Active Exploitation of SonicWall VPNs
A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours…
Sources
- T1Active Exploitation of SonicWall VPNsHuntress