Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SonicWall

SonicWall Vendor Cyber Rating & Cyber Score

bit.ly

For more than 30 years, SonicWall is a partner-first unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments. Today, SonicWall delivers a unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments, providing the protection, visibility and operational resilience that modern businesses demand.  Today, SonicWall delivers a unified cybersecurity portfolio that helps SMBs, MSPs, and IT teams consolidate network, endpoint, cloud, and threat response across hybrid environments, providing the protection, visibility and operational resilience that modern


SonicWall A.I CyberSecurity Scoring

SonicWall
Company Information
Website:https://bit.ly/4mqYSV6
Employees number:1,958
Number of followers:128,529
NAICS:541514
Industry Type:Computer and Network Security
Homepage:bit.ly
SonicWall Risk Score (AI oriented)
Between 0 and 549
logo
SonicWallComputer and Network Security
Updated:
31/07/2026
100/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SonicWall Global Score (TPRM)
xxxx
logo
SonicWallComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SonicWall
SonicWallCritical
Current Score
100C (CRITICAL)
01000
31 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
100Before Incident
JULY 2026
100Before Incident
Cyber Attack
29 Jul 2026SonicWall
SonicWall: Huntress warns about attack spree that hit 30 SonicWall customers in 2 days

SonicWall VPN and Firewall Accounts Hit by Rapid Credential Stuffing Attack

100After Incident
CRITICAL0
SON1785450554
SonicWall VPN and Firewall Accounts Hit by Rapid Credential Stuffing Attack Huntress researchers uncovered an active credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in under 48 hours. The attacks, which began on Saturday, escalated quickly, breaching 92 unique user accounts within 41 hours before abruptly stopping on Monday. The campaign appeared broad and opportunistic, affecting various SonicWall devices without targeting specific industries. Attackers leveraged validated credentials against remote access portals, though the exact source whether stolen logs, prior breaches, or unpatched vulnerabilities remains unclear. Notably, no post-compromise activity has been observed, suggesting the intrusions may be pre-positioning for future attacks. Huntress’s findings are based on telemetry from its customer base, meaning the true scope of affected organizations could be larger. SonicWall has yet to issue an official advisory, though a spokesperson confirmed an ongoing investigation. This incident follows a pattern of persistent threats against SonicWall devices. In 2025, an undisclosed state-sponsored actor breached SonicWall’s cloud environment, stealing firewall configurations for all customers. The company has also faced multiple zero-day exploits, including two actively exploited flaws patched earlier this month after a three-week window of exposure. Since late 2021, 17 SonicWall vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities Catalog, with 10 linked to ransomware attacks, including a recent surge by the Akira ransomware group. Edge devices like SonicWall firewalls remain a prime target, accounting for over 70% of active intrusions tracked by Huntress, particularly in ransomware deployments. The attack underscores the risks of unsecured remote access solutions and the ongoing challenges of defending against credential-based threats.
INCIDENT DETAILS -
TYPE
Credential Stuffing
MOTIVATION
Pre-positioning for future attacks
IMPACT
Systems Affected: SonicWall VPN and firewall accounts
DATA BREACH
Number Of Records Exposed: 92 unique user accounts
JULY 2026
100Before Incident
Vulnerability
22 Jul 2026SonicWall
Check Point: CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks

Critical Check Point Authentication Flaw Actively Exploited in the Wild

100After Incident
CRITICAL0
CHE1784787889
Critical Check Point Authentication Flaw Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about CVE-2026-16232, a critical authentication vulnerability in Check Point SmartConsole that is being actively exploited. The flaw, rated 9.3 on the CVSS scale, affects Check Point Security Management and Multi-Domain Management platforms, allowing unauthenticated remote attackers to obtain an application login token and gain full administrative access to affected systems. The vulnerability was discovered during an internal BLAST (Business Logic Attack Surface Testing) review under Check Point’s Frontier AI Readiness Program. Exploitation has been confirmed in real-world attacks, though limited to environments where management interfaces are exposed to the internet without IP-based restrictions. Attackers could leverage this access to modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks, risking full infrastructure compromise. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the need for immediate patching. Affected versions include R81.10, R81.20, R82, and R82.10, with older versions also potentially vulnerable. Check Point has released a Jumbo Hotfix (July 22, 2026) to remediate the issue and strengthen system resilience. In the same advisory, Check Point disclosed two additional high-severity vulnerabilities: - CVE-2026-62144 (CVSS 9.3): Another authentication bypass and privilege escalation flaw in management systems, though not yet exploited. - CVE-2026-62145 (CVSS 7.5): A local privilege escalation issue in GaiaOS WebUI, currently unexploited. Security teams are advised to restrict SmartConsole and management access to trusted IP addresses, enforce firewall protections, and monitor for indicators of compromise, including: - 151.241.99[.]207 - 151.241.99[.]233 - 158.62.198[.]182 - 192.142.10[.]99 - 139.28.37[.]250 - 194.213.18[.]137 The incident underscores the risks of exposed management interfaces and the necessity of proactive patching, strict access controls, and continuous monitoring to mitigate evolving threats.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Systems Affected: Check Point Security Management and Multi-Domain Management platformsOperational Impact: Full administrative access, modification of security policies, deployment of malicious configurations, potential full infrastructure compromise
JULY 2026
100Before Incident
Vulnerability
15 Jul 2026SonicWall
SonicWall, Oracle, Microsoft, KNX Association, AsyncAPI and Cisco: Ernst & Young (EY) - Security Affairs

Cybersecurity Roundup: Critical Vulnerabilities, Supply Chain Attacks, and Major Breaches

100After Incident
CRITICAL0
CISSONMICORAASYKNX1784341544
Cybersecurity Roundup: Critical Vulnerabilities, Supply Chain Attacks, and Major Breaches The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with new entries, including a KNX Association protocol flaw (Connection Authorization Option 1) and multiple Oracle, SonicWall, Microsoft, and Cisco IOS vulnerabilities. These additions highlight active exploitation risks, urging organizations to prioritize patching. In a supply chain attack, malicious actors injected malware into AsyncAPI npm packages, which collectively see 2 million weekly downloads. The compromised packages could expose developers to data theft or further compromise. Lidl disclosed a data breach affecting online shop customers in Germany, Belgium, and the Netherlands, though details on the scope and impact remain limited. Microsoft’s July 2026 Patch Tuesday set a record with 621 CVEs addressed, marking the largest security update in its history. The fixes span critical vulnerabilities across Windows, Office, and other enterprise products. The U.S. Treasury sanctioned a VPN provider and cryptor seller linked to billions in ransomware losses, targeting infrastructure used by cybercriminals to evade detection and launder payments. Japan faced multiple cyber incidents, including a malware attack on Nihon Kotsu, the country’s largest taxi operator, which temporarily suspended services. Additionally, Nichirei, a major food company, confirmed a cyberattack, though operational disruptions were not disclosed. Ernst & Young (EY) is investigating a data breach involving third-party support tickets, raising concerns over unauthorized access to sensitive client information. Two members of the Scattered Spider hacking group were sentenced for their role in a £29 million cyberattack on Transport for London (TfL), underscoring the group’s financial motivations and persistent threat to critical infrastructure. A new Russian cyber campaign was uncovered, distributing fake Webex and Zoom installers to deploy Starland RAT, a remote access trojan used for espionage and data exfiltration. Security researchers identified CrashStealer, a macOS infostealer leveraging signed apps to bypass Gatekeeper protections, and TuxBot v3, an AI-powered IoT botnet with documented flaws but potential for large-scale attacks. The EU imposed sanctions on FSB-linked hackers for cyber sabotage, targeting state-backed actors behind disruptive campaigns. A Chinese cyber espionage group was found using Claude and DeepSeek AI models to enhance malware development, including a custom PowerShell reconnaissance tool. SonicWall warned of active exploitation of two SMA 1000 zero-day vulnerabilities, while Zoom patched CVE-2026-53412, a critical account takeover flaw that could allow unauthorized access to user sessions.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationSupply Chain AttackData BreachRansomwareMalware AttackCyber Espionage
MOTIVATION
Financial GainEspionageData TheftSabotage
IMPACT
Financial Loss: £29 million (Scattered Spider attack on TfL)Customer data (Lidl)Sensitive client information (EY)Personally identifiable information (various breaches)Nihon Kotsu taxi servicesNichirei food company systemsTransport for London (TfL)Downtime: Temporary suspension of Nihon Kotsu servicesService disruptions (Nihon Kotsu)Unauthorized access (EY)LidlEYNihon KotsuNichireiLidl customersEY clients
DATA BREACH
Customer dataSensitive client informationPersonally identifiable informationHigh (PII, client data)Lidl customer dataEY client data
JUNE 2026
100Before Incident
MAY 2026
100Before Incident
APRIL 2026
100Before Incident
Vulnerability
01 Apr 2026SonicWall
SonicWall and Fortinet: Ransomware Groups Increasingly Deploy EDR Kill Techniques

Ransomware Tactics Evolve: EDR-Kill Becomes Standard as AI and Speed Reshape Attacks

