Huntress Threat Advisory: Widespread SonicWall SSLVPN Compromise
ID: d535b0cb-de94-5933-9ec0-3554168eac22
STIX ID: report--d535b0cb-de94-5933-9ec0-3554168eac22
Feed Name: Huntress Blog
Huntress reports a spike in SonicWall SSLVPN compromises beginning October 4, observing clustered rapid authentications across more than 100 accounts in 16 customer environments (notably originating from 202.155.8.73), with some instances showing post-exploitation scanning and attempts to access local Windows accounts; SonicWall separately warned that an unauthorized party accessed MySonicWall cloud backup files containing encrypted credentials, and both Huntress and SonicWall provide containment and remediation guidance including credential resets, MFA enforcement, and restricted remote management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
