Breaking
March 12, 2025

Thousands of SonicWall VPN devices are facing worrying security threats | usagoldmines.com


  • BishopFox scanned the internet for SonicWall VPNs and found hundreds of thousands that can be accessed via the internet
  • Tens of thousands were running old, vulnerable software versions
  • Some were past their end-of-life date, putting them at risk of attack

Tens of thousands of SonicWall VPN firewall platforms are vulnerable to different flaws, putting their users at risk of remote exploitation, data breaches, privilege escalation, and more.

Cybersecurity researchers at BishopFox scanned the internet with Shodan and BinaryEdge, and running proprietary scripts to analyze the returning data, discovered there were 430,363 endpoints exposed to the internet.

While this doesn’t necessarily mean they’re vulnerable, endpoints such as these ones should not be connected to the wider internet to begin with, since it means crooks could try to access them and look for holes.

End of life

“The management interface on a firewall should never be publicly exposed, as this presents an unnecessary risk,” BishopFox said in its report. “The SSL VPN interface, although designed to provide access to external clients over the internet, should ideally be protected by source IP address restrictions.”

Drilling deeper, BishopFox found that almost 120,000 endpoints were running versions affected by serious vulnerabilities, including 25,485 endpoints with critical severity flaws, and 94,018 endpoints with high severity bugs. Furthermore, they said that 20,710 endpoints were running versions of the software that are no longer supported by the vendor.

This presents a rather large attack surface that threat actors can exploit. SonicWall SSL VPN devices are often targeted in different campaigns, including the recent strikes by both Fog and Akira ransomware groups. These threat actors were abusing flaws to gain initial access to corporate networks, where they later deployed ransomware encryptors and wreaked havoc across enterprise infrastructure.

To tackle the threat, businesses should make sure they are always running the latest versions of their software, and that their endpoints are still supported by their respective vendors.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

I compared Manus AI to ChatGPT – now I understand why everyone is calling it the next DeepSeek erich...

Despite everything, US EV sales are up 28% this year Jonathan M. Gitlin | usagoldmines.com

Metallica Immersive Concert Experience Coming to Apple Vision Pro Juli Clover | usagoldmines.com

Apple Account Cards in Wallet Expanding to More Countries Juli Clover | usagoldmines.com

iPad Air M3 review roundup– should you buy Apple's new mid-range tablet? mark.wilson@futurenet.com (...

Pocket Casts makes its web player free, takes shots at Spotify and AI Kevin Purdy | usagoldmines.com

New Macs and iPads Begin Arriving to Customers Around the World Juli Clover | usagoldmines.com

Now HP printers are being bricked following firmware update | usagoldmines.com

Apple Vision Pro goes off to never never land with Metallica concert footage lance.ulanoff@futurenet...

OpenAI pushes AI agent capabilities with new developer API Benj Edwards | usagoldmines.com

X’s globe-trotting defense of ads on Nazi posts violates TOS, Media Matters says Ashley Belanger | u...

Best home office monitors 2025: Displays that get the job done | usagoldmines.com

Google: We’re Working On That ‘Receiving Media’ Issue in Messages Tim | usagoldmines.com

Seven Home Improvement Projects You Can Get Done in One Day Jeff Somers | usagoldmines.com

Bluesky Now Lets You Hide DMs From Strangers Pranay Parab | usagoldmines.com

Texas measles outbreak spills into third state as cases reach 258 Beth Mole | usagoldmines.com

How whale urine benefits the ocean ecosystem Jennifer Ouellette | usagoldmines.com

Leaked GeForce RTX 5060 and 5050 specs suggest Nvidia will keep playing it safe Andrew Cunningham | ...

Apple patches 0-day exploited in “extremely sophisticated attack” Dan Goodin | usagoldmines.com

Best external drives 2025: Backup, storage, and portability | usagoldmines.com

Microsoft’s Remote Desktop app is going away | usagoldmines.com

Update Firefox now! Extensions and streaming sites could break otherwise | usagoldmines.com

Pixel 9 is $200 Off and Starts at $599 Kellen | usagoldmines.com

Three New Things We Know About the Nintendo Switch 2 Jake Peterson | usagoldmines.com

The New iPad and iPad Air Are Already Discounted Before Their Release Daniel Oropeza | usagoldmines....

Make Sure to Update: iOS 18.3.2 and macOS Sequoia 15.3.2 Include Important Security Fixes Juli Clove...

PSA: iOS 18.3.2 Re-Enables Apple Intelligence If You Turned It Off Juli Clover | usagoldmines.com

Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date lucy.buglass@f...

Facebook engineers say bigger hard disk drives is making one critical metric far, far worse waynewil...

Six ways Microsoft’s portable Xbox could be a Steam Deck killer Kyle Orland | usagoldmines.com

Don’t have a Copilot key? Microsoft is adding a keyboard shortcut for you | usagoldmines.com

My Favorite Amazon Deal of the Day: The 13-inch M3 Apple MacBook Air Daniel Oropeza | usagoldmines.c...

Apple Releases visionOS 2.3.2 With Streaming Playback Fix Juli Clover | usagoldmines.com

Apple Releases tvOS 18.3.1 Juli Clover | usagoldmines.com

Apple Releases iOS 18.3.2 With Bug Fixes Juli Clover | usagoldmines.com

Apple Releases macOS Sequoia 15.3.2 Juli Clover | usagoldmines.com

Mac Studio Still Lacks 'High Power Mode' Offered on Some MacBook Pro and Mac Mini Models Joe Rossign...

Apple Continues Removing iOS 18 Siri Personal Context References After Delay Juli Clover | usagoldmi...