100After Incident
CRITICAL0
SONFOR1785147921
Ransomware Tactics Evolve: EDR-Kill Becomes Standard as AI and Speed Reshape Attacks A new report from Halcyon reveals a sharp escalation in ransomware sophistication, with attackers increasingly disabling endpoint detection and response (EDR) tools a tactic once reserved for advanced groups now standard across the ecosystem. Published on July 27, the Q2 2026 Ransomware Evolution Report highlights how ransomware operations are becoming faster, more automated, and harder to detect, despite a 5.7% quarterly decline in publicly claimed attacks. Key Trends in Q2 2026 During the quarter, 89 active ransomware groups executed 1,988 attacks across 101 countries. While overall attack volume dipped, tactics grew more aggressive. Leading groups Qilin (293 attacks), The Gentlemen (214), DragonForce (143), Akira (119), and LockBit 5.0 (102) prioritized speed, with some achieving initial breach to encryption in under an hour. The Gentlemen, a rising threat, has rapidly refined its arsenal by reverse-engineering techniques from groups like Babuk, Qilin, and Medusa, incorporating their strongest encryption and evasion methods. Targeted Sectors and Exploited Vulnerabilities Manufacturing bore the brunt of attacks (19.8%), followed by construction, business services, retail, and software. Ransomware groups exploited critical flaws in enterprise edge devices, including Citrix NetScaler ADC/Gateway (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591). Emerging groups like KryBit, Payload, PEAR, and World Leaks also reemerged, signaling a broadening threat landscape. AI’s Role in Ransomware Operations AI is no longer experimental for ransomware actors. Halcyon observed its integration across the attack chain, from malware disguised as AI productivity tools (e.g., EvilAI) to AI-assisted negotiations and even agentic ransomware capable of autonomous intrusion stages. The shift underscores how threat actors are leveraging automation to outpace defenses. State-Linked Ransomware and EDR Evasion The report also noted growing evidence of Iran-linked actors disguising espionage as ransomware operations, blurring the line between criminal and state-sponsored activity. Meanwhile, the democratization of EDR-kill techniques now a staple among top groups has slashed defenders’ response windows, forcing a reevaluation of traditional security controls. Halcyon’s findings paint a stark picture: ransomware is evolving into a more adaptive, AI-driven threat, with attackers systematically dismantling defenses before encryption even begins.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainEspionage (state-linked actors)
DATA BREACH
Data Encryption: Yes
MARCH 2026
100Before Incident
FEBRUARY 2026
100Before Incident
JANUARY 2026
100Before Incident
Ransomware
01 Jan 2026SonicWall
SonicWall: UK manufacturing hit by ransomware surge, SonicWall says

UK Manufacturing Hit Hardest by Ransomware as Attacks Surge 28%

100After Incident
CRITICAL0
SON1785487061
UK Manufacturing Hit Hardest by Ransomware as Attacks Surge 28% UK manufacturing has emerged as the most targeted sector for ransomware attacks, with 1.84 million incidents recorded between January and May 2025, according to SonicWall. The data, gathered from 364 specialized sensors in industrial environments, reveals a sharp rise in cyber threats against factories, contrasting with declining extortion attempts in other sectors. Nearly all ransomware activity 1.79 million hits was attributed to the Filecoder malware family, with attacks heavily concentrated on just two sensors, suggesting a targeted approach rather than broad sector-wide campaigns. In addition to ransomware, sensors logged 15.8 million intrusion attempts and 12.2 million malware threats, indicating persistent probing of industrial networks. Key vulnerabilities exploited by attackers include: - Apache Log4j flaws, generating 1.1 million hits across 34% of monitored sensors, exposing unpatched SCADA, MES, and ERP systems. - React Server Components RCE vulnerabilities, detected in 45% of sensors, targeting modern web-based operational dashboards. - Legacy infrastructure risks, as manufacturers struggle to patch older systems due to production downtime concerns. Unlike other sectors, IoT-related attacks were less prevalent, with only 230,000 hits recorded, as threat actors prioritized application vulnerabilities over connected devices. The surge in attacks reflects the unique challenges of securing industrial environments, where operational technology (OT) systems often tied to physical production processes are difficult to patch without disrupting operations. Meanwhile, the adoption of internet-facing tools, such as customer portals and digital dashboards, has expanded the attack surface, often without equivalent security controls. SonicWall’s EMEA Executive Vice President, Spencer Starkey, noted the distinct tactics used against UK manufacturing: "Attackers see factory floors as prime extortion targets, where downtime means lost revenue and supply chain chaos." He highlighted the dual risk of unpatched legacy systems and rapidly scanned new digital frameworks, complicating cybersecurity efforts for manufacturers.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Extortion
IMPACT
SCADAMESERP systemsOperational dashboardsDowntime: Production downtimeOperational Impact: Lost revenue and supply chain chaosRevenue Loss: Lost revenue
DATA BREACH
Data Encryption: Yes (Filecoder malware)
Vulnerability
01 Jan 2026SonicWall
Fortinet and SonicWall: Ransomware reaches elevated ‘new normal’ as attack volumes hold steady into 2026, reshape baseline risk expectations

Ransomware Activity Stabilizes at Elevated Levels in Q1 2026, Shifting Tactics and Targets

100After Incident
CRITICAL0
FORSON1776335417
Ransomware Activity Stabilizes at Elevated Levels in Q1 2026, Shifting Tactics and Targets The first quarter of 2026 marked a period of sustained ransomware activity, with attack volumes remaining steady compared to both the previous quarter and the same period in 2025, according to GuidePoint Security’s Ransomware and Cyber Threat Insights report. After a late-2025 surge, the threat landscape has settled into a "new normal," with no significant spikes or declines in victim counts or active ransomware groups. ### Key Trends in Ransomware Activity The most active ransomware group, Qilin, claimed 361 victims a 25% drop from its Q4 2025 peak of 484. Meanwhile, The Gentlemen, a relative newcomer that ranked 16th in Q4 2025 with just 35 victims, surged to 182 victims, becoming the second-most active group. Akira, another long-standing player, saw a 22% decline in activity (from 226 to 176 victims), likely due to the waning effectiveness of its exploitation of SonicWall SSL VPN vulnerabilities. Clop continued its prolonged extortion campaign, posting victims in Q1 2026 from breaches that occurred in late 2025 a tactic consistent with its history of stretching out disclosures over months. ### Geographic and Sector Shifts The U.S. remained the top target, accounting for 51% of all ransomware victims (1,084 incidents), followed by the U.K. and Canada (4% each, 88 incidents). Thailand entered the top 10 for the first time, signaling growing ransomware impacts in developing economies. Brazil and India also remained frequent targets, reflecting persistent threats to emerging markets. While manufacturing remained the most targeted sector, construction saw a 44% year-over-year increase, pushing it into the top five. This shift suggests attackers are expanding into industries with weaker cybersecurity defenses but valuable operational data. ### Evolving Tactics: Extortion Over Encryption Ransomware groups are increasingly abandoning traditional encryption-based attacks in favor of data theft and extortion-only operations. This approach reduces operational complexity while maintaining pressure on victims through the threat of public data leaks. ### Emerging and Declining Threat Groups - NightSpire, a financially motivated group operating since 2025, claimed 74 victims in Q1 2026 alone, primarily targeting SMBs with unpatched FortiOS/FortiProxy vulnerabilities (CVE-2024-55591). The group relies on living-off-the-land tools (PowerShell, PsExec, WMI) to evade detection. - Scattered Spider, LAPSUS$, and ShinyHunters rebranded under the unified banner "Scattered LAPSUS$ Hunters" in August 2025, though the move reflected overlapping membership rather than a true merger. The group remains highly efficient, compressing attack timelines to 24–48 hours and has been linked to over $66 million in extortion demands since 2022. - Akira, one of the longest-operating RaaS groups (active since 2023), saw its victim count drop after peaking in Q4 2025, likely due to declining exploitation of SonicWall flaws. ### AI Supply Chain Attack Highlights New Risks In February 2026, VirusTotal reported the first large-scale supply chain attack on an AI platform, targeting OpenClaw’s skills marketplace. Attackers published 314 malicious "skills" automation tools disguised as legitimate software that delivered information-stealing malware. The incident underscored the growing risks of agentic AI systems, which rely on instruction-based (rather than code-based) extensions, making traditional malware detection less effective. ### Outlook: Stability with Potential Disruptions While Q1 2026 saw no major shifts in overall ransomware volume, GuidePoint warned that periods of stability have historically been short-lived. The report noted that law enforcement actions, internal conflicts, or new group formations could disrupt the current equilibrium. Additionally, a mid-year "summer slowdown" a recurring dip in victim claims between Q2 and Q3 may temporarily reduce activity before potential resurgences later in the year.
INCIDENT DETAILS -
TYPE
ransomwaredata extortionsupply chain attack
MOTIVATION
financial gaindata theftextortion
IMPACT
Financial Loss: > $66 million (Scattered LAPSUS$ Hunters since 2022)Data Compromised: data theft and extortion; personally identifiable information (PII) at riskFortiOS/FortiProxySonicWall SSL VPNOpenClaw AI skills marketplaceOperational Impact: operational disruptions in targeted sectors (e.g., manufacturing, construction)Brand Reputation Impact: potential reputational damage due to data leaksIdentity Theft Risk: high (due to PII exposure)
DATA BREACH
personally identifiable information (PII)operational dataproprietary informationSensitivity Of Data: highpartial (ransomware attacks)none (extortion-only attacks)
Vulnerability
01 Jan 2026SonicWall
SonicWall: Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild

