Hackers Launch Massive SonicWall Firewall Attack Using 4,000+ IP Addresses
ID: 0b69ade0-f633-5f71-b701-6393f48cd2ba
STIX ID: report--0b69ade0-f633-5f71-b701-6393f48cd2ba
Feed Name: GBHackers
GreyNoise observed 84,142 SonicWall SonicOS scanning sessions from 4,305 unique IPs between Feb 22–25, 2026, concentrated on an SSL VPN status API to enumerate exposed VPN appliances for future credential stuffing and vulnerability abuse; attackers used commercial proxy networks, distinct HTTP fingerprints, and multiple infrastructure clusters while active CVE exploitation during the window was minimal, though several high‑severity SonicWall CVEs (notably CVE‑2024‑53704) are in CISA's KEV and have documented ransomware use, prompting urgent patching, MFA enforcement, and access restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
