
New VPN Attack Warning — What You Need To Know
VPN Security Has A History Of Compromise
Let's get the virtual elephant out of the private networking room before moving on to the latest VPN warning. A VPN app, far from being a security silver bullet, can actually just be an extension of your threat surface. How many examples would you like me to provide as evidence of this? I'll throw Google's warning about a backdoor bundled with a free VPN app into the ring for starters, or how about the FBI warning concerning Medusa ransomware compromising VPN credentials? One more? OK, the recent Katz Stealer warning as this threat also targeted VPN credentials.
The latest VPN security warning comes from Julian Tuin, a senior threat intelligence researcher at Arctic Wolf Labs, who has confirmed that 'an increase in ransomware activity targeting SonicWall firewall devices for initial access,' has been observed late in July. More specifically, Tuin said, 'multiple pre-ransomware intrusions were observed within a short period of time, each involving VPN access through SonicWall SSL VPNs.'
While there can, and should, be questions asked as to whether these attacks could have occurred thanks to brute force or credential stuffing methods in at least some cases, Tuin warned that the 'available evidence points to the existence of a zero-day vulnerability.' Not least as some of the SonicWall devices were fully security patched and had also had credential rotation applied before the attacks took place. 'Despite TOTP MFA being enabled,' Tuin said, 'accounts were still compromised in some instances.'
I have reached out to SonicWall for a statement and will update this article in due course.
Mitigating The Potential For VPN Attack
Given that the Artic Wolf report revolves around a spike in attacks involving the Akira Ransomware group, known to have compromised more than 300 organizations and with some very high-profile names published to the hacker's data leak site listings, the threat should not be taken lightly. Throw in the fact that SonicWall only recently issued a warning regarding the CVE-2025-40599 vulnerability in SMA 100 appliances, which could see remote code execution if successful, and you would be foolish not to at least mitigate against the potential of attacks.
'Given the high likelihood of a zero-day vulnerability,' Tuin said, 'organizations should consider disabling the SonicWall SSL VPN service until a patch is made available and deployed.'
Meanwhile, SonicWall has previously said that organizations should harden defenses, including security services such as botnet protection that can help detect those targeting SSL VPN endpoints, as well as enforcing multi-factor authentication.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


CNN
38 minutes ago
- CNN
The desperate effort to save an injured Ukrainian soldier
We process your data to deliver content or advertisements and measure the delivery of such content or advertisements to extract insights about our website. We share this information with our partners on the basis of consent. You may exercise your right to consent, based on a specific purpose below or at a partner level in the link under each purpose. Some vendors may process your data based on their legitimate interests, which does not require your consent. You cannot object to tracking technologies placed to ensure security, prevent fraud, fix errors, or deliver and present advertising and content, and precise geolocation data and active scanning of device characteristics for identification may be used to support this purpose. This exception does not apply to targeted advertising. These choices will be signaled to our vendors participating in the Transparency and Consent Framework. The choices you make regarding the purposes and vendors listed in this notice are saved and stored locally on your device for a maximum duration of 1 year.
Yahoo
42 minutes ago
- Yahoo
What we know about electric car grants worth £1,500 as first eligible EV models confirmed
The government has unveiled a series of Citroen models eligible under the government's new £650 million electric car grants scheme. The first electric car models eligible for the government's new £650 million electric car grants have been announced. Drivers will be able to save £1,500 with the purchase of new Citroen e-C3, e-C4, e-C5 and e-Berlingo cars, the Department for Transport (DfT) said. The discount will be automatically applied at the point of sale, and will enable motorists purchasing a new electric car to save either £1,500 or £3,750, depending on sustainability criteria. The government's vow to make it cheaper to buy an electric car comes as part of its goal of banning the sale of new fully petrol or diesel cars and vans from 2030. Transport Secretary Heidi Alexander said: 'With the first four models approved today, and more to come over the next few weeks, this summer we're making owning an electric car cheaper, easier and a reality for thousands more people across the UK." Under the government's zero emission vehicle (Zev) mandate, at least 28% of new cars sold by each manufacturer in the UK this year must be zero emission, which generally means pure electric. Across all manufacturers, the figure during the first half of the year was 21.6%. Alexander has already announced £63m worth of funding to boost charging infrastructure, including £25m of support for local authorities to provide at-home charging for motorists who don't have driveways. Another £8m will be spent on powering electric ambulances and medical fleets across 200 sites within the NHS, while road signs