• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-urges-admins-to-disable-sslvpn-amid-rising-attacks/

SonicWall urges admins to disable SSLVPN amid rising attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 5, 2025
·
Updated

SonicWall has warned customers to disable SSLVPN services due to ransomware gangs potentially exploiting an unknown security vulnerability in SonicWall Gen 7 firewalls to breach networks over the past few weeks. The warning comes after Arctic Wolf Labs reported on Friday that it had observed multiple Akira ransomware attacks, likely using a SonicWall zero-day vulnerability, since July 15th. "The initial access methods have not yet been confirmed in this campaign," the Arctic Wolf Labs researchers said. "While the existence of a zero-day vulnerability is highly plausible, credential access through brute force, dictionary attacks, and credential stuffing have not yet been definitively ruled out in all cases." Arctic Wolf also advised SonicWall administrators on Friday to temporarily disable SonicWall SSL VPN services due to the strong possibility that a SonicWall zero-day vulnerability was being exploited in these attacks. Cybersecurity company Huntress has also confirmed Arctic Wolf's findings on Monday and published a report providing indicators of compromise (IOCs) collected while investigating this campaign. "A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware," Huntress warned. "Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach." The same day, SonicWall con...

Read full article

Affected Software

2 affected components
SonicWall Gen 7 firewalls
SonicWall SSL VPN

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses SonicWall's warning to disable SSLVPN services due to increasing ransomware attacks exploiting a security vulnerability.

2

What security implications are discussed in the article?

The article highlights the risk of ransomware gangs using an unknown vulnerability in SonicWall Gen 7 firewalls to breach networks.

3

What products or software are affected according to the article?

The affected products include SonicWall Gen 7 firewalls and SonicWall SSL VPN.

4

What actions does SonicWall recommend to its users?

SonicWall recommends that administrators disable SSLVPN services on their devices to mitigate the risk.

5

Why is the warning urgent for administrators?

The warning is urgent due to the rising number of attacks leveraging the security vulnerability in recent weeks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203