SonicWall SMA1000 Series Hit by Actively Exploited Zero-Day Vulnerabilities

100After Incident
CRITICAL0
SON1784219373
SonicWall SMA1000 Series Hit by Actively Exploited Zero-Day Vulnerabilities SonicWall recently disclosed two critical vulnerabilities in its SMA1000 Series remote access appliances, one of which was already under active exploitation before the advisory was published. The flaws CVE-2026-15409 (a server-side request forgery bug with a CVSS score of 10.0) and CVE-2026-15410 (a high-severity local privilege escalation flaw) have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming real-world attacks. The exploit chain begins with the /wsproxy websocket proxy feature in SonicWall’s WorkPlace application, which attackers manipulate to redirect traffic to internal services. By targeting an Erlang process on port 1050 which uses a hardcoded authentication cookie threat actors achieve unauthenticated remote code execution (RCE). From there, they escalate privileges to root access by exploiting a path traversal flaw in the remove_hotfix workflow, allowing arbitrary script execution. Affected models include SMA1000 Series 6210, 7210, and 8200v running firmware versions 12.4.3-03434 and 12.5.0-02800. SonicWall firewalls and the SMA 100 Series are not impacted. Attacker Activity & Impact Rapid7 researchers observed threat actors leveraging compromised appliances as stealthy entry points into corporate networks. Post-exploitation, attackers harvested credentials, session data, and TOTP MFA seeds, then pivoted into Active Directory environments. Unusual login patterns including authentications from non-corporate devices (e.g., "kali") originating from the appliance itself served as key indicators of compromise. Mitigation & Indicators of Compromise (IOCs) SonicWall has released patches (12.4.3-03453 or 12.5.0-02835) to address the flaws, with no workarounds available. Organizations are advised to assume compromise if suspicious activity is detected, including: - Unusual /wsproxy requests - Abnormal remove_hotfix calls - Unexpected NTLM logons from the appliance’s internal IP Public proof-of-concept exploits for CVE-2026-15409 are already circulating, and a Metasploit module is reportedly in development, increasing the likelihood of widespread attacks. Attacker Infrastructure Observed malicious activity has been linked to the following IP ranges: - 45.131.194.0/24 - 45.146.54.0/24 - 63.135.161.0/24 - 173.239.211.0/24 - Specific IPs: 193.37.32[.]179, 193.37.32[.]214, 216.73.163[.]151, 216.73.163[.]158
INCIDENT DETAILS -
TYPE
Zero-Day ExploitationRemote Code ExecutionPrivilege Escalation
IMPACT
CredentialsSession dataTOTP MFA seedsSystems Affected: SMA1000 Series 6210, 7210, and 8200v running firmware versions 12.4.3-03434 and 12.5.0-02800Operational Impact: Compromised appliances used as stealthy entry points into corporate networks; pivoting into Active Directory environmentsIdentity Theft Risk: High (due to harvested credentials and MFA seeds)
DATA BREACH
CredentialsSession dataTOTP MFA seedsSensitivity Of Data: HighPersonally Identifiable Information: Yes (credentials, MFA seeds)
DECEMBER 2025
100Before Incident
Vulnerability
15 Dec 2025SonicWall
Ivanti, SonicWall and Cisco: Vulnerability exploitation surges often precede disclosure, offering possible early warnings

Exploitation Surges Preceding Vulnerability Disclosures (Dec 2025 - Mar 2026)

100After Incident
CRITICAL0
IVASONCIS1776702475
GreyNoise Report: Exploitation Surges Often Precede Vulnerability Disclosures by Weeks A recent report from threat intelligence firm GreyNoise reveals that hackers frequently begin exploiting software vulnerabilities before vendors publicly disclose them sometimes weeks in advance. Analyzing attack patterns between mid-December 2025 and late March 2026, GreyNoise found that nearly half of all scanning and exploitation surges targeting specific products were followed by vulnerability disclosures within three weeks. The median time between a surge in malicious activity and a vendor’s disclosure was 11 days, offering organizations a potential early warning to patch or harden systems. Of the 42 scanning events observed, 57% led to disclosures, while 56% of brute-force attempts and 42% of remote-code-execution (RCE) probes also preceded public CVEs. The report highlights distinct patterns in attacker behavior: - Scanning activity was widely dispersed, with many IP addresses conducting a few sessions each likely broad reconnaissance. - Later-stage attacks (brute-force and RCE) were more concentrated, with fewer IPs generating high session volumes, suggesting targeted exploitation. - High-severity flaws generated the most probing activity, with some exploitation detected up to 39 days before disclosure. Notable examples include: - A Cisco vulnerability exploited in five surges over 18 days before disclosure, with IP activity dropping but session counts rising a shift from reconnaissance to focused attacks. - Juniper, SonicWall, and Ivanti flaws also saw early exploitation, with one Ivanti flaw targeted 36 days prior to disclosure. GreyNoise’s findings underscore that exploitation surges can serve as an early indicator of undisclosed vulnerabilities, particularly for critical infrastructure vendors. The data suggests that organizations monitoring such activity may gain a critical window to mitigate risks before patches are available.
INCIDENT DETAILS -
TYPE
Zero-day exploitationReconnaissanceBrute-force attackRemote Code Execution (RCE)
MOTIVATION
Exploitation of undisclosed vulnerabilitiesData exfiltrationTargeted attacks
NOVEMBER 2025
100Before Incident
Ransomware
20 Nov 2025SonicWall
SonicWall

Rise in Ransomware Attacks Exploiting Compromised VPN Credentials in Q3 2024

100After Incident
CRITICAL0
SON5792057112025
SonicWall suffered a prolonged ransomware campaign by the Akira group, exploiting compromised VPN credentials (SSLVPN services) as the primary initial access vector. The attack involved credential stuffing and brute-force techniques, targeting weak or absent MFA controls and insufficient lockout policies. The breach extended to SonicWall’s cloud service, exposing sensitive configuration backups of client devices—critical data that could facilitate further attacks on customers. Akira accounted for 39% of Beazley’s incident response cases in Q3, highlighting systemic vulnerabilities in SonicWall’s security posture. The incident underscores the risk of leaked credentials on the dark web, which were weaponized to deploy ransomware across multiple victim environments. The compromise not only disrupted SonicWall’s operations but also amplified supply-chain risks for its clients, as attackers leveraged stolen backups to exploit downstream targets. The financial and reputational damage includes regulatory scrutiny, customer distrust, and potential litigation, compounded by the operational outages caused by ransomware encryption. The attack also revealed critical gaps in patch management, as Akira exploited unpatched systems alongside weak credential hygiene. While the report does not confirm data exfiltration beyond configuration backups, the potential for broader data leaks (e.g., customer or employee PII) remains a latent risk, given the nature of ransomware operations. The incident aligns with broader trends where VPN appliances are prime targets, with SonicWall’s breach serving as a case study in how initial access brokers monetize stolen credentials to deploy high-impact ransomware.
INCIDENT DETAILS -
TYPE
RansomwareCredential TheftVulnerability Exploitation
MOTIVATION
Financial Gain (Ransomware)Data TheftUnauthorized Access
IMPACT
Sensitive Configuration Backups (SonicWall Cloud Breach)Potential PII/Enterprise Data (via Ransomware)SonicWall VPN DevicesCisco ASA VPN AppliancesCitrix NetScaler GatewaysEnterprise Endpoints (via SEO Poisoning)Disrupted Remote AccessPotential Data Encryption (Ransomware)Supply Chain RisksErosion of Trust in VPN/RDP SecurityReputational Damage to SonicWall/Cisco/CitrixHigh (Due to Credential Theft)
DATA BREACH
Configuration Backups (SonicWall Cloud)Potential PII/Enterprise Data (Ransomware)High (Configuration Backups)Potentially High (Ransomware)Data Exfiltration: Likely (Akira/Qilin/INC Modus Operandi)Data Encryption: Yes (Ransomware Attacks)Personally Identifiable Information: Potential (Via Credential Theft/Ransomware)
NOVEMBER 2025
100Before Incident
Vulnerability
01 Nov 2025SonicWall
SolarWinds, SonicWall and Cisco: Payouts King ransomware uses QEMU VMs to bypass endpoint security

