Cybersecurity company SonicWall is urging its customers to disable SSL VPN on its latest line of firewall appliances after security researchers reported an increase in ransomware incidents targeting SonicWall customers.
See also: SonicWall patches critical SMA 100 vulnerability

In a statement this week, SonicWall said it has seen a “significant increase” in security incidents targeting Generation 7, where customers have SSL VPN (virtual private network) enabled. The company said it is “actively investigating these incidents to determine whether they are related to a previously disclosed vulnerability or whether a new vulnerability may be responsible.”
The company's warning comes as security researchers say they have identified hackers targeting SonicWall devices to gain initial access to a victim's network.
Hackers are increasingly targeting enterprise products like firewalls and VPNs, which act as digital gatekeepers, allowing legitimate employees access to a company's network. However, security weaknesses in these products can allow malicious hackers to gain entry, allowing attackers to launch data-stealing or destructive attacks.
See also: SonicWall SMA appliances compromised with OVERSTEP rootkit
Security firm Arctic Wolf said it has seen breaches targeting SonicWall customers since mid-July. The company said “available evidence indicates the existence of a zero-day vulnerability,” referring to a security flaw that was discovered and exploited before the vendor could patch the problem.

Researchers reported that they observed a short interval between the exploitation of the SonicWall firewall and the subsequent deployment of -encrypting , or ransomware.
Huntress Labs, another cybersecurity firm, said it was "likely" that a zero-day flaw in SonicWall firewalls is responsible for the attacks and warned that hackers exploiting the flaw have been observed gaining access to a company's domain controllers, which manage the devices and users on that network.
See also: SonicWall: Fake NetExtender steals VPN credentials
In its blog, Huntress said it believes the Akira ransomware gang is behind some of the attacks targeting SonicWall customers. Akira is known to target enterprise products, such as Fortinet firewalls , to penetrate large networks.
"This is a critical, ongoing threat," Huntress wrote.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