Sean Plankey selected as CISA director by President Trump | usagoldmines.com

Future PlayStation games could have AI-powered characters, if this leaked prototype of Aloy is anyth...

Still using an iPad as a Home Hub? Bad news – Apple is about to end support for it | usagoldmines.c...

Apple One's Premier subscription tier just got two new perks, but I still don't think it's worth nea...

BEVs are better than combustion: The 2025 BMW i4 xDrive40 review Jonathan M. Gitlin | usagoldmines.c...

Lorex 2K Dual Lens Indoor Pan-Tilt Wi-Fi Security Camera review | usagoldmines.com

Giant, AI ads are coming to Windows Copilot. Thanks, Microsoft | usagoldmines.com

Select Xfinity Internet Customers Get Free Xfinity Mobile Line Tim | usagoldmines.com

New iPhone 16 Colors Looking Increasingly Unlikely Hartley Charlton | usagoldmines.com

Apple Seeds Third Public Betas of iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4 Juli Clover | usagol...

This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want ...

Business investors are positive about AI’s impact on the economy | usagoldmines.com

Neil Druckmann reveals new details about Naughty Dog's Intergalactic: The Heretic Prophet, says it's...

Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – an...

'I'm like Gemma, I'm in the dark': Severance star Dichen Lachman shares disappointing filming update...

OpenAI wants to help your business build its next generation of AI agents | usagoldmines.com

New leak claims Indiana Jones and the Great Circle PS5 release will come in April | usagoldmines.co...

Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024 | usagoldmines.com

Elon Musk claims bad actors in Ukraine are behind “massive“ X cyberattack Ashley Belanger | usagoldm...

Google’s 10-year-old Chromecast is busted, but a fix is coming Ryan Whitwam | usagoldmines.com

Telecom tells employees they won’t get bonuses if they don’t follow RTO policy Scharon Harding | usa...

I spent $200/mo on ChatGPT Pro so you don’t have to. It wasn’t worth it | usagoldmines.com

Turn 1 laptop port into 5 (including 4K HDMI) with this $10 gadget | usagoldmines.com

Still using Apple’s old Home architecture? Get ready for a big change | usagoldmines.com

Asus’ newest monitors are also air purifiers, for some reason… | usagoldmines.com

X was hacked and disruptions continue, with inaccessible feeds and more | usagoldmines.com

Get Asus’ OLED laptop with 16GB RAM for just $500 today (47% off) | usagoldmines.com

Lexar’s spacious 1TB microSD card is a bargain now that it’s 45% off | usagoldmines.com

How to Keep Listening to Audio After Your Boox Palma Goes to Sleep Joel Cunningham | usagoldmines.co...

The New Photoshop iPhone App, Unpacked Lifehacker BrandX and Adobe | usagoldmines.com

The Best AI Object Erasers for Photos, Ranked David Nield | usagoldmines.com

Cruel Intentions has been canceled after one season on Prime Video, but I'm not surprised by its cru...

Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen | u...

Asus might have just changed the display game for good with three new air-purifying monitors - and o...

How Trump could potentially claw back CHIPS funding Ashley Belanger | usagoldmines.com

Beware this sneaky new ‘CAPTCHA’ that tricks you into installing malware | usagoldmines.com

Acer’s crazy RTX 4070 laptop with 32GB RAM is a stunning $550 off | usagoldmines.com

How to keep app volumes consistent in Windows 11 | usagoldmines.com

Some older Chromecasts are suddenly ‘untrusted,’ can’t cast anymore | usagoldmines.com

Here’s the wildest fake CPU I’ve ever seen — and it was sold on Amazon | usagoldmines.com

Pixel 10 Series Renders Show Off a Very Familiar Design Kellen | usagoldmines.com

The Best Free and Paid Cloud Storage Services Khamosh Pathak | usagoldmines.com

Tinker Lets You Create Custom Watch Faces for Your iPhone Pranay Parab | usagoldmines.com

Apple Arcade Adding Six New Games in April, Including RollerCoaster Tycoon and Katamari Joe Rossigno...

QuickBooks Adds Support for Tap to Pay on iPhone Hartley Charlton | usagoldmines.com

Want to buy an RX 9070 or 9070 XT but fed up of the GPUs being out of stock? AMD promises that “more...

Quordle hints and answers for Wednesday, March 12 (game #1143) | usagoldmines.com

NYT Strands hints and answers for Wednesday, March 12 (game #374) | usagoldmines.com

NYT Connections hints and answers for Wednesday, March 12 (game #640) | usagoldmines.com

Allstate sued for exposing personal customer information in plaintext | usagoldmines.com

Ending the fix/break cycle of End User Computing support | usagoldmines.com

'We will draw inspiration': Joe and Anthony Russo reveal which of Marvel's Secret Wars comic book se...

This is what it looks like when parasitic worms directly invade your brain Beth Mole | usagoldmines....

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Is the TOR network still secure? Key online anonymity tools, explained | usagoldmines.com

How to Wipe Saved Passwords From Your Web Browser Emily Long | usagoldmines.com

What People Are Getting Wrong This Week: 'Transgender Mice' Research Stephen Johnson | usagoldmines....

M4 Max and M3 Ultra Mac Studio Reviews: Apple's Most Powerful Mac Ever Hartley Charlton | usagoldmin...

Get Last-Minute Amazon Discounts on Apple's New iPad Ahead of Tomorrow's Launch Mitchel Broussard | ...

Nation-state threats are targeting UK AI research | usagoldmines.com

This new health protocol combines 40 smartwatch biomarkers and blood tests to give you a health scor...

A new SMS energy scam is using Elon Musk’s face to steal your money | usagoldmines.com

Leave a Reply