SonicWall SMA Appliances Were Compromised Before Anyone Knew They Were Vulnerable
SonicWall, a company that makes network security hardware used by businesses to manage remote access, disclosed this week that attackers had already exploited two zero-days (security flaws that are unknown to the vendor at the time of attack) in its SMA series appliances before any patch existed, according to The Hacker News.
The attackers used these flaws to gain root access — the highest level of control over a system, equivalent to having a master key to every room in a building. From there, they could install persistent backdoors (hidden access points built into a compromised system), intercept credentials, and move freely through the networks the devices were supposed to be protecting.
SMA appliances are commonly used by businesses to let employees connect securely from outside the office. That makes them a high-value target: compromise the gateway, and you own the door.
The number of affected organisations has not been confirmed in the source material. SonicWall has now issued patches.
What you should do: If your organisation uses SonicWall SMA appliances, check with your IT team today. The patches are out — apply them immediately. If you manage these devices yourself, visit the official SonicWall advisory and upgrade before the end of the day.
Sources

