SonicWall Releases Advisory for Customers after Security Incident

Release Date: 22nd of September 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and individuals that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

SonicWall has released a security advisory to assist their customers with protecting systems impacted by the MySonicWall cloud backup file incident. SonicWall’s investigation found that a malicious actor performed a series of brute force techniques against their MySonicWall.com web portal to gain access to a subset of customer’s preference files stored in their cloud backup. While credentials within the files were encrypted, the files also included information that actors can use to gain access to customer’s SonicWall Firewall devices

TIP: Important Update

 

References

  1. https://www.cisa.gov/news-events/alerts/2025/09/22/sonicwall-releases-advisory-customers-after-security-incident
  2. https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330
  3. https://www.youtube.com/watch?v=LMkZJEIS1Ek
  4. https://psirt.global.sonicwall.com/vuln-list