Laptop emitting light beams with digital figures, shields, spider icon, and world map visible

Daily Dose of Cybersecurity News - October 12, 2025

Widespread SonicWall SSL VPN Compromise Detected

High

What happened

Cybersecurity firm Huntress identified a widespread compromise of SonicWall SSL VPN devices, with attackers using valid credentials to access multiple customer environments. The rapid authentication into numerous accounts suggests that the attackers possess legitimate credentials rather than employing brute-force methods. The activity began on October 4, 2025, affecting over 100 accounts across 16 customers. In some cases, attackers conducted network scanning and attempted access to local Windows accounts.

Who is affected

Organizations utilizing SonicWall SSL VPN devices, particularly those with accounts accessed from IP address 202.155.8[.]73, are impacted.

Why it matters

The compromise of SSL VPN devices poses significant security risks, including unauthorized network access, potential data breaches, and the possibility of further exploitation within affected networks. The use of valid credentials indicates a sophisticated attack vector that may bypass traditional security measures.

How it could have been prevented

Implementing robust multi-factor authentication (MFA) for all remote access accounts can mitigate unauthorized access. Regularly monitoring and auditing VPN access logs for unusual activity can help in early detection of compromises. Restricting VPN access to trusted IP addresses and disabling unused accounts can further reduce the attack surface.

Relevant professional terms

SSL VPN
A Secure Sockets Layer Virtual Private Network that allows users to securely access a private network over the internet.
Multi-Factor Authentication (MFA)
A security process that requires users to provide multiple forms of verification to gain access to a system.

Recommended reading: Arctic Wolf Observes July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPN

Exploitation of Velociraptor DFIR Tool in LockBit Ransomware Attacks

High

What happened

Threat actors, identified as Storm-2603, exploited vulnerabilities in on-premises SharePoint servers to deploy an outdated version of Velociraptor, an open-source digital forensics and incident response (DFIR) tool. This version contained a privilege escalation vulnerability (CVE-2025-6264), enabling arbitrary command execution and facilitating the deployment of Warlock, LockBit, and Babuk ransomware.

Who is affected

Organizations utilizing on-premises SharePoint servers are at risk, particularly those with unpatched vulnerabilities that can be exploited to gain initial access.

Why it matters

The misuse of legitimate security tools like Velociraptor underscores the evolving tactics of threat actors, highlighting the need for organizations to secure and monitor their cybersecurity tools to prevent them from being weaponized.

How it could have been prevented

Regularly updating and patching software to address known vulnerabilities, monitoring for unauthorized use of security tools, and implementing strict access controls can mitigate such attacks.

Relevant professional terms

Privilege Escalation
Gaining higher-level permissions on a system than originally granted, often to execute unauthorized actions.
Digital Forensics and Incident Response (DFIR)
The practice of investigating and responding to cyber incidents to understand their impact and prevent future occurrences.

Recommended reading: thehackernews.com