matters: Organizations running SonicWall VPNs face immediate risk of unauthorized access, lateral movement, and ransomware deployment; urgent mitigation or service restriction is required today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Active Exploitation of SonicWall VPNs
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Active Exploitation of SonicWall VPNs
A likely zero-day vulnerability in SonicWall virtual private networks (VPNs) is being actively exploited to bypass multifactor authentication (MFA) and deploy ransomware. Threat actors are gaining access to domain controllers within hours of initial breach. Huntress recommends disabling the VPN service immediately or restricting access through Internet Protocol (IP) allow-listing.
Why it matters: Organizations running SonicWall VPNs face immediate risk of ransomware deployment and domain controller compromise; administrators should disable or severely restrict the service until a patch is available.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Active Exploitation of SonicWall VPNs
A likely zero-day vulnerability in SonicWall virtual private networks (VPNs) is being actively exploited to bypass multifactor authentication (MFA) and deploy ransomware. Threat actors are gaining access to domain controllers within hours of initial breach. Huntress recommends disabling the VPN service immediately or restricting access through Internet Protocol (IP) allow-listing.
Why it matters: Organizations running SonicWall VPNs face immediate risk of ransomware deployment and domain controller compromise; administrators should disable or severely restrict the service until a patch is available.
- Source published
- First seen by Cybersecurity Tracker