news.mlab.sh
Back to the feed
vulnerability

SonicWall's SMA1000 boxes under active attack again

CriticalCVSS 10.0
Summary

This article highlights ongoing attacks targeting SonicWall's SMA1000 boxes, with attackers leveraging stolen API keys and credits to gain unauthorized access. The vulnerability stems from a lack of immediate detection, allowing attackers to operate undetected for weeks. The SonicWall devices are being actively exploited, representing a significant security risk.

This article focuses on a persistent security issue affecting SonicWall's SMA1000 boxes. Security researchers have discovered that attackers are actively exploiting these devices, leveraging stolen METR API keys and substantial credit allowances to gain unauthorized access. The vulnerability was initially discovered when a security attacker stole a METR API key and subsequently used $600,000 worth of credits without detection for weeks. The SonicWall devices are being targeted, indicating a broader concern about the security posture of these devices and the potential for wider exploitation. The SonicWall devices are being actively exploited, indicating a broader concern about the security posture of these devices and the potential for wider exploitation.

Read the full article at The Register