By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported
Computing

SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported

News Room
Last updated: 2025/08/05 at 2:47 AM
News Room Published 5 August 2025
Share
SHARE

Aug 05, 2025Ravie LakshmananZero-Day / Network Security

SonicWall said it’s actively investigating reports to determine if there is a new zero-day vulnerability following reports of a spike in Akira ransomware actors in late July 2025.

“Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled,” the network security vendor said in a statement.

“We are actively investigating these incidents to determine whether they are connected to a previously disclosed vulnerability or if a new vulnerability may be responsible.”

Cybersecurity

While SonicWall is digging deeper, organizations using Gen 7 SonicWall firewalls are advised to follow the steps below until further notice –

  • Disable SSL VPN services where practical
  • Limit SSL VPN connectivity to trusted IP addresses
  • Activate services such as Botnet Protection and Geo-IP Filtering
  • Enforce multi-factor authentication
  • Remove inactive or unused local user accounts on the firewall, particularly those with SSL VPN access
  • Encourage regular password updates across all user accounts

The development comes shortly after Arctic Wolf revealed it had identified a surge in Akira ransomware activity targeting SonicWall SSL VPN devices for initial access since late last month.

Huntress, in a follow-up analysis published Monday, also said it has observed threat actors pivoting directly to domain controllers merely a few hours after the initial breach.

Attack chains commence with the breach of the SonicWall appliance, followed by the attackers taking a “well-worn” post-exploitation path to conduct enumeration, detection evasion, lateral movement, and credential theft.

Identity Security Risk Assessment

The incidents also involve the bad actors methodically disabling Microsoft Defender Antivirus and deleting volume shadow copies prior to deploying Akira ransomware.

Huntress said it detected around 20 different attacks tied to the latest attack wave starting on July 25, 2025, with variations observed in the tradecraft used to pull them off, including in the use of tools for reconnaissance and persistence, such as AnyDesk, ScreenConnect, or SSH.

There is evidence to suggest that the activity may be limited to TZ and NSa-series SonicWall firewalls with SSL VPN enabled, and that the suspected flaw exists in firmware versions 7.2.0-7015 and earlier.

“The speed and success of these attacks, even against environments with MFA enabled, strongly suggest a zero-day vulnerability is being exploited in the wild,” the cybersecurity company said. “This is a critical, ongoing threat.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Grab a 4-pack of Tile Mate Bluetooth trackers in fun colors for under $60
Next Article Apple’s Back-to-School Sale Offers Free Accessories When You Buy an iPad or Mac
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

OpenAI's New Models Aren't Really Open: What to Know About Open-Weights AI
News
A Quick Guide To LLM Code Generation Technology And Its Limits | HackerNoon
Computing
Nvidia Pushes Back on AI Chip Tracking, Kill Switches, But US Might Do It Anyway
News
The best robot vacuum and mop to buy right now
News

You Might also Like

Computing

A Quick Guide To LLM Code Generation Technology And Its Limits | HackerNoon

9 Min Read
Computing

Honor celebrates four years of independence from Huawei with launch of Magic 7 series · TechNode

1 Min Read
Computing

GitHub Copilot Leads The Charge In Commercial LLM-Assisted Programming | HackerNoon

5 Min Read
Computing

Amazon will offer OpenAI’s open-weight models, sidestepping Microsoft via Apache 2.0 license

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?