SonicWall hacked via zero-day flaw in remote access tools

The company admits "highly sophisticated" hackers exploited flaws in its SMA 100 series products

A hand typing on a keyboard in a malicious manner

SonicWall has admitted that it's been the target of a cyber attack which saw hackers take advantage of zero-day vulnerabilities in its secure remote access products.

The network security provider issued a statement confirming the incident after being contacted by SC Media, which received an anonymous tip that SonicWall's systems had been breached.

The company stated that it had “identified a coordinated attack on its internal systems by highly sophisticated threat actors exploiting probable zero-day vulnerabilities on certain SonicWall secure remote access products”.

The company didn’t specify when exactly the incident took place. IT Pro contacted SonicWall for a timeline of the attack but is yet to receive a response from the company.

Over the weekend, SonicWall issued an additional statement which ruled out that its NetExtender VPN Client product had been compromised, adding that the only products to remain under investigation are from the SMA 100 series which “provide Secure, Mobile and Remote Access” to SMBs. 

However, SonicWall clarified that, despite the investigation, all “SMA 100 series products may be used safely in common deployment use cases”.

The company also said that it “fully understands the challenges previous guidance had in a work-from-home environment, but the communicated steps were measured and purposeful in ensuring the safety and security of [its] global community of customers and partners”.

“As the front line of cyber defense, we have seen a dramatic surge in cyberattacks on governments and businesses, specifically on firms that provide critical infrastructure and security controls to those organizations,” it added.

Despite a decline in the number of security incidents, the last year was deemed as the worst for data breaches on record.

The news of the incident comes months after SonicWall released patches for a critical vulnerability in the SonicOS operating system, which is responsible for running SonicWall virtual private network (VPN) appliances.

Featured Resources

Defeating ransomware with unified security from WatchGuard

How SMBs can defend against the onslaught of ransomware attacks

Free download

The IT expert’s guide to AI and content management

How artificial intelligence and machine learning could be critical to your business

Free download

The path to CX excellence

Four stages to thrive in the experience economy

Free download

Becoming an experience-based business

Your blueprint for a strong digital foundation

Free download

Recommended

Microsoft brings passwordless security to consumer accounts
Microsoft Windows

Microsoft brings passwordless security to consumer accounts

16 Sep 2021
Datto launches its business continuity solution for Azure
disaster recovery (DR)

Datto launches its business continuity solution for Azure

15 Sep 2021
Smishing attacks increased 700% in first six months of 2021
scams

Smishing attacks increased 700% in first six months of 2021

14 Sep 2021
Hackers develop Linux port of Cobalt Strike for new attacks
Security

Hackers develop Linux port of Cobalt Strike for new attacks

14 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Apple patches zero-day flaw abused by infamous NSO exploit
exploits

Apple patches zero-day flaw abused by infamous NSO exploit

14 Sep 2021
Google takes down map showing homes of 111,000 Guntrader customers
data breaches

Google takes down map showing homes of 111,000 Guntrader customers

2 Sep 2021