Huntress is tracking a fast growing credential stuffing campaign against SonicWall remote access devices, with confirmed compromises climbing daily since late July. The attackers are testing large batches of leaked username and password pairs against internet facing logins until one works, a tactic Huntress has seen repeat against SonicWall SSL VPN products for over a year because it keeps succeeding.
Any firm using a firewall or SSL VPN appliance to let staff work remotely is exposed the same way. A password that leaked years ago from an unrelated account can still protect a firm's remote access today, and that door leads straight to case files and trust account records.
Rule 4-1.6 requires reasonable safeguards on the door staff use every day to work remotely, not just email.
ArisGate closes exactly these gaps before an attacker finds them. Schedule a free security audit today.