SonicWall Gen6: patched. MFA bypass still works. Ransomware deployed.

Firmware fix closes one path. 6 manual LDAP steps close the real bypass — most teams never apply them.

Patched ≠ protected. CVE-2024-12802 

#CyberSecurity #SonicWall #Ransomware

Before you continue

“Patchato” non significa protetto: attaccanti bypassano l’MFA sui VPN SonicWall Gen6 e raggiungono i file server in 30 minuti

CVE-2024-12802 sulle appliance SonicWall Gen6 SSL-VPN viene sfruttata attivamente nonostante la patch disponibile. Il motivo: il fix firmware non basta — richiede sei passaggi manuali aggiuntivi che la maggior parte degli amministratori non esegue. Il risultato: attori del ransomware ecosystem bypassano l'MFA, entrano nelle reti e raggiungono i file server in meno di trenta minuti.

https://insicurezzadigitale.com/patchato-non-significa-protetto-attaccanti-bypassano-lmfa-sui-vpn-sonicwall-gen6-e-raggiungono-i-file-server-in-30-minuti/

Hackers bypass SonicWall VPN MFA due to incomplete patching

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks.

BleepingComputer

A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days.

🔗 https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400

#GreyNoise #ThreatIntel #SonicWall

Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix

Attackers bypassed MFA on patched SonicWall Gen6 VPNs because admins missed extra manual steps required to fully fix the flaw.

Security Affairs

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

In a shocking exploit, hackers have successfully bypassed multi-factor authentication on SonicWall VPN devices, breaching security in as little as 30 minutes. ReliaQuest researchers detected the first in-the-wild exploitation of CVE-2024-12802, warning of a swift and stealthy threat.

https://osintsights.com/hackers-exploit-sonicwall-vpn-flaw-to-bypass-mfa?utm_source=mastodon&utm_medium=social

#Sonicwall #VpnExploit #MfaBypass #Cve202412802 #EmergingThreats

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

Learn how hackers exploit SonicWall VPN flaw to bypass MFA and protect your network now with expert insights and prevention strategies today effectively.

OSINTSights
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now

SonicWall patches SonicOS bugs in Gen 6, 7 and 8 firewalls.The firm released firmware updates to block bypass attacks and unauthorized access

Security Affairs

SonicWall SonicOS: Drei Sicherheitslücken erlauben Zugriffskontroll-Umgehung und Denial-of-Service

Die Lücken betreffen zentrale Schutzmechanismen von Firewall-Systemen und erlauben es Angreifern unter bestimmten Voraussetzungen, Zugriffskontrollen zu umgehen, eingeschränkte Dienste anzusprechen oder Geräte durch einen erzwungenen Absturz außer Betrieb zu setzen.

https://www.all-about-security.de/sonicwall-sonicos-drei-sicherheitsluecken-erlauben-zugriffskontroll-umgehung-und-denial-of-service/

#sonicwall #DOS #firewall #itsecurity

SonicWall SonicOS: Drei Sicherheitslücken erlauben Zugriffskontroll-Umgehung und Denial-of-Service

SonicWall meldet drei SonicOS-Schwachstellen (SNWLID-2026-0004): Zugriffsumgehung, Path Traversal und DoS. Workaround verfügbar, Patches nötig.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit

Massenangriff auf SonicWall-Firewalls: 4.300 IP-Adressen scannen gezielt VPN-Infrastrukturen

Zwischen dem 22. und 25. Februar 2026 registrierten Analysten von GreyNoise mehr als 84.000 Scan-Sitzungen gegen SonicWall-Firewalls – verteilt auf vier koordinierte Angriffswellen. Die Kampagne folgt einem bekannten Muster: Vor eigentlichen Einbruchsversuchen kartieren Angreifer systematisch exponierte VPN-Zugangspunkte.

https://www.all-about-security.de/massenangriff-auf-sonicwall-firewalls-4-300-ip-adressen-scannen-gezielt-vpn-infrastrukturen/

#sonicwall #firewall #vpn #cybersecurity

Massenangriff auf SonicWall-Firewalls: 4.300 IP-Adressen scannen gezielt VPN-Infrastrukturen

Sicherheitsforscher dokumentieren koordinierte Aufklärungskampagne gegen SonicWall-VPNs – mit Ransomware-Gruppen wie Akira im Hintergrund.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit