Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
2 articles · Updated June 23, 2026 -
CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the…
2 articles · Updated June 23, 2026 -
Marquis Software Solutions Data Breach Exposes Customer Data of US Banks
Marquis Software Solutions experienced a ransomware attack on August 14, 2025, leading to the exposure of sensitive customer information, including Social Security Numbers and names. The company serves numerous banks…
6 articles · Updated December 3, 2025 -
Critical Vulnerability in WatchGuard Firebox OS Actively Exploited
A critical vulnerability (CVE-2025-9242) in WatchGuard Firebox OS allows remote unauthenticated attackers to execute arbitrary code. Affected versions include Fireware OS 11.x, 12.x, and 2025.1. The U.S. Cybersecurity &…
3 articles · Updated November 13, 2025 -
Critical Vulnerability in WatchGuard Fireware OS Exposed to Remote Attacks
A critical vulnerability (CVE-2025-9242) in WatchGuard's Fireware OS has been identified, allowing remote unauthenticated attackers to execute arbitrary code on over 54,000 Firebox devices globally. The U.S.…
4 articles · Updated November 14, 2025 -
SonicWall Blames State Actor for Customer Data Breach
SonicWall reported that a state-sponsored threat actor conducted a brute-force attack on its MySonicWall cloud backup service, compromising firewall configuration files of all affected customers. An investigation by…
3 articles · Updated November 6, 2025 -
SonicWall Investigates State-Backed Breach of Cloud Backup Service
SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…
11 articles · Updated November 26, 2025 -
SonicWall SMA1000 Zero-Day Vulnerability Disclosed
SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…
5 articles · Updated December 17, 2025 -
Surge in BaoLoader Malware Campaigns Reported by ReliaQuest
ReliaQuest has reported an increase in malware campaigns utilizing manufactured trust and user interaction, with a notable rise in incidents involving the BaoLoader malware. The company identified spearphishing links,…
2 articles · Updated January 15, 2026
Recent Intelligence Reports
- Bitdefender — www.bitdefender.com · June 23, 2026
- Exploitation Of Sonicwall Vpn — www.huntress.com · June 23, 2026
- CVE-2024-40766 — nvd.nist.gov · June 23, 2026
- CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) — Isc.Sans.Edu · June 23, 2026
- ReliaQuest warns of BaoLoader surge & trust attacks — Securitybrief · January 15, 2026
- ReliaQuest warns of BaoLoader surge & trust attacks — Securitybrief.Au · January 15, 2026
- Sonicwall warns of new SMA1000 zero — Bleepingcomputer · December 17, 2025
- CVE-2025-40602: SonicWall Secure Mobile Access (SMA) 1000 Zero — Tenable · December 17, 2025