Tuesday , August 4 2026
SonicWall firewall

SonicWall Firewall Targeted by Hackers; 597,000 Sessions Observed

A big increase in scanning across the internet for SonicWall firewall management interface has been observed. GreyNoise, a threat intelligence company, found a big increase in scans of SonicWall SonicOS management APIs from May 9 to May 18, 2026.

The most notable spike occurred on May 12, when approximately 597,000 sessions were recorded in a single day. This represents a roughly 46-fold increase compared to the average daily activity observed over the previous 30 days.

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

This is the highest single-day activity seen on the SonicWall SonicOS API Scanner tag in the last 90 days. It shows a big, planned effort to check exposed firewall interfaces.

Hackers Scan SonicWall Firewalls

Earlier this year, GreyNoise researchers noticed a rise in activity that came before the announcement of CVE-2026-0400, a SonicWall flaw shared on February 24, 2026.

The increases on January 18, January 30, and February 14 happened 37, 25, and 10 days before that news, respectively.

This connection does not prove a new weakness, but it shows a pattern where attackers start looking for problems before public announcements or attacks.

GreyNoise says the recent increase is a signal, not a guess, but it could show early surveillance.

Analysis of the GreyNoise scanning traffic reveals consistent tooling and infrastructure:

Tooling: Nearly 99% of requests use a Chrome 119 user-agent on Linux x86_64, matching earlier campaigns where 94.5% of traffic used the same fingerprint.

Source infrastructure: Around 56% of traffic originates from networks in the Netherlands and 44% from Ukraine, accounting for over 99% of observed sessions.

ASN concentration: A single autonomous system (AS211736) contributes roughly half of the total scanning volume.

Targeted services: Ports 80 and 8080 (HTTP) are almost exclusively targeted, indicating focus on web-based management interfaces.

Classification: The majority of source IPs are categorized as suspicious by GreyNoise.

Security teams that use SonicWall devices should act quickly to lower risks and be ready for possible hacking attempts:

Immediate actions:

Limit SonicOS management API and SSL VPN access to trusted IPs only.
Remove public access to firewall management interfaces.
Enforce MFA for all SSL VPN users.
Audit systems for unauthorized admin accounts created after May 1, 2026.
Deploy dynamic IP blocklists to filter suspicious sources.

Even though there is no new flaw confirmed, the amount and type of this activity show that defenders should see this increase as a warning sign.

Check Also

BlueField

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This …