CISA Confirms SonicWall SMA1000 Flaws Exploited by Ransomware
TL;DR. CISA confirmed ransomware gangs exploit two SonicWall SMA1000 vulnerabilities, including a severe server-side request forgery flaw. - These vulnerabilities target enterprise-grade secure remote access gateways used by large corporations and government agencies. - Threat actors exploited the flaws as zero-days before patches were released, deploying custom malware. - CISA previously added these flaws to its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch.
- Ransomware gangs exploit SonicWall SMA1000 vulnerabilities, including a critical SSRF flaw.
- The affected SMA1000 gateways provide VPN access for corporate and government networks.
- Threat actors leveraged the flaws as zero-days, deploying custom malware.
- CISA listed these vulnerabilities in its KEV Catalog, mandating federal agency patching.
Sources
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — bleepingcomputer.com