SonicWall Cloud Portal Breach Exposes Customer Firewall Configs
Want more insights like this?
SonicWall confirmed attackers breached its MySonicWall.com platform through brute force attacks, accessing firewall configuration files from less than 5% of its customer base. The stolen files contained encrypted passwords and network details that could help attackers exploit customer firewalls more effectively.
This marks a troubling shift from previous SonicWall vulnerabilities, which targeted customer-deployed devices. This time, attackers hit SonicWall's own infrastructure, raising questions about the company's internal security practices.
SonicWall disabled the backup feature and launched an investigation. Affected customers should reset credentials and monitor for unusual activity. The breach adds to SonicWall's security woes—CISA lists 14 exploited vulnerabilities since 2021, including nine used in ransomware attacks.
Source: CyberScoop