for EV charging hubs will be introduced on major A-roads in England. What do we know about the new subsidies for EV drivers? The grants will be funded through a new £650m scheme announced on 14 July, which will be restricted to vehicles priced up to £37,000. The Department for Transport (DfT) said at the time that 23 new models were available for less than £30,000. Amounts given will be based on a car's 'sustainability criteria', the DfT said, with the greenest vehicles placed in band one, meaning a grant of up to £3,750. Band two vehicles will receive up to £1,500. Edmund King, AA president, said: 'This discount of £1,500 for some more affordable EVs will help a number of those with tighter budgets. We look forward to seeing the full list of discounts up to £3,750 on more models to really push the market forward.' Ian Plummer, commercial director of online vehicle marketplace Auto Trader, previously said 'any incentives' to help people buy an electric car are welcome as many drivers are 'put off by the high upfront cost'. Prior to the government's announcement, The Telegraph reported that the grants would provide a huge boost for Nissan, which has a plant in Sunderland, but would be unlikely to help Tesla, whose cars are generally beyond the scheme's price range. How many people are buying EVs? In the first half of this year, electric car sales in the UK increased by a third, according to figures from the Society of Motor Manufacturers and Traders (SMTT) lobby group. Sales of battery electric cars rose by 34.6% to 224,838 vehicles between the start of January and the end of June. Of the 191,200 cars sold in the UK in June, a quarter (almost 47,400) were electric vehicles. The government wants to phase out the sale of new petrol and diesel cars from 2030 onwards, although hybrids can be sold until 2035. It says all new cars and vans will have to be 100% zero emission by 2035. How much more expensive are electric cars to buy? The average cost to buy an electric car in the UK is currently about £46,000, according to financial researchers NimbleFins, although it says that prices range from £14,995 (for a Dacia Spring Electric) to as much as £330,000 for a Rolls-Royce Spectre. Among luxury electric brands such as Tesla, Porsche, Audi, Jaguar and Mercedes, the average cost is about £69,000, while a non-luxury EV is about £33,000 on average. NimbleFins said the cost of an average small car is about £22,000, rising to £27,000 for a medium-sized car and £35,000 for an SUV, inclusive of petrol and electric models. The Electric Car Scheme says the average petrol car costs £21,964, compared to about £49,000 for an EV. How much do electric vehicles cost to run? The average cost of running a car in the UK is £3,357, according to NimbleFins. This includes fuel, car insurance, repairs, road tax and the purchase or depreciation per year. It said that despite electricity prices currently being high, fuel costs much less with an EV than a petrol or diesel engine. The average cost for a mile of driving is about 7p on a standard electricity tariff or as low as 2p per mile on a time of use EV tariff, charging the vehicle at off-peak times, such as during the night. For a petrol or diesel car, NimbleFins says the cost of fuel per mile can be anything between 13p and 17p. The Electric Car Scheme says drivers of EVs can save up to £1,500 per year over 10,000 miles in fuel costs than with a petrol or diesel. Read more Major problem with plan to let EV drivers charge outside their homes (BristolLive) China's electric car revolution hammers demand for oil (The Telegraph) Volkswagen reports electric vehicles sales surge in 2025 (DW)
Yahoo
an hour ago
- Yahoo
China's Baidu to deploy robotaxis on rideshare app Lyft
Chinese internet giant Baidu plans to launch its robotaxis on rideshare app Lyft in Germany and Britain in 2026, pending regulatory approval, the two companies said on Monday. Last month, Baidu announced a similar agreement with Uber in Asia and the Middle East as it seeks to take pole position in the competitive autonomous driving field both at home and abroad. Lyft and Baidu said Monday that "in the following years" the fleet of Apollo Go driverless cars will be expanded to thousands of vehicles across Europe. They did not specify which other countries the cars would be deployed in, and it was not clear how long it might take to gain regulatory approval for the initial deployment. Driverless taxis are already on some roads with limited capacity in the United States and China, most notably in the central city of Wuhan, where a fleet of over 500 can be hailed by app in designated areas. Their reach is spreading, with Shanghai's financial district Pudong recently announcing a batch of permits for multiple companies to operate robotaxis. China's tech companies and automakers have poured billions of dollars into self-driving technology in recent years, with intelligent driving the new battleground in the country's cutthroat domestic car market. Baidu is not alone among Chinese companies in searching to expand its foothold abroad. Its rival WeRide is also active in the Gulf region, and in January announced it had been picked to lead a small pilot project in Switzerland. another Chinese company, said in May that it had signed a deal to launch its self-driving taxis on Uber in "a key market in the Middle East later this year". San Francisco-based Lyft in April said it had agreed to buy German taxi app Freenow, planting a flag in the European market. The acquisition marked Lyft's "most significant expansion outside North America", the group said. isk/reb/lb