InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: SonicWall prompts password reset after a cloud backup violation affecting less than 5% of customers
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > SonicWall prompts password reset after a cloud backup violation affecting less than 5% of customers
Technology

SonicWall prompts password reset after a cloud backup violation affecting less than 5% of customers

September 18, 2025 4 Min Read
Share
SonicWall Urges Password Resets
SHARE

SonicWall urges customers to reset their credentials after the firewall configuration backup files are exposed in a security breaches affecting MySonicWall accounts.

The company said that suspicious activity targeting the firewall’s cloud backup service was recently detected, with unknown threat actors accessing backup firewall priority files stored in the cloud with less than 5% of customers.

“The credentials in the file were encrypted, but the file also contains information that allows attackers to potentially leverage the associated firewall,” the company said.

The network security company said it was unaware that these files were leaked online by threat actors, adding that it was not a ransomware event targeting the network.

“In fact, this was a series of brute force attacks aimed at gaining access to preferred files stored in backups for the possibility of further use by threat actors.” It is currently unknown who is responsible for the attack.

As a result of the incident, the company is urging its customers to follow the steps below –

  • Log in to mysonicwall.com and check if cloud backup is enabled
  • Check if the affected serial number is flagged for your account
  • Start containment and repair steps by restricting access to services from the WAN, turning off access to HTTP/HTTPS/SSH management, disabling access to SSL and IPSEC VPNs, resetting passwords and TOTPS stored in the firewall, and checking for abnormal activity logs and recent configuration changes.

Additionally, it is recommended that you import fresh configuration files provided by SonicWall into your firewall. The new configuration file contains the following changes –

  • Randomized passwords for all local users
  • If enabled, reset the TOTP binding
  • Randomized IPSEC VPN Keys
See also  China-linked Plugx and BookWorm Malware Attack Targets Asia Telecom and ASEAN Network

“The modified configuration files provided by SonicWall were created from the latest configuration files in cloud storage.” “Do not use the file if the latest configuration file does not represent the desired settings.”

This disclosure is because threat actors belonging to the Akira Ransomware group continue to target untargeted Sonic Wall devices in order to gain initial access to the target network by leveraging the security flaws of a year ago.

Earlier this week, cybersecurity company Huntress detailed an Achira ransomware incident involving the exploitation of Sonic Wall VPN, where threat actors leverage plain text files containing recovery codes for security software (MFA) to suppress incident visibility and remove endpoint protection.

“In this incident, the attacker attempted to use the exposed Huntress recovery code to log in to the Huntress portal, close active alerts, initiate an uninstallation of the Huntress EDR agent, effectively blind the organization’s defenses, and remain vulnerable to subsequent attacks.

“This level of access can be weaponized to disable defenses, manipulate detection tools, and perform malicious actions. Organizations must handle recovery codes with the same sensitivity as privileged account passwords.”

Share This Article
Twitter Copy Link
Previous Article Dead by DaylightDev is hiring for people with a generator AI experience Dead by DaylightDev is hiring for people with a generator AI experience
Next Article Confusion within FEMA as death threats distract you from the hurricane response Confusion within FEMA as death threats distract you from the hurricane response

Latest News

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated…

November 30, 2025

You Might Also Like

WhatsApp malware 'Maverick' hijacks browser sessions and targets Brazil's largest banks
Technology

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

9 Min Read
Evil malware is set in AI tools to infiltrate global organizations
Technology

Evil malware is set in AI tools to infiltrate global organizations

6 Min Read
Quantum Hacks to AI Defenses
Technology

From quantum hacks to AI defense – an expert guide to building unbreakable cyber resilience

7 Min Read
Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices
Technology

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?