#SSLVPN
Among many others CISA does stuff like this. Apparently it won't be for long. www.thestack.technology/sonicwall-ss...
SonicWall SSLVPN authentication flaw exploited warns CISA
Bug lets attackers to bypass even accounts with multi-factor authentication enabled.
www.thestack.technology
February 19, 2025 at 11:26 PM
SonicWall has warned customers to disable SSLVPN services due to ransomware gangs potentially exploiting an unknown security vulnerability in SonicWall Gen 7 firewalls to breach networks over the past few weeks.
SonicWall urges admins to disable SSLVPN amid rising attacks
SonicWall has warned customers to disable SSLVPN services due to ransomware gangs potentially exploiting an unknown security vulnerability in SonicWall Gen 7 firewalls to breach networks over the past few weeks.
www.bleepingcomputer.com
August 5, 2025 at 11:28 AM
SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks
SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks | TechCrunch
Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully-patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-day" bug currently unknown to SonicWall.
techcrunch.com
August 5, 2025 at 2:01 PM
American cybersecurity company SonicWall urged customers today to patch a high-severity SonicOS SSLVPN security flaw that can allow attackers to crash vulnerable firewalls.
New SonicWall SonicOS flaw allows hackers to crash firewalls
American cybersecurity company SonicWall urged customers today to patch a high-severity SonicOS SSLVPN security flaw that can allow attackers to crash vulnerable firewalls.
www.bleepingcomputer.com
November 20, 2025 at 3:56 PM
Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports.
Over 25,000 SonicWall VPN Firewalls exposed to critical flaws
Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports.
www.bleepingcomputer.com
December 17, 2024 at 3:27 PM
Bad day for VPN routers: Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474 auth bypass by HTTP, privesc via command injection. Exploitation enables pre-auth RCE chaining the bypass to inject arbitrary commands in PHP session handling, targeting SSLVPN devices.
labs.watchtowr.com/pots-and-pan...
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
It'll be no surprise that 2024, 2023, 2022, and every other year of humanities' existence has been tough for SSLVPN appliances. Anyhow, there are new vulnerabilities (well, two of them) that are bein...
labs.watchtowr.com
November 20, 2024 at 8:21 PM
New: SonicWall is urging customers to disable SSLVPN as researchers report ransomware attacks targeting SonicWall firewalls. Particularly problematic for big companies that rely on these devices. Arctic Wolf and Huntress say it's likely a zero-day under attack but SonicWall is still investigating.
SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks | TechCrunch
Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully-patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-d...
techcrunch.com
August 5, 2025 at 1:55 PM
SonicWall says that recent Akira ransomware attacks exploiting Gen 7 firewalls with SSLVPN enabled are exploiting an older vulnerability rather than a zero-day flaw.
SonicWall finds no SSLVPN zero-day, links ransomware attacks to 2024 flaw
SonicWall says that recent Akira ransomware attacks exploiting Gen 7 firewalls with SSLVPN enabled are exploiting an older vulnerability rather than a zero-day flaw.
www.bleepingcomputer.com
August 7, 2025 at 3:28 PM
Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports. #SonicOS #SonicWall #SSLVPN www.bleepingcomputer.com/news/securit...
Over 25,000 SonicWall VPN Firewalls exposed to critical flaws
Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports.
www.bleepingcomputer.com
December 18, 2024 at 6:50 AM
GET /php/ztp_gate.php/.js.map HTTP/1.1
Host: {{Hostname}}
X-PAN-AUTHCHECK: off

GTFO! Come on, they are laughing at us now.

labs.watchtowr.com/pots-and-pan...
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
Note: Since this is 'breaking' news and more details are being released, we're updating this post as more details become available (and as we think of better memes). Mash that F5 key every so often fo...
labs.watchtowr.com
November 19, 2024 at 10:17 AM
SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups
SonicWall SSLVPN Under Attack Following the Breach of All Customers' Firewall Backups
cybersecuritynews.com
October 13, 2025 at 3:46 AM
-California regulates AI
-UK Crypt-Key goes live
-Taiwan warns of "abnormal" social media accounts
-China offers reward for Taiwan's psychological warfare unit
-Australia, UK publish annual cyber threat reports
-SonicWall SSLVPN mass-compromise
-Another surveillance provider exposed (Cyber WAP)
October 15, 2025 at 7:00 AM
Researchers warn that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, valid credentials.
SonicWall VPN accounts breached using stolen creds in widespread attacks
Researchers warn that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, valid credentials.
www.bleepingcomputer.com
October 13, 2025 at 3:59 PM
Exploiting SSLVPN vulnerabilities in Fortinet devices (CVE-2022–42475)

medium.com/@INTfinitySG...

#fortinet #infosec
December 23, 2023 at 12:23 PM
nother reason to have a dedicated firewall engineer on staff - all these vendors, and their flaws recently, are gonna help get me hired

friendly reminder, my services are available

cybersecuritynews.com/sonicwall-so...
CISA Warns of SonicWall SonicOS RCE Vulnerability Actively Exploited in the Wild
CISA has escalated warnings about a critical SonicOS SSLVPN Vulnerability zero-day vulnerability in SonicWall’s SonicOS.
cybersecuritynews.com
February 19, 2025 at 7:51 PM
So the official SonicWall mitigation leads with "turn it off" ? ooooof.
August 4, 2025 at 6:48 PM
100%

SSLVPN needs to die, hopefully Tailscale (or similar tech) adoption will kill it once and for all.
November 22, 2024 at 12:53 PM
SonicWall urges admins to patch exploitable SSLVPN bug immediately
SonicWall urges admins to patch exploitable SSLVPN bug immediately
SonicWall is emailing customers urging them to upgrade their firewall's SonicOS firmware to patch an authentication bypass vulnerability in SSL VPN and SSH management that is "susceptible to actual exploitation."
www.bleepingcomputer.com
January 8, 2025 at 7:40 PM
🦋 SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks

Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-d...
#Security
SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks | TechCrunch
Security researchers say they have evidence that ransomware gangs are hacking into large companies that rely on fully patched SonicWall firewalls. The researchers say it's likely the flaw is a "zero-day" bug currently unknown to SonicWall.
techcrunch.com
August 6, 2025 at 9:16 AM
The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices.
Akira ransomware exploiting critical SonicWall SSLVPN bug again
The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices.
www.bleepingcomputer.com
September 11, 2025 at 4:32 PM
SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances
SonicWall SSLVPN Vulnerability Let Remote Attackers Crash Firewall Appliances
cybersecuritynews.com
April 24, 2025 at 9:49 AM
⚠️📢 Der Hersteller SonicWall verzeichnet Angriffe auf seinen Gen 7 Firewalls. Weitere IT-Sicherheitsunternehmen beobachten Ransomware-Angriffe durch die Ausnutzung einer potentiellen Zero-Day Schwachstelle. Betreiber sollten schnellstmöglich handeln.
https://www.bsi.bund.de/dok/1158462
Version 1.0: SonicWall Gen 7 Firewalls - Ransomware-Angriffe beobachtet
Am 4. August 2025 bestätigte der Hersteller SonicWall bereits veröffentlichte Berichte anderer Quellen, wonach derzeit Angriffe auf seine Gen 7 Firewalls mit aktiviertem SSLVPN beobachtet werden. Arctic Wolf und Huntress hatten in diesem Zusammenhang zuvor Blogbeiträge herausgegeben, in denen die...
www.bsi.bund.de
August 5, 2025 at 4:00 PM
SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely
SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely
cybersecuritynews.com
November 21, 2025 at 6:53 AM