Payouts King Ransomware Abuses QEMU for Stealthy Attacks

100After Incident
CRITICAL0
SOLSONCIS1776457498
Payouts King Ransomware Abuses QEMU for Stealthy Attacks The Payouts King ransomware operation is leveraging the QEMU emulator as a reverse SSH backdoor to deploy hidden virtual machines (VMs) on compromised systems, evading endpoint security detection. QEMU, an open-source virtualization tool, allows attackers to execute malicious payloads, store files, and establish covert remote access tactics previously observed in campaigns by 3AM ransomware, LoudMiner, and CRON#TRAP. ### Two Active Campaigns Cybersecurity firm Sophos identified two distinct campaigns exploiting QEMU: 1. STAC4713 (Payouts King) - First observed in November 2025, linked to the GOLD ENCOUNTER threat group. - Initial access via exposed SonicWall VPNs and later through SolarWinds Web Help Desk (CVE-2025-26399). - More recent attacks used Cisco SSL VPN exploits and Microsoft Teams phishing, tricking employees into installing QuickAssist. - Attackers deploy a hidden Alpine Linux VM (v3.22.0) via a scheduled task (TPMProfiler), disguising virtual disks as databases or DLLs. - Tools inside the VM include AdaptixC2, Chisel, BusyBox, and Rclone, with reverse SSH tunnels for persistence. - Post-infection, they exfiltrate NTDS.dit, SAM, and SYSTEM hives via SMB and Rclone to remote SFTP servers. 2. STAC3725 (CitrixBleed 2 Exploitation) - Active since February 2025, targeting NetScaler ADC/Gateway (CVE-2025-5777). - After compromise, attackers deploy a ZIP archive containing a malicious executable that: - Installs a service (AppMgmt). - Creates a local admin user (CtxAppVCOMService). - Deploys ScreenConnect for persistence. - A QEMU-based Alpine Linux VM is then launched, where attackers manually install tools like Impacket, KrbRelayx, BloodHound.py, and Metasploit for credential harvesting, AD reconnaissance, and data exfiltration via FTP. ### Ransomware Tactics & Attribution Payouts King employs AES-256 (CTR) + RSA-4096 encryption, intermittent file encryption, and anti-analysis techniques. Ransom notes direct victims to dark web leak sites. Zscaler suggests ties to former BlackBasta affiliates, citing similar initial access methods (e.g., spam bombing, Teams phishing, Quick Assist abuse). The group also terminates security tools via low-level system calls and establishes persistence through scheduled tasks. Organizations are advised to monitor for unauthorized QEMU installations, suspicious SYSTEM-level tasks, and unusual SSH port forwarding.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
NTDS.ditSAMSYSTEM hivesPersonally Identifiable Information (PII)SonicWall VPNSolarWinds Web Help DeskCisco SSL VPNMicrosoft TeamsNetScaler ADC/GatewayActive DirectoryOperational Impact: Disruption due to ransomware encryption and data exfiltrationBrand Reputation Impact: Potential damage due to data breach and ransomware attackIdentity Theft Risk: High (due to PII exposure)
DATA BREACH
Active Directory credentialsSystem hivesPersonally Identifiable Information (PII)Sensitivity Of Data: High (PII, credentials, system files)Data Encryption: AES-256 (CTR) + RSA-4096NTDS.ditSAMSYSTEM hives
OCTOBER 2025
100Before Incident
Ransomware
27 Oct 2025SonicWall
Marquis: Marquis cyber breach exposes ‘fourth-party’ dangers

Ransomware Attack on Fintech Firm Marquis

100After Incident
CRITICAL0
MAR1767095032
Massive Ransomware Attack on Fintech Firm Exposes 1.35 Million Bank Customers A ransomware attack on U.S.-based fintech provider Marquis, which serves over 700 banks and credit unions, has compromised the personal and financial data of nearly 1.35 million customers—far exceeding initial estimates of 400,000. The breach, disclosed between October 27 and November 25, exposed sensitive details, including bank account numbers, debit and credit card information, across at least 74 of Marquis’s clients. The incident underscores a critical vulnerability in the financial sector’s supply chain security, particularly the often-overlooked risk posed by "fourth-party" vendors—the suppliers of a bank’s third-party providers. The attack exploited a vulnerability in a SonicWall firewall used by Marquis, highlighting gaps in due diligence. While 95% of bank directors assess third-party security, only 40% extend scrutiny to fourth parties, according to cybersecurity firm Qualys. The fallout is expected to reshape risk management practices. Banks are likely to tighten vendor contracts, demand continuous vulnerability scanning, and face higher cyber insurance premiums—which have already surged 30-50% post-breach. Regulators may also intervene, with U.S. agencies (FDIC/OCC) and UK authorities (FCA/PRA) poised to impose stricter controls, including mandatory monitoring and shared encryption responsibilities. Beyond financial penalties, the breach could lead to brand damage, executive liability, and even judicial consequences for institutions failing to secure their supply chains. The attack aligns with broader trends: a Semperis report reveals that 52% of ransomware incidents occur on weekends or holidays, while attackers increasingly use regulatory complaints and physical threats as extortion tactics. The incident serves as a stark reminder of the escalating sophistication of cybercriminals targeting financial infrastructure.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Bank account numbers, debit and credit card numbers, and other personal detailsSystems Affected: Marquis systems and those of its banking clientsOperational Impact: Disruption to banking services and supply chain operationsBrand Reputation Impact: Significant brand damage expectedLegal Liabilities: Potential heavy penalties and judicial penalties for executivesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personal and financial detailsNumber Of Records Exposed: 1.35 millionSensitivity Of Data: High (bank account numbers, debit/credit card numbers)Personally Identifiable Information: Yes
OCTOBER 2025
100Before Incident
Breach
08 Oct 2025SonicWall
Wisner Baum LLP: DATA BREACH ALERT: Edelson Lechtzin LLP is Investigating Claims on Behalf of Wisner Baum LLP Clients Whose Data May Have Been Compromised

Wisner Baum LLP Data Breach Investigation

100After Incident
CRITICAL0
WIS1769454564
Wisner Baum LLP Investigates Data Breach Impacting Sensitive Personal Information On January 26, 2026, Edelson Lechtzin LLP announced an investigation into a data breach at Wisner Baum LLP, a Los Angeles-based law firm specializing in litigation against major corporations. The breach was first detected on October 9, 2025, when Wisner Baum identified suspicious activity on its IT network. An internal investigation revealed that an unauthorized third party accessed the firm’s systems between October 8 and October 9, 2025, potentially exfiltrating files containing sensitive personal data. Affected information may include names, driver’s license numbers, bank account and routing details, and medical records. Edelson Lechtzin LLP is exploring legal action on behalf of individuals whose data may have been compromised. The firm, known for handling class action lawsuits involving data breaches, securities fraud, and consumer protection cases, is currently gathering information from impacted parties. No further details on the scope of the breach or the number of affected individuals have been disclosed at this time. The incident remains under investigation.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive personal information, including names, driver’s license numbers, bank account and routing details, and medical recordsSystems Affected: IT networkLegal Liabilities: Potential legal actionIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
NamesDriver’s license numbersBank account and routing detailsMedical recordsSensitivity Of Data: HighData Exfiltration: PotentialPersonally Identifiable Information: Yes
OCTOBER 2025
100Before Incident
Cyber Attack
01 Oct 2025SonicWall
SonicWall

Coordinated Cyber Intrusions Targeting SonicWall SSL VPN Devices

100After Incident
CRITICAL0
SON1232512101325
A sophisticated cyberattack campaign targeted SonicWall SSL VPN devices, compromising over 100 accounts since early October. Attackers exploited valid, exposed credentials (not brute-force) from a centralized IP (202.155.8.73), indicating a premeditated, highly coordinated operation. The breach aligns with SonicWall’s disclosure that unauthorized parties accessed encrypted firewall configuration backups (containing sensitive credentials) via the MySonicWall cloud platform, contradicting their earlier claim that only <5% of installations were affected.The attackers conducted reconnaissance, credential validation, and network scans, escalating to attempts at accessing local Windows accounts on compromised systems. While SonicWall denies a direct link between the backup leak and VPN intrusions, the timing and methodical approach suggest exploitation of stolen configurations. The risk includes catastrophic data loss, lateral movement, and further system compromise, prompting urgent remediation: credential resets, service disablement (HTTP/S, SSH, SSL VPN), MFA enforcement, and enhanced logging.The attack’s scale, precision, and potential for widespread exploitation—leveraging leaked configurations—poses a severe threat to global organizations relying on SonicWall’s infrastructure. Immediate action is critical to prevent further intrusions and mitigate damage.
INCIDENT DETAILS -
TYPE
Unauthorized AccessCredential StuffingReconnaissancePotential Data Exfiltration
MOTIVATION
EspionageData TheftNetwork CompromisePotential Ransomware Preparation
IMPACT
Firewall Configuration DataCredentials (Potential)Network AccessSonicWall SSL VPN DevicesLocal Windows Accounts (Attempted Access)Firewall ConfigurationsNetwork Scans ConductedUnauthorized Access AttemptsPotential Lateral MovementHigh (Due to Widespread Advisory and Urgent Remediation)Loss of Trust in SonicWall Security ProductsHigh (If Credentials Compromised)Potential for Further Exploitation
DATA BREACH
Firewall Configuration Backups (Encrypted)Credentials (Potential)Network Topology DataSensitivity Of Data: High (Configuration Files Contain Sensitive Network/Credential Data)Data Exfiltration: Unconfirmed (But Strong Indication of Reconnaissance and Potential Exfiltration)Data Encryption: Yes (Backups Were Encrypted, but Credentials May Still Be Exposed)Firewall Configuration FilesBackup DataPersonally Identifiable Information: Potential (If Credentials Include PII)
SEPTEMBER 2025
100Before Incident
Breach
18 Sep 2025SonicWall
SonicWall

