SonicWall Breached, Customer Firewall Data Exposed in Cloud Attack
Want more insights like this?
SonicWall disclosed a data breach on September 17 where attackers accessed cloud backup files for customer firewalls through brute force attacks targeting their API service. The breach affected fewer than 5% of SonicWall's firewall install base, exposing encrypted credentials and configuration files that could help attackers exploit the related firewalls.
The security vendor immediately disabled the backup feature and launched an investigation with third-party experts. Impacted customers using MySonicWall.com cloud backups are advised to check their accounts, verify if their serial numbers are listed, and rotate all passwords and multi-factor authentication credentials stored in their firewalls.
This marks another security challenge for SonicWall, which has become a frequent target for cybercriminals attacking network edge devices.
Source: Dark Reading