SonicWall says hackers are exploiting a new zero-day bug to breach customer networks

Date:

Share post:


Cybersecurity company SonicWall says hackers are exploiting a newly discovered vulnerability in one of its enterprise products to break into its customers’ corporate networks. 

SonicWall said in an advisory that the vulnerability in its SMA1000 remote access appliance, which companies use to allow their employees to remotely log in to their corporate networks as if they were in the office, allows anyone over the internet to plant malware on affected devices without needing a login for the system.

The vulnerability, tracked as CVE-2025-23006, was discovered by Microsoft and shared with SonicWall last week. In a subsequent support post, SonicWall said the vulnerability is “confirmed as being actively exploited in the wild,” indicating that some of SonicWall’s corporate customers had been hacked. The bug is known as a zero day because it was exploited before SonicWall had time to provide customers with a fix.

When contacted by TechCrunch, neither SonicWall nor Microsoft said how many companies had their networks compromised in the attacks, but urged customers to patch affected systems by installing the security hotfix that SonicWall has since released.

Several thousand SMA1000 appliances are exposed to the internet, according to a Shodan search result shared by Bleeping Computer, putting many of those companies with unpatched systems at greater risk of attacks.

Malicious hackers are increasingly targeting corporate cybersecurity products, such as firewalls, remote access tools, and VPN products. These devices exist on the perimeter of corporate networks to protect against would-be intruders and unauthorized access. But they also have a propensity to contain software bugs that can render their security protections ineffective, allowing hackers to compromise the very networks that these devices were tasked with protecting.

In recent years, some of the biggest makers of corporate cybersecurity products, including Barracuda, Check Point, Cisco, Citrix, Fortinet, Ivanti, and Palo Alto Networks, have disclosed zero-day attacks targeting their customers, which have resulted in broader network compromises. 

According to U.S. cybersecurity agency CISA, the top most routinely exploited vulnerabilities during 2023 were found in enterprise products developed by Citrix, Cisco, and Fortinet, and used by hackers to conduct operations against “high-priority targets.”



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

eBay makes it easier to find fast-shipping items and local listings

eBay announced on Thursday that it has updated its platform to help buyers find fast-shipping items and...

IBM closes $6.4B HashiCorp acquisition

IBM has finalized its multi-billion dollar HashiCorp acquisition, two days after the U.K.’s antitrust regulator gave the...

Amazon debuts Ocelot, its first quantum computing chip

Amazon Web Services (AWS) has introduced Ocelot, its first quantum computing chip. The news brings it into...

Unique, a Swiss AI platform for finance, raises $30M

A four-year-old Swiss startup has raised a sizable chunk of change to capitalize on the burgeoning “agentic...

Taktile helps fintechs build automated decision-making workflows

The automated logic behind many financial decisions — for example, decisions that determine whether a client is...

Instagram may spin off Reels into a separate app

Meta is mulling launching a standalone app for short-form videos, The Information reported, citing an anonymous source...

Apple iPhone 16e review: An A18 chip and Apple Intelligence for $599

Apple delivered its latest budget handset, the $599 iPhone 16e, without pomp. There was no big event...

Europe’s Relay pulls in $35M Series A after applying Asia’s model to delivery

Being somewhat later than Europe in adopting the idea of parcel delivery, much of Asia built its...