SonicWall MySonicWall Backup Exposure Incident

100After Incident
MEDIUM0
SON1091810100325
SonicWall detected a security incident where threat actors accessed encrypted backup firewall preference files stored in the MySonicWall cloud service for fewer than 5% of its firewall install base. Although no files were leaked online, the exposed data included encrypted credentials and configuration details that could facilitate further exploitation of affected firewalls. The breach resulted from brute-force attacks targeting the cloud backup service, not ransomware. SonicWall locked out the attackers, notified authorities, and urged impacted customers to reset credentials, reconfigure VPN pre-shared keys, and update TOTP bindings to mitigate risks. The remediation process requires importing new preference files, which disrupts VPNs and user access, necessitating manual reconfiguration. The company emphasized no evidence of data leaks but warned of potential follow-on attacks if exposed configurations were misused.
INCIDENT DETAILS -
TYPE
Data ExposureUnauthorized Access
MOTIVATION
Data TheftPotential Future Exploitation
IMPACT
Firewall preference files (encrypted credentials and configuration details)SonicWall Firewalls with MySonicWall cloud backups enabledDowntime: Potential downtime during remediation (VPN reconfiguration, TOTP reset, and firewall reboot)Disruption of IPSec VPNsTOTP bindings resetUser access reconfigurationMaintenance window requirements for remediationBrand Reputation Impact: Moderate (urgent advisory issued, but no data leakage confirmed)Identity Theft Risk: Low (credentials were encrypted, but exposure increases risk)
DATA BREACH
Firewall preference files (configuration details and encrypted credentials)Sensitivity Of Data: Medium (encrypted credentials but potential for exploitation)Data Encryption: Partially (credentials were encrypted, but other configuration details were exposed)Firewall backup preference files
AUGUST 2025
100Before Incident
Breach
14 Aug 2025SonicWall
Marquis Software Solutions

CoVantage Credit Union and Marquis Software Solutions Data Breach

100After Incident
CRITICAL0
MAR1463814112725
Marquis Software Solutions, a Texas-based technology provider serving over 500 banks and credit unions, detected unauthorized network activity on August 14, 2025. A third-party breach investigation confirmed that an attacker accessed and exfiltrated sensitive files from its systems, exposing personally identifiable information (PII) of individuals associated with clients like CoVantage Credit Union. The compromised data included names, addresses, phone numbers, Social Security numbers, financial account details, and dates of birth—high-risk information for identity theft and financial fraud. Notifications to affected individuals began in late October 2025, with at least 22 New Hampshire residents confirmed impacted as of November 26, 2025. While the breach was isolated to Marquis’ environment (sparing CoVantage’s internal systems), the scale of exposed data—particularly SSNs and financial records—poses severe risks of fraud, phishing, and long-term identity exploitation. Marquis offered 24 months of credit monitoring via Epiq Privacy Solutions, but the incident underscores systemic vulnerabilities in third-party vendors handling sensitive financial data. Legal firms are pursuing class-action lawsuits for compensation, citing negligence in safeguarding consumer information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesPhone numbersSocial Security numbersFinancial account informationDates of birthSystems Affected: Marquis Software Solutions' systems (CoVantage Credit Union's internal systems were not impacted)Identity Theft Risk: High (PII exposed)Payment Information Risk: High (financial account information exposed)
DATA BREACH
Personally Identifiable Information (PII)Financial DataSensitivity Of Data: High (includes SSNs, financial account info)Data Exfiltration: Potentially acquired by unauthorized third partyNamesAddressesPhone numbersSocial Security numbersDates of birth
AUGUST 2025
100Before Incident
Ransomware
02 Aug 2025SonicWall
SonicWall

Zero-Day Vulnerability in SonicWall Firewall Devices Exploited by Akira Ransomware Group

100After Incident
CRITICAL0
SON517080325
A suspected zero-day vulnerability in SonicWall firewall devices has led to a significant increase in ransomware attacks by the Akira ransomware group. The flaw allows attackers to gain initial access to corporate networks through SonicWall's SSL VPN feature, leading to subsequent ransomware deployment. The attackers have bypassed multi-factor authentication (MFA), indicating a sophisticated attack vector. The time between the initial VPN breach and the deployment of ransomware is short, giving victims little time to react. Arctic Wolf has recommended disabling the SonicWall SSL VPN service immediately until an official patch is developed and deployed.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
Systems Affected: SonicWall Firewall Devices
JUNE 2025
100Before Incident
Ransomware
16 Jun 2025SonicWall
SonicWall

Q3 2025 Ransomware Surge and VPN Credential Exploits

100After Incident
CRITICAL0
SON3832338111925
In Q3 2025, SonicWall faced a prolonged ransomware campaign by the Akira group, exploiting weak access controls in its SSLVPN services. Attackers leveraged credential stuffing to bypass authentication, targeting devices with absent MFA and insufficient lockout policies. The breach enabled unauthorized access to corporate networks, potentially exposing sensitive data and operational integrity. While the report does not confirm data exfiltration, the exploitation of SonicWall’s security appliances—critical for VPN access—poses severe risks, including lateral movement into customer environments, financial fraud, or operational disruptions. The incident underscores systemic vulnerabilities in access management, with attackers commoditizing stolen credentials via infostealers like Rhadamanthys. Though no direct customer data leak was confirmed, the compromise of VPN infrastructure threatens financial reputation, regulatory compliance, and trust in SonicWall’s security products. Mitigation required emergency patches, MFA enforcement, and forensic investigations to assess potential downstream impacts.
INCIDENT DETAILS -
TYPE
RansomwareCredential StuffingZero-Day Exploits
MOTIVATION
Financial Gain (Ransomware)Data Theft (Credential Harvesting)Cybercrime-as-a-Service (Infostealers)
IMPACT
VPN CredentialsCorporate Data (via Ransomware)Potential PII (via Infostealers)SonicWall SSLVPN AppliancesMicrosoft SharePointCrushFTP ServersCisco ASA VPNCitrix NetScalerDisrupted Business Operations (Ransomware)Increased Incident Response WorkloadPotential Supply Chain RisksErosion of Trust in Affected VPN/Software VendorsReputational Damage to Victim OrganizationsHigh (via Stolen Credentials)Potential Follow-on Attacks
DATA BREACH
VPN CredentialsCorporate Data (Ransomware)Potential PII (Infostealers)High (Credentials)Variable (Corporate/Data Theft)Data Exfiltration: Likely (Ransomware Double Extortion)Data Encryption: Yes (Ransomware)Personally Identifiable Information: Potential (via Infostealers)
FEBRUARY 2025
100Before Incident
Vulnerability
01 Feb 2025SonicWall
SonicWall and Marquis Software Solutions: Marquis Sues SonicWall, Alleges 2025 Cloud Flaw Led To Ransomware Hit / Fresh Today / CUToday.info

Marquis Software Solutions Sues SonicWall Over 2025 Cloud Vulnerability Linked to Ransomware Attack

100After Incident
CRITICAL0
SONMAR1772202741
Marquis Software Solutions Sues SonicWall Over 2025 Cloud Vulnerability Linked to Ransomware Attack Marquis Software Solutions has filed a lawsuit against SonicWall, alleging that a February 2025 cloud vulnerability enabled a ransomware attack in August 2025, exposing sensitive data from hundreds of financial institutions, including credit unions. The breach, which triggered widespread notifications across the credit-union system, has had significant fallout for affected organizations. According to the complaint, the attacker exploited exposed credentials and firewall configuration data from SonicWall’s cloud incident, bypassing multifactor authentication (MFA) protections. Marquis claims SonicWall introduced an exploitable flaw through an API code change, allowing unauthorized downloads of firewall configuration backups. The company alleges that predictable device serial numbers and unencrypted MFA "scratch codes" in the backups enabled threat actors to compromise systems. SonicWall has denied the allegations, stating it has not found technical evidence linking its cloud incident to the ransomware attack and plans to contest the claims. Meanwhile, Marquis, which serves over 700 banks and credit unions including Artisans’ Bank and VeraBank reported that the breach led to customer notifications, legal expenses, forensic costs, and class-action litigation. The company is seeking damages, arguing SonicWall failed to adequately protect customer firewall data.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Financial Loss: Legal expenses, forensic costsData Compromised: Sensitive data from financial institutionsSystems Affected: Firewall configurations, MFA-protected systemsOperational Impact: Customer notifications, class-action litigationBrand Reputation Impact: Significant fallout for affected organizationsLegal Liabilities: Class-action litigation, lawsuit against SonicWall
DATA BREACH
Type Of Data Compromised: Firewall configuration data, MFA scratch codes, sensitive financial dataSensitivity Of Data: High (financial institutions' data)Data Encryption: Unencrypted MFA scratch codes
JANUARY 2025
100Before Incident
Ransomware
01 Jan 2025SonicWall
SonicWall and Fortinet: BYOVD Attacks Help Ransomware Gangs Bypass Endpoint Defenses

