SonicWall says state-sponsored hackers behind security breach in September

In September 2023, SonicWall, a prominent cybersecurity company, disclosed a significant security breach attributed to state-sponsored hackers. The attackers exploited vulnerabilities in SonicWall's secure remote access products, impacting thousands of customers worldwide. This breach highlights the increasing sophistication and persistence of nation-state cyber adversaries targeting critical cybersecurity infrastructure. The breach was detected through SonicWall's internal security monitoring, which revealed unauthorized access to their systems. The attackers leveraged zero-day vulnerabilities and advanced persistent threat (APT) tactics to infiltrate the network, evade detection, and maintain prolonged access. SonicWall promptly issued security advisories and patches to mitigate the vulnerabilities and protect their customers. This incident underscores the critical need for organizations to adopt robust cybersecurity measures, including timely patch management, continuous monitoring, and threat intelligence sharing. It also emphasizes the growing threat landscape where state-sponsored groups focus on compromising security vendors to gain broader access to their clientele. SonicWall's response involved collaboration with law enforcement and cybersecurity experts to investigate the breach and enhance their defenses. Customers are urged to apply the latest updates and review their security configurations to prevent exploitation. The breach serves as a stark reminder of the evolving tactics employed by state-sponsored hackers and the importance of vigilance in cybersecurity practices. Organizations must remain proactive in defending against sophisticated threats to safeguard sensitive data and maintain trust in digital security solutions.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 05 Nov 2025 17:15:14 +0000


Cyber News related to SonicWall says state-sponsored hackers behind security breach in September

