Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The most durable USB-C cable I’ve tested so far is only $11 this weekend (and I’ll be buying several)

    November 30, 2025

    Finally, an Android tablet that I wouldn’t mind keeping my iPad Pro for (especially at this price)

    November 30, 2025

    How much RAM will your PC really need in 2025? A Windows and Mac expert’s view

    November 30, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»SonicWall VPN accounts breached using stolen credits in widespread attacks
    Security

    SonicWall VPN accounts breached using stolen credits in widespread attacks

    PineapplesUpdateBy PineapplesUpdateOctober 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    SonicWall VPN accounts breached using stolen credits in widespread attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SonicWall VPN accounts breached using stolen credits in widespread attacks

    Researchers have warned that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, legitimate credentials.

    Although in some cases the attackers disconnected after a short time, in others they performed network scans and attempted to access local Windows accounts.

    The majority of this activity began on October 4, as observed by Huntress, a managed cybersecurity platform across multiple customer environments.

    “Threat actors are increasingly authenticating multiple accounts into compromised devices,” the researchers said, adding, “The speed and scale of these attacks suggests that the attackers appear to be controlling legitimate credentials rather than brute-force them.”

    The attacks affected more than 100 SonicWall SSLVPN accounts across 16 environments protected by Huntress, indicating a significant and widespread campaign that was still ongoing on October 10.

    In the majority of cases, the malicious requests originated from the IP address 202.155.8(.)73, researchers said,

    Following the authentication phase, Huntress observed activity typical for the reconnaissance and lateral movement phases of the attack as the threat actor tried to access a large number of local Windows accounts.

    Huntress underlined that they found no evidence of compromises linked to the recent SonicWall breach, which exposed firewall configuration files for all cloud backup customers.

    Because they contain highly sensitive data, these files are encrypted, and the credentials and secrets contained within them are individually encrypted using the AES-256 algorithm.

    While an attacker can decode the files, they will see authentication passwords and keys in encrypted form, the network security company said. Explained,

    BleepingComputer has contacted SonicWall for comment on the activity observed by Huntress researchers, but no statement was immediately available.

    According to SonicWall’s security checklist, system administrators need to take the following protective steps:

    • Reset and update all local user passwords and temporary access codes
    • Update passwords on an LDAP, RADIUS, or TACACS+ server
    • Update secrets in all IPSec site-to-site and GroupVPN policies
    • Update L2TP/PPPoE/PPTP WAN Interface Password
    • Reset L2TP/PPPoE/PPTP WAN Interface

    Huntress proposes additional measures to immediately restrict WAN management and remote access when not required, and to disable or limit HTTP, HTTPS, SSH, and SSL VPNs until all secrets are encrypted.

    External API keys, dynamic DNS, and SMTP/FTP credentials should also be revoked, and automation secrets related to firewall and management systems should be invalidated.

    All administrator and remote accounts should be protected by multi-factor authentication. Resumption of service should be done in a phased manner to monitor suspicious activity at each stage.


    PICS BAS Summit

    attend Breach and Attack Simulation Summit and experience future of security verificationHear from top experts and see how AI-powered BAS Changing breach and attack simulations.

    Don’t miss the event that will shape the future of your security strategy

    accounts attacks breached credits Sonicwall stolen VPN widespread
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOracle releases second emergency patch for E-Business Suite in two weeks
    Next Article This midrange OnePlus phone outperforms pricier models — and it’s on sale at Best Buy
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    What was stolen and how?

    October 20, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    The most durable USB-C cable I’ve tested so far is only $11 this weekend (and I’ll be buying several)

    November 30, 2025

    Finally, an Android tablet that I wouldn’t mind keeping my iPad Pro for (especially at this price)

    November 30, 2025

    How much RAM will your PC really need in 2025? A Windows and Mac expert’s view

    November 30, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.