logo

Configuration of IT-Security solutions matter – and sometimes a single parameter can cause big trouble

ID: 12f61999-6dd8-5d6b-9d59-ea01379f012f

STIX ID: report--12f61999-6dd8-5d6b-9d59-ea01379f012f

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2025-07-02

Date Updated: 2026-05-01

Author: Jonas Spieckermann

...
...

A WatchGuard customer was compromised when attackers used stolen/brute-forced VPN credentials and logged in via a legacy Firebox-DB account that bypassed MFA; after network scanning and credential theft they exfiltrated files via SMB (uploaded to fastupload.io) and executed Akira ransomware on an unprotected server, leading to encryption but successful recovery from clean backups. The report highlights the attack chain, detection gaps, and recommends disabling legacy authentication, enforcing MFA, enabling brute-force protection, ensuring EPDR on all hosts, segmentation, patching, NDR/MDR monitoring, and HTTPS inspection to prevent similar incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.