SonicWall today warned of an “imminent” ransomware campaign targeting its older Secure Mobile Access (SMA) and Secure Remote Access (SRA) products and advised customers to either update their firmware or immediately disconnect their appliances and change all related passwords.
“Organizations that fail to take appropriate actions to mitigate these vulnerabilities on their SRA and SMA 100 series products are at imminent risk of a targeted ransomware attack,” the security alert said.
Threat researchers at Mandiant, which also discovered the SolarWinds breach in December, alerted SonicWall that cybercriminals using stolen credentials were trageting SMA 100 series and SRA products running unpatched and end-of-life 8.x firmware. This is a known vulnerability that SonicWall patched in newer firmware versions released this year.
“The affected end-of-life devices with 8.x firmware are past temporary mitigations,” the alert said. “Continued use of this firmware or end-of-life devices is an active security risk.”
However, the vendor said it will provide a complimentary, virtual SMA 500v until Oct. 31 for customers with end-of-life devices that cannot upgrade to 9.x or 10.x firmware. This should provide those customers “sufficient time to transition to a product that is actively maintained,” it added.
SMA 1000 series products are not affected by the vulnerability.
In an emailed statement to SDxCentral, SonicWall said that it “immediately and repeatedly contacted impacted organizations of mitigation steps and update guidance.”
“Even though the footprint of impacted or unpatched devices is relatively small, SonicWall continues to strongly advise organizations to patch supported devices or decommission security appliances that are no longer supported, especially as it receives updated intelligence about emerging threats,” the statement said. “The continued use of unpatched firmware or end-of-life devices, regardless of vendor, is an active security risk.”
SonicWall recently noted that May, with 62.3 million attacks, saw the most ransomware attacks since it started tracking them in 2013, while April set the previous high at 48.3 million. In fact, between Jan. 1 and the end of May alone, SonicWall recorded 226.3 million ransomware attacks, a 116% increase over 2020.
“The bombardment of ransomware attacks is forcing organizations into a constant state of defense rather than an offensive stance,” SonicWall CEO Bill Conner wrote in an earlier email to SDxCentral.
The SonicWall warning follows a slew of high-profile ransomware attacks and comes as another report found ransomware now accounts for nearly two-thirds of all malware attacks.
According to Positive Technologies’ Cybersecurity Threatscape Q1 2021 research, also published today, the number of attacks increased by 17% compared to the first quarter of 2020, with 77% being targeted attacks.
Cybercriminals attacked government institutions, industrial companies, scientific organizations, and educational institutions the most. Their main targets are personal data and credentials, and attacks on organizations are also aimed at stealing commercial secrets.
Comments