Hackers Actively Scan SonicWall Firewall Interfaces as 597,000 Sessions Observed
ID: 06071504-38b3-5c80-9a1b-38cf51b3f745
STIX ID: report--06071504-38b3-5c80-9a1b-38cf51b3f745
Feed Name: GBHackers
**Executive summary:** GreyNoise observed a sharp surge in automated scanning of SonicWall SonicOS management interfaces between May 9–18, 2026 (peaking at ~597,000 sessions on May 12), characterized by a uniform Chrome 119 user-agent, concentrated ASN activity, and geography from the Netherlands and Ukraine; researchers note similarities to prior scanning waves that preceded the public disclosure of CVE-2026-0400 and advise restricting management access, enforcing MFA, reviewing admin accounts, and monitoring for suspicious traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
