This Week in Security: July 30, 2026

ArisGate Security Team

•
July 30, 2026
ARISGATE SECURITY BRIEF · CREDENTIAL & ACCESS RISK
A password that leaked years ago might still be your firm's front door.
A fast-growing credential stuffing campaign is targeting SonicWall remote access devices, and it works because people reuse passwords.

Huntress is tracking a fast growing credential stuffing campaign against SonicWall remote access devices, with confirmed compromises climbing daily since late July. The attackers are testing large batches of leaked username and password pairs against internet facing logins until one works, a tactic Huntress has seen repeat against SonicWall SSL VPN products for over a year because it keeps succeeding.

Why this matters for your firm

Any firm using a firewall or SSL VPN appliance to let staff work remotely is exposed the same way. A password that leaked years ago from an unrelated account can still protect a firm's remote access today, and that door leads straight to case files and trust account records.

Florida Bar Rule 4-1.6

Rule 4-1.6 requires reasonable safeguards on the door staff use every day to work remotely, not just email.

What to do this week

  1. Confirm multi factor authentication is enabled on every remote access login, not just email.
  2. Review login logs for unfamiliar IP addresses or unusual hours.
  3. Disable unused accounts.
  4. Confirm your appliance firmware is current.

How ArisGate helps

ArisGate closes exactly these gaps before an attacker finds them. Schedule a free security audit today.

Schedule a Call