Ransomware Evolves into Stealthier, More Destructive Threat in 2026

100After Incident
CRITICAL0
SONFOR1778660813
Ransomware Evolves into Stealthier, More Destructive Threat in 2026 In 2026, ransomware attacks have shifted from opportunistic strikes to highly calculated, multi-stage operations, adapting to global anti-ransomware efforts. A new Kaspersky report reveals that while overall attack volumes declined in 2025, the sophistication of these threats has surged with manufacturing alone facing an estimated $18 billion in potential losses. Attackers are now exploiting trusted system components to evade detection before deploying their payloads. A key tactic is the "Bring Your Own Vulnerable Driver" (BYOVD) technique, where cybercriminals use legitimate, signed drivers to disable security tools including EDR killers that terminate monitoring agents. This method turns evasion into a repeatable phase of the attack lifecycle, systematically eroding defensive visibility. Ransomware developers are also future-proofing their malware with post-quantum cryptography, such as the PE32 family’s use of ML-KEM (Kyber1024), which offers encryption strength comparable to AES-256. This ensures victims have virtually no chance of recovering files without paying. With global ransom payments dropping to just 28% in 2025, threat actors are pivoting to encryptionless extortion. Instead of locking files, they steal sensitive data and threaten public disclosure, turning ransomware into a data security and compliance crisis one that backups alone cannot mitigate. The criminal ecosystem has also seen a shift. Following the disappearance of RansomHub in 2025, Qilin has emerged as the dominant ransomware-as-a-service (RaaS) platform, while new groups like "The Gentlemen" operate with structured, business-like efficiency. Other emerging actors Devman, MintEye, and DireWolf demonstrate how low the barrier to entry remains, often targeting enterprise hardware from Fortinet, SonicWall, and Cisco. As ransomware evolves, organizations face an increasingly hostile landscape where even their own security tools are under siege.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
Financial Loss: $18 billion (manufacturing sector alone)Data Compromised: Sensitive data (encryptionless extortion)Manufacturing sectorEnterprise hardware (Fortinet, SonicWall, Cisco)
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: High (personally identifiable/sensitive business data)Data Exfiltration: Yes (encryptionless extortion)Data Encryption: Yes (post-quantum cryptography - ML-KEM/Kyber1024)
Vulnerability
01 Jan 2025SonicWall
SonicWall

SonicWall Cyber Attack

100After Incident
CRITICAL0
SON502042125
SonicWall has experienced a cyber attack due to a remote code execution vulnerability affecting its Secure Mobile Access (SMA) appliances. These flaws impacted various SMA models and were exploited despite being patched four years ago. The flaw allowed remote threat actors to inject arbitrary commands and execute arbitrary code. This has been under active exploitation since at least January 2025 as confirmed by cybersecurity company Arctic Wolf and federal agencies. As a response to the attack, SonicWall has updated the security advisory and revised the CVSS score based on the newfound impacts.
INCIDENT DETAILS -
TYPE
Remote Code Execution
IMPACT
Systems Affected: Various SMA models
Vulnerability
01 Jan 2025SonicWall
SonicWall, DragonForce, Fortinet, Cl0p and Play: Europol IOCTA 2026 report flags shift to industrialised cybercrime powered by AI, ransomware and data theft

Europol’s IOCTA 2026 Report: Ransomware, AI, and Hybrid Threats Reshape Cybercrime Landscape

100After Incident
CRITICAL0
PHISONFORDRARAV1777458596
Europol’s IOCTA 2026 Report: Ransomware, AI, and Hybrid Threats Reshape Cybercrime Landscape Europol’s latest Internet Organised Crime Threat Assessment (IOCTA) 2026 reveals a rapidly evolving cybercrime ecosystem, marked by professionalized ransomware operations, the exploitation of AI, and deepening ties between cybercriminals and hybrid threat actors. The report, covering trends from 2025, highlights a shift in extortion tactics, the rise of ransomware-as-a-service (RaaS), and the growing intersection of cybercrime with broader criminal networks. ### Ransomware Dominates, Tactics Evolve Ransomware remains the EU’s most pervasive cyber threat, with over 120 active brands observed in 2025. Attackers are moving away from traditional data encryption, instead favoring pure data theft and extortion, leveraging psychological pressure tactics such as DDoS attacks, corporate email spamming, and cold-calling victims. The report notes that enterprises are often less prepared for data leaks than encryption, making this shift particularly effective. The RaaS model has lowered the barrier to entry, enabling even low-skilled actors to launch attacks using bundled toolkits. These platforms now offer integrated services, including botnets for payload delivery, data exfiltration infrastructure, machine learning support, and ransom negotiation tools. Operators take a cut of each payment, incentivizing the development of streamlined, all-in-one offerings. Key ransomware groups in 2025 include: - Qilin: A dominant player with ties to the defunct Conti group, offering high affiliate payouts (up to 85%) and automated exploitation of Fortinet SSL VPN vulnerabilities. - Akira: Linked to Conti, expanding attacks to virtualized environments via SonicWall VPN flaws. - DragonForce: A modular, service-driven group using leaked Conti and LockBit code, specializing in tailored extortion for high-value targets. - LockBit: Struggled to recover after its 2024 takedown but released a cross-platform variant with enhanced anti-forensics. - Cl0p & Play: Closed groups operating with strict internal security, targeting critical infrastructure and deploying double extortion. A new alliance between DragonForce, LockBit, and Qilin emerged in late 2025, signaling deeper collaboration in the ransomware ecosystem. Meanwhile, semi-closed and closed groups such as Fog and BlackBasta are adopting tighter control, recruiting only trusted affiliates and developing proprietary tools to evade detection. ### Hybrid Threats and Cybercrime-as-a-Service The IOCTA 2026 report warns of blurring lines between cybercriminals and hybrid threat actors, with state-linked groups increasingly using criminal networks as proxies for disruptive operations. In the cybercrime-as-a-service (CaaS) economy, hybrid actors are simply another customer, complicating attribution and enforcement. A notable development is the Scattered LAPSUS$ Hunters (SLSH) alliance, formed in August 2025 by Scattered Spider, ShinyHunters, and LAPSUS$. These English-speaking groups specialize in SIM swapping, social engineering, insider recruitment, and large-scale data theft, targeting corporations, healthcare, and transport sectors. Their tactics include persistent harassment post-payment, and some members have ties to The Com network, a criminal ecosystem linked to extremism and child exploitation. ### AI, Infostealers, and DDoS as Enablers Cybercriminals are rapidly adopting AI tools to automate attacks, enhance social engineering, and blur the line between legitimate and malicious technology. Infostealers remain a critical enabler, fueling a broad illicit market that supplies ransomware affiliates, fraudsters, and initial access brokers (IABs). DDoS attacks persist as a low-effort, high-impact tool, often used for extortion or ideological disruption. While mitigation measures have improved, the minimal resources required make DDoS a sustainable strategy for destabilization, with targets including governments and critical infrastructure. ### Law Enforcement Challenges and Future Outlook Europol’s Executive Director, Catherine De Bolle, emphasized the urgent need for proactive, collaborative efforts to counter cybercrime’s accelerating pace. The report calls for: - Investment in AI capabilities for law enforcement. - Stronger cross-border cooperation and data retention policies. - Closer private-sector collaboration to access critical data held by online service providers. The IOCTA 2026 report concludes that the cybercrime landscape will continue evolving at speed, driven by advanced tools and complex criminal networks. Law enforcement’s ability to close the "velocity gap" matching the pace of cybercriminal innovation will determine its effectiveness in the coming years.
INCIDENT DETAILS -
TYPE
ransomwaredata extortioncybercrime-as-a-serviceDDoSinfostealer attacks
MOTIVATION
financial gainextortiondata theftdisruptionideological motives
IMPACT
Data Compromised: high-volume data theft and exfiltrationenterprise systemscritical infrastructurehealthcaretransport sectorsOperational Impact: persistent harassment post-payment, psychological pressure tactics (DDoS, email spamming, cold-calling)Brand Reputation Impact: high (due to data leaks and extortion tactics)Identity Theft Risk: high (due to infostealers and PII exposure)Payment Information Risk: high (due to data exfiltration and ransomware attacks)
DATA BREACH
personally identifiable information (PII)corporate datasensitive business informationSensitivity Of Data: highData Exfiltration: yespartial (ransomware strains)none (pure data theft extortion)Personally Identifiable Information: yes
Vulnerability
01 Jan 2025SonicWall
SonicWall, Fortinet and Palo Alto Networks: Google Warns Ransomware Groups Are Pivoting To Data Theft As Profits Decline

