logo

Huntress Threat Advisory: Widespread SonicWall SSLVPN Compromise

ID: d535b0cb-de94-5933-9ec0-3554168eac22

STIX ID: report--d535b0cb-de94-5933-9ec0-3554168eac22

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-10-10

Date Updated: 2026-04-28

...
...

Huntress reports a spike in SonicWall SSLVPN compromises beginning October 4, observing clustered rapid authentications across more than 100 accounts in 16 customer environments (notably originating from 202.155.8.73), with some instances showing post-exploitation scanning and attempts to access local Windows accounts; SonicWall separately warned that an unauthorized party accessed MySonicWall cloud backup files containing encrypted credentials, and both Huntress and SonicWall provide containment and remediation guidance including credential resets, MFA enforcement, and restricted remote management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.