• News/
  • https://www.theregister.com/2025/08/04/sonicwall_investigates_cyber_incidents/

SonicWall investigates 'cyber incidents,' including ransomware targeting suspected 0-day

The Register
·
Jessica Lyons
·
Published Aug 4, 2025
·
Updated

SonicWall on Monday confirmed that it's investigating a rash of ransomware activity targeting its firewall devices, following multiple reports of a zero-day bug under active exploit in its VPNs. "SonicWall is actively investigating a recent increase in reported cyber incidents involving a number of Gen 7 firewalls running various firmware versions with SSL VPN enabled," a company spokesperson told The Register. "These cases have been flagged both internally and by third-party threat research teams, including Arctic Wolf, Google Mandiant, and Huntress," the spokesperson continued. "We are working closely with these organizations to determine whether the activity is tied to a previously disclosed vulnerability or represents a zero-day vulnerability." While the firewall vendor has yet to confirm a new bug, if and when it does spot a security flaw, SonicWall promised to release updated firmware and guidance "as quickly as possible." In the meantime, the vendor urged customers using Gen 7 firewalls to disable SSL VPN services "where practical," and take the following steps to mitigate any potential intrusions: However, the vendor did warn that MFA enforcement alone may not protect against the ransomware activity under investigation. Considering that all manner of miscreants, from Chinese government cyberspies to ransomware and extortion gangs, have made a hobby of hijacking SonicWall VPNs in the past, we'd suggest implementing these mitigation measures ASAP, while keeping an eye o...

Read full article

Affected Software

2 affected components
SonicWall firewall
SonicWall VPN

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses SonicWall's investigation into a series of ransomware incidents affecting its firewall devices and a suspected 0-day vulnerability in its VPNs.

2

What security implications are discussed?

The piece highlights the potential risks associated with a zero-day vulnerability being actively exploited, putting users' devices and data at significant risk.

3

What products or software are affected?

The affected products include SonicWall Firewall and SonicWall VPN.

4

What actions is SonicWall taking in response to the incidents?

SonicWall is actively investigating the reported ransomware attacks and the associated zero-day exploit.

5

How does this impact SonicWall users?

Users of SonicWall devices may be vulnerable to attacks, and it is recommended they monitor their systems for unusual activity and apply any available security patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203