If you manage a SonicWall firewall for a small business or a handful of clients, stop what you are doing and read this.
According to The Hacker News, SonicWall attacks are a headline item in this week's threat roundup — published July 30, 2026. This is not a theoretical risk or a slow-burn advisory. SOC teams are reporting a measurable spike in SonicWall exploitation cases across multiple firewall generations, with indicators including logins from known-malicious IP addresses and signs that MFA is being bypassed entirely.
For the solo IT admin or small business owner running a SonicWall without a SOC behind you, that last part should hit hard: your MFA may not protect you from this one.
What's Actually Happening
Attackers are actively targeting SonicWall SSL VPN interfaces. The exploitation pattern reported across multiple sources includes:
- Authentication attempts and successful logins originating from IP addresses flagged in threat intelligence feeds
- MFA bypass techniques that allow attackers to authenticate without completing the second factor
- Activity spanning multiple SonicWall hardware generations — this is not limited to one old model
This is the same class of threat we saw play out with Fortinet earlier this year. If you want a frame of reference for how fast these situations escalate, we covered the FortiGate credential leak and its implications for small business firewall decisions in our breakdown of the FortiGate credential leak. The pattern is consistent: edge devices get exploited, credentials get harvested, and small businesses without monitoring are the last to know.
The Immediate Checklist
Do not wait for your next maintenance window. Work through this list today.
1. Check Your Firmware Version Right Now
Log into your SonicWall management interface and confirm your current firmware version. Cross-reference it against SonicWall's published security advisories at psirt.global.sonicwall.com. If you are not on the latest stable release for your appliance generation, schedule the update for tonight — not next week.
2. Pull Your Authentication Logs
Navigate to your VPN authentication logs and look for: - Login successes from geographic locations that make no sense for your users - Login attempts or successes outside normal business hours - Any IP addresses that appear repeatedly across failed and then successful attempts - Accounts that authenticated without completing MFA challenges
If you see any of these, treat it as a confirmed incident and move to containment before continuing.
3. Cross-Reference IPs Against Threat Intel
Export your recent authentication log IPs and run them through a free threat intelligence lookup — VirusTotal, AbuseIPDB, or Shodan will give you a quick read. Known-bad IPs showing up in successful authentication logs is a strong indicator of compromise.
4. Audit Active VPN Users and Sessions
Terminate all active VPN sessions and force re-authentication. Review which user accounts have VPN access and remove anyone who no longer needs it. Stale accounts with VPN permissions are a free pass for attackers who have obtained credentials.
5. Verify MFA Is Actually Enforced
This sounds obvious, but the reports of MFA bypass make it worth confirming that MFA is not just configured — it is enforced and cannot be skipped. Check for any policy exceptions, legacy authentication paths, or service accounts that bypass MFA. We have a deeper look at how MFA bypass works in practice in our post on device code phishing and MFA bypass in Microsoft 365 — the bypass mechanics differ but the concept of finding the gap in your enforcement is the same.
6. Restrict Management Interface Access
Your SonicWall management interface should not be reachable from the public internet. If it is, lock it down to specific trusted IP ranges immediately. This is a basic hardening step that eliminates a large portion of the attack surface.
7. Enable Geo-IP Blocking
If your business has no legitimate reason for VPN connections from foreign countries, enable geo-IP filtering to block authentication attempts from those regions. This will not stop a sophisticated attacker using proxies, but it eliminates a significant volume of opportunistic exploitation.
8. Review and Rotate Credentials
For any accounts with VPN access, force a password reset. If you have reason to believe a session was compromised, treat those credentials as burned and rotate everything associated with that account — not just the VPN password.
If You Think You Are Already Compromised
If your log review turns up indicators of unauthorized access, do not try to quietly patch and move on. The right steps are:
- Isolate the affected environment if possible
- Preserve your logs before they rotate
- Notify your cyber insurance carrier — most policies require prompt notification
- Engage an incident response resource
Speaking of insurance: an active exploitation event like this is exactly the scenario your carrier will ask about at renewal. If you have not documented your patching and hardening actions, now is a good time to start. We covered what insurers actually look for in our cyber insurance renewal security controls checklist.
The Bigger Picture
Edge devices — firewalls, VPN concentrators, remote access gateways — are the most targeted infrastructure category in small business environments right now. They sit on the perimeter, they are often under-monitored, and when they are running outdated firmware they become an open door.
The SonicWall situation is active today. The Fortinet situation was active a few months ago. There will be another one after this. The pattern does not change; only the vendor name does.
The answer is not to panic-replace your hardware every time a CVE drops. The answer is to have a repeatable process: patch fast, audit regularly, and know what normal looks like in your environment so you can spot what is not.
Take Action
Reactive patching is necessary right now — but it is not a long-term strategy. Proactive scanning catches misconfigurations, exposed services, and known vulnerabilities before attackers find them first.
Oscar Six Security's Radar gives solo IT admins and small business owners an affordable, no-fluff vulnerability scan for $99 — so you know exactly what your external attack surface looks like before the next advisory drops.
Focus Forward. We've Got Your Six.