Ransomware Landscape Shifts in 2025 as Cybercriminals Pivot to Data Extortion

100After Incident
CRITICAL0
FORSONPAL1773829502
Ransomware Landscape Shifts in 2025 as Cybercriminals Pivot to Data Extortion Google Threat Intelligence’s 2025 ransomware report reveals a major transformation in cybercriminal tactics, driven by declining profits from traditional encryption-based attacks. With organizations improving their defenses nearly half of victims restored systems from backups in 2024 ransom payment rates hit a historic low by 2025. The average ransom demand also dropped by a third, falling from $2 million in 2024 to $1.34 million. The ransomware ecosystem has faced significant disruptions, including law enforcement crackdowns and internal conflicts that dismantled prominent groups like LockBit, ALPHV, Basta, and RansomHub. These upheavals forced cybercriminals to adopt stricter vetting processes for affiliates. Despite these challenges, the threat landscape remains active, with groups like Qilin and Akira filling the void. Data-leak site posts surged by nearly 50% in 2025, with the REDBIKE ransomware family accounting for 30% of analyzed incidents. Attackers continue to exploit vulnerabilities in firewalls and VPNs, particularly in products from Fortinet, SonicWall, and Palo Alto, which were used in a third of 2025 intrusions. Virtualization infrastructure, such as ESXi hypervisors, has become a prime target, involved in 43% of attacks up from 29% the previous year. Cybercriminals are also adopting cross-platform ransomware and leveraging AI for victim analysis, while decentralized Web3 networks help shield their operations. As profits shrink, the report warns of a potential rise in aggressive extortion tactics in 2026.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
FirewallsVPNsVirtualization infrastructure (ESXi hypervisors)
Vulnerability
01 Jan 2025SonicWall
SonicWall: Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks

Ransomware and Financial Fraud Surge in 2025, Driven by Remote Access Vulnerabilities

100After Incident
CRITICAL0
SON1776925440
Ransomware and Financial Fraud Surge in 2025, Driven by Remote Access Vulnerabilities The 2026 InsurSec Report from At-Bay, analyzing over 100,000 policy years of claims data, reveals a sharp rise in cyber incidents in 2025, with ransomware and financial fraud leading the surge. Overall claim frequency increased by 7% year-over-year, while average severity hit a record $221,000. Ransomware severity reached $508,000 up 16% from 2024 making it the costliest incident type. Remote Access Exploits Dominate Ransomware Attacks Remote access services were the primary entry point for 87% of ransomware claims, up from 80% in 2024. VPN compromises accounted for 73% of intrusions where the vector was identified, a steep rise from 38% in 2023. SonicWall devices were involved in one-third of ransomware claims. Improved email security has shifted attacker focus away from phishing, with no ransomware claims originating from email in 2025. The Akira ransomware group saw a 364% spike in activity in late 2025, executing attacks within hours or minutes of initial access. Akira’s average ransom demand reached $1.2 million 50% higher than non-Akira demands with payments averaging $452,000. Organizations with 24/7 managed detection and response (MDR) monitoring avoided encryption in every Akira case, while two-thirds of attacks occurred outside business hours, exploiting gaps in coverage. Smaller Businesses Face Growing Threats Companies under $25 million in revenue experienced the steepest increases, with ransomware frequency rising 21% and severity climbing 40% to $422,000. Manufacturing saw ransomware frequency at 2.2 times the portfolio average, while technology firms faced the highest severity ($875,000), followed by finance ($731,000) and healthcare ($675,000). Financial Fraud Losses Escalate Financial fraud remained the most common incident type, comprising 30% of claims for the third consecutive year. Email was the initial vector in 82% of cases, with average stolen funds rising 16% to $285,000. The largest single loss recorded was $9.65 million. Attackers increasingly routed malicious links through trusted cloud platforms like Cloudflare, which appeared in 69% of abused infrastructure alerts. Rapid reporting improved recovery outcomes funds were returned in 70% of cases reported within three days, dropping to 30% after two weeks. At-Bay recovered $56 million in stolen funds in 2025. Third-Party Liability Claims Surge Third-party liability claims rose 70%, the largest increase among tracked incident types. Lawsuits under the California Invasion of Privacy Act (CIPA) accounted for 34% of claims, up from 7% in 2023, expanding beyond Meta Pixel to include tracking tools from LinkedIn and TikTok. Class action lawsuits followed 6% of ransomware incidents and 4% of data breaches, adding defense costs and settlements to initial attack damages. Business interruption coverage was triggered in one-third of ransomware claims, with average severity reaching $510,000 nearly triple that of claims without it. The largest single business interruption payout hit $5 million.
INCIDENT DETAILS -
TYPE
ransomwarefinancial fraudthird-party liability
MOTIVATION
financial gain
IMPACT
Financial Loss: $221,000 (average severity), $508,000 (ransomware severity), $285,000 (financial fraud), $9.65 million (largest single loss)Operational Impact: business interruption coverage triggered in one-third of ransomware claimsLegal Liabilities: third-party liability claims rose 70%, class action lawsuits followed 6% of ransomware incidents and 4% of data breaches
DATA BREACH
Data Encryption: data encryption in ransomware attacks
AUGUST 2024
100Before Incident
Ransomware
01 Aug 2024SonicWall
SonicWall

Akira Ransomware Exploits Critical SonicWall Vulnerability (CVE-2024-40766) in Ongoing Attacks

100After Incident
CRITICAL0
SON2902029091125
The Akira ransomware gang exploited a critical CVE-2024-40766 (CVSS 9.8) vulnerability in SonicWall’s SSLVPN appliances, a flaw originally disclosed in August 2024 but left unpatched by many organizations. Over 438,000 SonicWall devices remained publicly exposed, enabling attackers to gain unauthorized access via misconfigurations, legacy credentials, and improper LDAP group settings. Akira and other ransomware groups (e.g., Fog) used this to encrypt systems within 10 hours of initial access, leading to widespread disruptions. Rapid7 reported double-digit incidents among its customers, while SonicWall confirmed fewer than 40 cases in early August 2025—though the actual impact is likely higher due to underreporting. The attacks leveraged default Virtual Office portal configurations, allowing MFA bypasses if credentials were previously exposed. Organizations failing to apply patches, enforce MFA, or restrict portal access faced full-system encryption, operational outages, and potential data exfiltration, threatening business continuity. The persistent exploitation highlights systemic negligence in mitigating known vulnerabilities, amplifying the risk of financial losses, reputational damage, and regulatory penalties for affected entities.
INCIDENT DETAILS -
TYPE
ransomwareunauthorized accessexploitation of vulnerability
MOTIVATION
financial gain (ransomware)
IMPACT
Systems Affected: SonicWall firewall devices (Gen 6/Gen 7), SSLVPN services, Virtual Office portalDowntime: <10 hours (encryption timeframe in some cases)Operational Impact: potential widespread disruption (438,000+ devices exposed)Brand Reputation Impact: high (publicized vulnerability exploitation)
DATA BREACH
Data Encryption: full system encryption (ransomware)
APRIL 2024
100Before Incident
Cyber Attack
01 Apr 2024SonicWall
SonicWall

SonicWall Cyber Threat Report: Escalating Cyberattacks

100After Incident
CRITICAL0
SON407050824
The SonicWall Cyber Threat Report highlights the escalating costs and frequencies of cyberattacks on organizations, underlining a worrying trend that affects businesses globally. In the last year, organizations with a relatively modest size of 100-5,000 users have not been spared, with more than half experiencing one or several cyber incidents. These unwelcome events have been financially damaging, with the average cost soaring to $5.34 million. Such a figure represents not just a direct financial burden but also unleashes a series of indirect consequences, including but not limited to, tarnished reputations, operational disruptions, and potential regulatory penalties. These findings, drawn from an exhaustive collection of real-world data and threat intelligence, underscore the critical need for heightened cybersecurity vigilance. A proactive and comprehensive approach to cybersecurity, backed by real-time threat intelligence and robust defense mechanisms, is imperative for organizations seeking to navigate the digital landscape securely and mitigate the risks posed by an ever-evolving threat landscape.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
$5.34 millionOperational disruptionsTarnished reputationsPotential regulatory penalties
MARCH 2024
248Before Incident
Ransomware
01 Mar 2024SonicWall
SonicWall

Widespread Cyber Threats Across SMBs

100After Incident
MEDIUM-148
SON105050824
Over the past year, organizations ranging from small to medium businesses with 100-5,000 users have faced a significant cyber threat landscape, with 57% experiencing at least one cyberattack. These incidents have resulted in substantial financial losses, averaging $5.34 million per attack. This figure underscores the grave financial implications cyber threats pose, compelling businesses to reassess their cybersecurity measures. SonicWall, renowned for its real-time cyber threat intelligence, has been at the forefront of these observations. Their 2024 Cyber Threat Report compiles extensive data from 1.1 million security sensors across 215 countries, offering invaluable insights into the nature and frequency of these threats. By analyzing cross-vector threat-related information and leveraging shared intelligence within the cybersecurity community, SonicWall plays a pivotal role in enabling organizations worldwide to bolster their defenses against an evolving cyber threat landscape.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Financial Loss: $5.34 million per attack
OCTOBER 2023
198Before Incident
Cyber Attack
01 Oct 2023SonicWall
SonicWall

