logo

Firewall Lockouts: Play Ransomware and SonicWall Exploits

ID: 7d16a8e1-b8db-59f1-89ec-f412784dddea

STIX ID: report--7d16a8e1-b8db-59f1-89ec-f412784dddea

Feed Name: Halcyon Blog

Threat Score
85/100

Date Published: 2025-09-09

Date Updated: 2026-04-28

...
...

Halcyon reports several incidents where ransomware groups (Play, Akira, Qilin) forcibly took control of SonicWall firewalls—locking out administrators and rendering breakglass accounts useless—leading responders to require ISP-level isolation and physical factory resets (a “paperclip” reset) to recover. The report highlights a debate between exploit of a potential zero-day versus misconfiguration during Gen-6 to Gen-7 migrations, notes widespread probing of internet-facing firewalls, and offers practical mitigation guidance (MFA, access restrictions, offsite backups, planning for ISP isolation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.