threat-intel
Hackers bypass SonicWall VPN MFA due to incomplete patching
High
Summary
Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, leveraging credential brute-forcing and a vulnerable driver, but were blocked by existing EDR solutions. This incident highlights the importance of complete remediation steps after patching and suggests a potential broker role for the threat actor.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data