Coordinated Cyber Intrusions Targeting SonicWall SSL VPN Devices

180After Incident
CRITICAL-18
SON1132511101325
A sophisticated cyberattack campaign targeted SonicWall SSL VPN devices, compromising over 100 accounts since early October 2023. Threat actors exploited valid, exposed credentials (rather than brute-force methods) to infiltrate systems, originating from a single IP (202.155.8.73), suggesting a centralized command structure. The breach escalated after SonicWall disclosed that unauthorized parties accessed encrypted firewall configuration backups—containing sensitive credentials—via its MySonicWall cloud service. While SonicWall initially claimed the breach affected under 5% of installations, the timing and precision of the attacks imply a direct link. Attackers conducted reconnaissance, scanned networks, and attempted to access local Windows accounts, posing risks of catastrophic data loss. SonicWall urged immediate mitigation: resetting all credentials (admin, VPN, LDAP, API), disabling remote services, enabling MFA, and enforcing strict access controls. The campaign’s scale and methodical execution highlight severe vulnerabilities in critical network infrastructure, with potential for widespread exploitation if unchecked.
INCIDENT DETAILS -
TYPE
Unauthorized AccessCredential StuffingReconnaissancePotential Data Exfiltration
MOTIVATION
EspionageData TheftPotential Follow-on Attacks
IMPACT
Firewall Configuration DataCredentials (Local Windows Accounts, VPN Pre-Shared Keys, LDAP, SNMP, API Secrets)SonicWall SSL VPN DevicesCompromised Customer NetworksNetwork ScansUnauthorized Access AttemptsPotential Lateral MovementHigh (Due to Widespread Compromises and Credential Exposure)High (If Credentials Are Abused)
DATA BREACH
Firewall Configuration BackupsEncrypted CredentialsNetwork Access CredentialsSensitivity Of Data: High (Configuration Data + Credentials)Potential (Unconfirmed but Likely Given Reconnaissance Activity)Backups Were Encrypted (But Credentials Still Exposed)Configuration FilesBackup Files
SEPTEMBER 2023
246Before Incident
Breach
01 Sep 2023SonicWall
SonicWall

SonicWall Cloud Backup Service Data Breach

185After Incident
CRITICAL-61
SON2392523100925
SonicWall confirmed that all customers using its MySonicWall cloud backup service were impacted by a cybersecurity breach initially disclosed in September 2023. The attackers accessed firewall configuration backup files, which include critical network settings, policies, user/group/domain details, DNS/log configurations, and certificates. While SonicWall claims no evidence of compromise to production firewalls or other systems, the exposed data could enable threat actors—including nation-state groups or ransomware operators—to map internal infrastructure, pivot into connected environments, or launch follow-on attacks. Initially, SonicWall downplayed the incident, stating only <5% of customers were affected, but an independent forensic review revealed 100% of cloud backup users were exposed. Customers were advised to delete cloud backups, rotate credentials, and recreate backups locally. The company has not disclosed the attack vector, attributed the breach to a specific threat actor, or confirmed whether data was exfiltrated, leaked, or destroyed. This incident follows prior SonicWall breaches, including a zero-day VPN exploit linked to ransomware attacks earlier in 2023, further eroding customer trust in its security posture.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized Access
MOTIVATION
Data ExfiltrationPotential Follow-on Attacks
IMPACT
Firewall Configuration FilesNetwork PoliciesUser/Group/Domain SettingsDNS and Log SettingsCertificatesMySonicWall Cloud Backup ServiceCustomers advised to delete backups, rotate credentials, and recreate backups locallyLoss of customer trust due to revised impact scope (from 5% to 100%)
DATA BREACH
Firewall Configuration FilesNetwork SettingsPoliciesCertificatesSensitivity Of Data: High (includes internal infrastructure details, user/group/domain settings, DNS/log settings)Backups were encrypted and compressed (but still accessed)Configuration Backup Files
APRIL 2023
459Before Incident
Ransomware
01 Apr 2023SonicWall
SonicWall

2024 Cyber Attack Trends Reported by SonicWall

174After Incident
CRITICAL-285
SON705050724
Over the past year, organizations ranging from 100 to 5,000 users have faced an increasing wave of cyberattacks. The 2024 SonicWall Cyber Threat Report highlights a concerning trend where 57% of these organizations endured at least one cyberattack, with an average financial toll of $5.34 million. This significant economic impact underscores the evolving and sophisticated nature of cyber threats. The report draws its conclusions from a robust dataset, courtesy of the SonicWall Capture Labs. This network, comprising over 1.1 million security sensors spread across 215 countries and territories, offers a unique vantage point into the tactics and vectors preferred by cyber adversaries. By analyzing cross-vector threat information and leveraging global malware and IP reputation data, SonicWall provides invaluable insights into cyber incidents. This comprehensive intelligence is not only a testament to the severity of the cybersecurity landscape but also serves as a critical resource for organizations aiming to navigate and mitigate the risks of cyberattacks.
INCIDENT DETAILS -
TYPE
Multiple
IMPACT
Financial Loss: $5.34 million
MARCH 2023
721Before Incident
Ransomware
01 Mar 2023SonicWall
Veeam, SonicWall and Cisco: Researchers Observe Sub-One-Hour Ransomware Attacks

Akira Ransomware Group Accelerates Attacks, Completing Full Compromise in Under an Hour

453After Incident
CRITICAL-268
VEESONCIS1775140482
Akira Ransomware Group Accelerates Attacks, Completing Full Compromise in Under an Hour Security researchers at Halcyon have identified a significant escalation in ransomware attack speed, with the Akira group now executing full attack lifecycles from initial access to data encryption in as little as one hour. The group, suspected to include former Conti hackers, has emerged as one of the most sophisticated ransomware operations since its debut in March 2023. Akira primarily gains entry by exploiting vulnerabilities in internet-facing VPN appliances and backup solutions, particularly those without multi-factor authentication (MFA). Targeted vendors have included SonicWall, Veeam, and Cisco, though the group also employs credential theft, spearphishing, password spraying, and initial access brokers (IABs) to breach networks. Once inside, Akira follows a double-extortion model, exfiltrating data before encrypting files. To evade detection, the group disables security software and leverages living-off-the-land tools like FileZilla, WinRAR, WinSCP, and RClone for data staging and encryption. Notably, Akira uses intermittent encryption scrambling as little as 1% of a file to maximize impact while minimizing detection time. Halcyon’s report highlights Akira’s disciplined operational tempo, with attacks typically completed in under four hours and some in less than 60 minutes. The group’s stealthy approach, reliance on zero-day exploits, and use of compromised credentials allow it to maintain covert access while rapidly encrypting systems. Since its emergence, Akira has reportedly generated $244 million in ransom payments, according to U.S. government estimates.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransom payments)
IMPACT
Financial Loss: $244 million in ransom payments (estimated)
JUNE 2021
762Before Incident
Breach
16 Jun 2021SonicWall
SonicWall

SonicWall Cloud Backup Service Breach Exposes All Customer Firewall Configurations

699After Incident
CRITICAL-63
SON5492754101225
SonicWall confirmed a severe breach where hackers accessed firewall configuration backup files for all customers using its cloud backup service (MySonicWall portal). Initially downplayed as affecting only 5% of users, an internal investigation (assisted by Mandiant) revealed a full compromise of encrypted backups—including firewall rules, VPN configurations, and access controls—via brute-force attacks. While SonicWall claims the exfiltrated data is encrypted, experts warn it could be decrypted or leveraged for targeted exploits, phishing, or network mapping. The breach forces thousands of enterprises to reset credentials, regenerate encryption keys, and conduct forensic audits, disrupting operations. The incident exacerbates SonicWall’s reputation after repeated vulnerabilities since 2021 (e.g., zero-days in Secure Mobile Access) and raises compliance concerns under GDPR/NIST. Though no immediate exploitation is reported, the stolen data poses long-term risks, including supply-chain attacks akin to SolarWinds. Customers are advised to update firmware, monitor anomalies, and adopt zero-trust architectures to mitigate fallout.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessCloud Security Incident
MOTIVATION
Data ExfiltrationPotential Future ExploitsNetwork Mapping
IMPACT
Firewall Configuration BackupsEncrypted CredentialsNetwork SettingsVPN ConfigurationsAccess ControlsMySonicWall PortalCloud Backup ServiceForensic Audits Required for All CustomersDisruption of OperationsUrgent Credential ResetsHeightened ScrutinyLoss of TrustComparisons to SolarWinds BreachPotential Regulatory ProbesPossible LawsuitsCompliance Risks (GDPR, NIST)Low (Data Encrypted but Potentially Decryptable)
DATA BREACH
Firewall Configuration BackupsEncrypted CredentialsNetwork Topology DataVPN SettingsAccess Control RulesNumber Of Records Exposed: All Customer Backups (Previously Estimated 5%, Revised to 100%)High (Network Infrastructure Details)Medium (Encrypted but Potentially Decryptable)Claimed by SonicWallExperts Warn of Potential Decryption RisksConfiguration BackupsEncrypted Credential FilesIndirect (via Network Mapping Potential)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SonicWall ?
?
What was SonicWall's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SonicWall's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on SonicWall's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SonicWall ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SonicWall's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?