Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks
News

Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks

Team-CWDBy Team-CWDOctober 18, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


SonicWall on Wednesday disclosed that an unauthorized party accessed firewall configuration backup files for all customers who have used the cloud backup service.

“The files contain encrypted credentials and configuration data; while encryption remains in place, possession of these files could increase the risk of targeted attacks,” the company said.

It also noted that it’s working to notify all partners and customers, adding it has released tools to assist with device assessment and remediation. The company is also urging users to log in and check for their devices.

The development comes a couple of weeks after SonicWall urged customers to perform a credential reset after their firewall configuration backup files were exposed in a security breach impacting MySonicWall accounts.

The list of impacted devices available on the MySonicWall portal has been assigned a priority level to help customers prioritize remediation efforts. The labels are as follows –

  • Active – High Priority: Devices with internet-facing services enabled
  • Active – Lower Priority: Devices without internet-facing services
  • Inactive: Devices that have not pinged home for 90 days

The latest post-mortem marks an about turn from its initial assessment when it claimed the threat actors accessed backup firewall preference files stored in the cloud for less than 5% of its customers. It also stated that while the credentials within those files were encrypted, they also included “information that could make it easier for attackers to potentially exploit the related firewall.”

It’s currently not known how many of its customers use the cloud backup service. SonicWall has yet to reveal when the attacks began or who is behind the activity. However, the company said it has since “hardened” its infrastructure, applied additional logging, and introduced stronger authentication controls to prevent a repeat.

Users are advised to follow the steps below with immediate effect –

  • Log in to MySonicWall.com account and verify if cloud backups exist for registered firewalls
  • If fields are blank, there is no impact
  • If fields contain backup details, verify whether impacted serial numbers are listed in the account
  • If Serial Numbers are shown, users should follow the containment and remediation guidelines for the listed firewalls

SonicWall said in cases where customers have used the Cloud Backup feature but no Serial Numbers are shown or only some of the registered Serial Numbers are displayed, it will provide additional guidance in coming days.

“A brute-force attack was conducted against their cloud backup API service, giving the threat actor access to a treasure trove of sensitive data, including firewall rules, encrypted credentials, routing configurations and more,” Ryan Dewhurst, head of Proactive Threat Intelligence at watchTowr, told The Hacker News. “This raises questions about why the vendor didn’t implement basic protections like rate limiting and stronger controls around public APIs.”

“Although the passwords were encrypted, attackers have all the time in the world to crack them offline at their leisure. If the passwords used were weak in the first place, it’s almost certain that the threat actor has the plaintext versions already. If the threat actor is unable to crack the passwords, you’re not out of the woods, as the information leaked will help in more complex targeted attacks.”



Source

computer security cyber attacks cyber news cyber security news cyber security news today cyber security updates cyber updates data breach hacker news hacking news how to hack information security network security ransomware malware software vulnerability the hacker news
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleProsper Data Breach Exposes 17 Million Customers’ Personal Info
Next Article UK, US Sanction Southeast Asia-Based Online Scam Network
Team-CWD
  • Website

Related Posts

News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What are brushing scams and how do I stay safe?

December 24, 2025

Here’s what you should know

February 6, 2026

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.