A scanning pattern similar to the one preceding CVE-2026-0400 in February is active again. May 12 saw the largest single-day session volume on this SonicWall tag in 90 days.

🔗 https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400

#GreyNoise #ThreatIntel #SonicWall

Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix

Attackers bypassed MFA on patched SonicWall Gen6 VPNs because admins missed extra manual steps required to fully fix the flaw.

Security Affairs

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

In a shocking exploit, hackers have successfully bypassed multi-factor authentication on SonicWall VPN devices, breaching security in as little as 30 minutes. ReliaQuest researchers detected the first in-the-wild exploitation of CVE-2024-12802, warning of a swift and stealthy threat.

https://osintsights.com/hackers-exploit-sonicwall-vpn-flaw-to-bypass-mfa?utm_source=mastodon&utm_medium=social

#Sonicwall #VpnExploit #MfaBypass #Cve202412802 #EmergingThreats

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

Learn how hackers exploit SonicWall VPN flaw to bypass MFA and protect your network now with expert insights and prevention strategies today effectively.

OSINTSights
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now

SonicWall patches SonicOS bugs in Gen 6, 7 and 8 firewalls.The firm released firmware updates to block bypass attacks and unauthorized access

Security Affairs

SonicWall SonicOS: Drei SicherheitslĂŒcken erlauben Zugriffskontroll-Umgehung und Denial-of-Service

Die LĂŒcken betreffen zentrale Schutzmechanismen von Firewall-Systemen und erlauben es Angreifern unter bestimmten Voraussetzungen, Zugriffskontrollen zu umgehen, eingeschrĂ€nkte Dienste anzusprechen oder GerĂ€te durch einen erzwungenen Absturz außer Betrieb zu setzen.

https://www.all-about-security.de/sonicwall-sonicos-drei-sicherheitsluecken-erlauben-zugriffskontroll-umgehung-und-denial-of-service/

#sonicwall #DOS #firewall #itsecurity

SonicWall SonicOS: Drei SicherheitslĂŒcken erlauben Zugriffskontroll-Umgehung und Denial-of-Service

SonicWall meldet drei SonicOS-Schwachstellen (SNWLID-2026-0004): Zugriffsumgehung, Path Traversal und DoS. Workaround verfĂŒgbar, Patches nötig.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit

Massenangriff auf SonicWall-Firewalls: 4.300 IP-Adressen scannen gezielt VPN-Infrastrukturen

Zwischen dem 22. und 25. Februar 2026 registrierten Analysten von GreyNoise mehr als 84.000 Scan-Sitzungen gegen SonicWall-Firewalls – verteilt auf vier koordinierte Angriffswellen. Die Kampagne folgt einem bekannten Muster: Vor eigentlichen Einbruchsversuchen kartieren Angreifer systematisch exponierte VPN-Zugangspunkte.

https://www.all-about-security.de/massenangriff-auf-sonicwall-firewalls-4-300-ip-adressen-scannen-gezielt-vpn-infrastrukturen/

#sonicwall #firewall #vpn #cybersecurity

Massenangriff auf SonicWall-Firewalls: 4.300 IP-Adressen scannen gezielt VPN-Infrastrukturen

Sicherheitsforscher dokumentieren koordinierte AufklĂ€rungskampagne gegen SonicWall-VPNs – mit Ransomware-Gruppen wie Akira im Hintergrund.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit
Marquis sues SonicWall over backup breach that led to ransomware attack

Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks.

BleepingComputer
Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led to ransomware attack | TechCrunch

Fintech giant Marquis is suing its firewall provider SonicWall, claiming that an earlier breach with SonicWall allowed hackers to deploy ransomware on Marquis' network.

TechCrunch
📱 La fuite cloud de SonicWall a permis un ransomware chez Marquis, touchant 74+ banques US et 400 000+ personnes
📝 Source: ctrlaltnod.com — Contexte: analyse...
📖 cyberveille : https://cyberveille.ch/posts/2026-01-31-la-fuite-cloud-de-sonicwall-a-permis-un-ransomware-chez-marquis-touchant-74-banques-us-et-400-000-personnes/
🌐 source : https://www.ctrlaltnod.com/news/sonicwall-breach-enabled-ransomware-attack-on-74-us-banks/
#SonicWall #chaĂźne_d_approvisionnement #Cyberveille
La fuite cloud de SonicWall a permis un ransomware chez Marquis, touchant 74+ banques US et 400 000+ personnes

Source: ctrlaltnod.com — Contexte: analyse publiĂ©e le 29 janvier 2026 dĂ©taillant l’enchaĂźnement entre une compromission du cloud MySonicWall (sept. 2025) et une attaque par ransomware contre Marquis Software Solutions (aoĂ»t 2025), avec impacts sectoriels aux États‑Unis. ‱ ÉvĂ©nement clĂ©: des acteurs Ă©tatiques ont accĂ©dĂ© au service cloud MySonicWall via des appels API, exfiltrant des sauvegardes de configurations de pare-feu. SonicWall a d’abord annoncĂ© un impact « < 5% » avant de confirmer que tous les clients du service de sauvegarde cloud Ă©taient touchĂ©s.

CyberVeille
Marquis blames ransomware breach on SonicWall cloud backup hack

Marquis Software Solutions, a Texas-based financial services provider, is blaming a ransomware attack that impacted its systems and affected dozens of U.S. banks and credit unions in August 2025 on a security breach reported by SonicWall a month later.

BleepingComputer