SonicWall says state-sponsored hackers behind security breach in September - In September 2023, SonicWall, a prominent cybersecurity company, disclosed a significant security breach attributed to state-sponsored hackers. The attackers exploited vulnerabilities in SonicWall's secure remote access products, impacting thousands ...
1 week ago Bleepingcomputer.com CVE-2023-3519 CVE-2023-3520 State-sponsored hackers
25 Best Managed Security Service Providers (MSSP) - 2025 - Pros & Cons: ProsConsStrong threat intelligence & expert SOCs.High pricing for SMBs.24/7 monitoring & rapid incident response.Complex UI and steep learning curve.Flexible, scalable, hybrid deployments.Limited visibility into endpoint ...
4 months ago Cybersecuritynews.com
Tech Security Year in Review - In this Tech Security Year in Review for 2023, let's look into the top data breaches of the past year. Each factor contributes to the growing threatscape, demanding a proactive and adaptable cybersecurity approach to safeguard your organization ...
1 year ago Securityboulevard.com
Over 178K SonicWall firewalls vulnerable to DoS, potential RCE attacks - Security researchers have found over 178,000 SonicWall next-generation firewalls with the management interface exposed online are vulnerable to denial-of-service and potential remote code execution attacks. These appliances are affected by two DoS ...
1 year ago Bleepingcomputer.com CVE-2022-22274 CVE-2023-0656
SonicWall Confirms That Hackers Stole Encrypted Customer Data in 2021 Breach - In late 2021, SonicWall, a prominent cybersecurity company, confirmed that hackers successfully stole encrypted customer data during a significant breach. This incident has raised concerns about the security of encrypted data and the methods threat ...
1 month ago Cybersecuritynews.com CVE-2021-20016 UNC2447
178K+ SonicWall Firewalls Vulnerable to DoS, RCE Attacks - Two unauthenticated denial-of-service vulnerabilities are threatening the security of SonicWall next-generation firewall devices, exposing more than 178,000 of them to both DoS as well as remote code execution attacks. SonicWall products affected are ...
1 year ago Darkreading.com CVE-2022-22274 CVE-2023-0656
SonicWall Accelerates SASE Offerings; Acquires Proven Cloud Security Provider - PRESS RELEASE. MILPITAS, Calif. - January 3, 2024 - SonicWall, a global cybersecurity leader, today announced the acquisition of Banyan Security, a leading provider of security service edge solutions for the modern workforce. This acquisition ...
1 year ago Darkreading.com
Analyzing the SonicWall Custom Grub LUKS Encryption Modifications - During our initial analysis of a virtual machine image for the application, we discovered a customized LUKS encryption mechanism meant to hinder reverse engineering of the application. We were able to recover the LUKS decryption key by leveraging ...
1 year ago Securityboulevard.com
Law Firms and Legal Departments Get Singled Out For Cyberattacks - Cyberattackers are doubling down on their attacks against law firms and corporate legal departments, moving beyond their historical activity of hacking and leaking secrets to targeting the sector with financial attacks, such as ransomware and ...
1 year ago Darkreading.com LockBit
Data Breach Response: A Step-by-Step Guide - In today's interconnected world, organizations must be prepared to respond swiftly and effectively in the face of a data breach. To navigate these challenges, a well-defined and comprehensive data breach response plan is essential. Let's explore the ...
1 year ago Securityzap.com
SonicWall Firewall Backups Stolen by Nation-State Actor - A recent cyberattack has targeted SonicWall firewall backups, with a nation-state actor believed to be behind the breach. This incident highlights the increasing sophistication of cyber threats against critical network infrastructure. SonicWall, a ...
6 days ago Darkreading.com nation-state actor
Former Uber CISO Speaks Out, After 6 Years, on Data Breach, SolarWinds - Joe Sullivan arrived at his sentencing hearing on May 4 this year, prepared to go to jail had the judge not gone with a parole board's recommendation of probation. A federal jury convicted the former Uber CISO months earlier on two charges of fraud ...
1 year ago Darkreading.com
SonicWall SMA1000 Vulnerability Let Attackers to Exploit Encoded URLs To Gain Internal Systems Access Remotely - SonicWall has issued a high-priority security advisory (SNWLID-2025-0010) revealing a critical Server-Side Request Forgery (SSRF) vulnerability in its SMA1000 Appliance Work Place interface. Discovered by security researcher Ronan Kervella of ...
5 months ago Cybersecuritynews.com
Hackers Leverage Compromised Third-Party SonicWall SSL VPN to Breach Networks - Cybersecurity researchers have uncovered a new wave of cyberattacks exploiting compromised third-party SonicWall SSL VPN appliances. Attackers are leveraging these vulnerabilities to gain unauthorized access to corporate networks, leading to data ...
2 months ago Cybersecuritynews.com CVE-2021-20016 CVE-2023-20036 UNC2447
FTC orders Blackbaud to boost security after massive data breach - Blackbaud has settled with the Federal Trade Commission after being charged with poor security and reckless data retention practices, leading to a May 2020 ransomware attack and a data breach affecting millions of people. Blackbaud is a U.S.-based ...
1 year ago Bleepingcomputer.com
178,000 SonicWall firewalls are vulnerable to old DoS bugs The Register - More than 178,000 SonicWall firewalls are still vulnerable to years-old vulnerabilities, an infosec reseacher claims. A study by Jon Williams, senior security engineer at Bishop Fox, this week highlights what he refers to as weapons-grade patch ...
1 year ago Go.theregister.com CVE-2022-22274 CVE-2023-0656
Hackers Compromise Intelligence Website Used by CIA and Other Agencies - As federal investigators continue their work, the dual breaches of critical intelligence infrastructure highlight the sophisticated and persistent nature of foreign cyber threats targeting America’s most sensitive defense and intelligence ...
3 months ago Cybersecuritynews.com Abyss
Russian hackers stole Microsoft corporate emails in month-long breach - Microsoft disclosed Friday night that some of its corporate email accounts were breached and data stolen by the Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12th, with Microsoft initiating its ...
1 year ago Bleepingcomputer.com APT29
Russian hackers stole Microsoft corporate emails in month-long breach - Microsoft disclosed Friday night that some of its corporate email accounts were breached and data stolen by the Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12th, with Microsoft initiating its ...
1 year ago Bleepingcomputer.com APT29
HPE: Russian hackers breached its security team's email accounts - Hewlett Packard Enterprise disclosed today that suspected Russian hackers known as Midnight Blizzard gained access to the company's Microsoft Office 365 email environment to steal data from its cybersecurity team and other departments. Midnight ...
1 year ago Bleepingcomputer.com Cozy Bear APT29
180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE - The majority of internet-exposed SonicWall next-generation firewall series 6 and 7 devices have not been patched against two potentially serious vulnerabilities, cybersecurity firm Bishop Fox reports. The issues, tracked as CVE-2022-22274 and ...
1 year ago Securityweek.com CVE-2022-22274 CVE-2023-0656
North Korean hackers exploit critical TeamCity flaw to breach networks - Microsoft says that the North Korean Lazarus and Andariel hacking groups are exploiting the CVE-2023-42793 flaw in TeamCity servers to deploy backdoor malware, likely to conduct software supply chain attacks. In September, TeamCity fixed a critical ...
1 year ago Bleepingcomputer.com CVE-2023-42793 Andariel
SonicWall SMA VPN devices targeted in attacks since January - A remote code execution vulnerability affecting SonicWall Secure Mobile Access (SMA) appliances has been under active exploitation since at least January 2025, according to cybersecurity company Arctic Wolf. Days after SonicWall tagged the security ...
6 months ago Bleepingcomputer.com CVE-2021-20035
SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild - The surge in attacks follows the public release of proof-of-concept (PoC) exploit code on February 10, 2025, by researchers at Bishop Fox, amplifying risks for organizations with unpatched devices. Security analysts attribute the rapid weaponization ...
8 months ago Cybersecuritynews.com CVE-2024-53704 Akira
SonicWall OS Command Injection Vulnerability Exploited in the Wild - “During further analysis, SonicWall and trusted security partners identified that ‘CVE-2023-44221 – Post Authentication OS Command Injection’ vulnerability is potentially being exploited in the wild,” SonicWall stated in ...
6 months ago Cybersecuritynews.com CVE-2023-44221

Cyber Trends (last 7 days)