ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices

Threat Score:
54
The Hacker News
1 month ago
Part of cluster #1304

Overview

Sophos and SonicWall have alerted users of critical security flaws in Sophos Firewall and Secure Mobile Access (SMA) 100 Series appliances that could be exploited to achieve remote code execution. The two vulnerabilitiesimpactingSophos Firewall are listed below - CVE-2025-6704(CVSS score: 9.8) - An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall...

Continue Reading on Original Site

Related Articles

5 articles
1
Amazon disrupts Russian APT29 hackers targeting Microsoft 365

Amazon disrupts Russian APT29 hackers targeting Microsoft 365

BleepingComputer • 2 hours ago

Amazon disrupts Russian APT29 hackers targeting Microsoft 365 Bill Toulas September 1, 2025 11:35 AM 0 Researchers have disrupted an operation attributed to the Russian state- threat group Midnight Blizzard, which sought access to Microsoft 365 accounts and data. Also known as APT29, the hacker group compromised websites in a watering hole campaign to redirect selected targets "to malicious infrastructure designed to trick users into authorizing attacker-controlled devices through Microsoft’s de

Score
86
Read more
2

Amazon Stops Russian APT29 Watering Hole Attack Exploiting Microsoft Auth

Infosecurity Magazine • 8 hours ago

The campaign shows APT29’s intentions to “cast a wider net in their intelligence collection efforts,” said Amazon

Score
85
Read more
3

Grandes ataques cibernéticos, ataques de ransomware e violaciones de datos: agosto de 2025

Ciberseguridadpyme • 8 hours ago

Revisión de los ⁢principales⁤ Ataques cibernéticos, ataques⁤ de Ransomware y‌ Violacias de Datos: Agosto 2025 El ciberespacio Ha​ Sido Durante Mucho Tiempo Un Campo de Batalla ⁤Tecnológico para Luchar contra ​la Ciberdelincuencia. Han ⁢Pasado Cinco Años Desde 2020, Un Año Marcado⁣ Por Un Número ‌sin precedentes de Ciberataques. Una organización​ Medida Que ⁢Las y⁣ las⁢ […] La entrada Grandes ataques cibernéticos, ataques de ransomware e violaciones de datos: agosto de 2025 se publicó primero en

Score
85
Read more
4

Ransomware Attack on Pennsylvania’s AG Office Disrupts Court Cases

Infosecurity Magazine • 6 hours ago

Pennsylvania’s Attorney General confirmed the OAG had refused to pay a ransom demand to the attackers after files were encrypted

Score
84
Read more
5

Amazon Disrupts Russian APT29 Watering Hole Targeting Microsoft Authentication

Hackread • 7 hours ago

Amazon has disrupted a Russian APT29 watering hole campaign that used compromised sites to target Microsoft authentication with…

Score
84
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

CVES
CVE-2024-13973
CVE-2024-13974
CVE-2025-40599
CVE-2025-6704
CVE-2025-7382
AGENCIES
NCSC
National Cyber Security Centre
COMPANIES
Google
ATTACK TYPES
Remote Code Execution
SQL Injection
VULNERABILITIES
Business Logic Vulnerability
Command Injection
RCE
Remote Code Execution
SQL Injection
SECURITY VENDORS
Sophos
APT GROUPS
APT41
MITRE ATT&CK
Proxy
RANSOMWARE
Light
One
ARTICLE INFORMATION
Article #4654
Published 1 month ago
The Hacker News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration