/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google says threat actors are breaching fully patched, end-of-life cybersecurity company SonicWall's appliances and stealing sensitive data from organizations

Threat actors are stealing sensitive data from organizations by breaching end-of-life appliances made by cybersecurity company SonicWall.

The Record Jonathan Greig

Context & Ripple Effects

SonicWall previously disclosed exploitation of a critical zero-day in its SMA 100 devices, underscoring the long-running exposure of its edge appliances to targeted attacks after the earlier SMA 100 zero-day exploitation. This report matters because the affected systems are described as fully patched yet end-of-life, shifting attention from patch deployment to product lifecycle risk.

Google’s threat reporting has also tracked a broader rise in in-the-wild zero-day exploitation as Google documented more exploited zero-days in 2023. Here, however, the immediate concern is not a newly announced patch gap but continued exposure in hardware no longer supported by its vendor.

First-order effects

  • Organizations using the affected end-of-life SonicWall appliances face active data-theft risk despite having applied available patches, requiring incident assessment and removal, replacement, or isolation of those devices.
  • SonicWall customers must treat vendor support status as a security control: a patched appliance can remain untenable when no further fixes or mitigations are available.

Second-order effects

  • Security teams and procurement functions will place greater weight on hardware refresh plans, support-end dates, and network segmentation when evaluating perimeter products.
  • Competing appliance vendors can differentiate on support longevity, migration tooling, and clear end-of-life communications as customers reassess exposure from legacy edge devices.

Third-order effects

  • If exploitation of retired but patched appliances persists, vulnerability management will increasingly extend beyond patch compliance toward continuous asset lifecycle management and rapid retirement of unsupported infrastructure.
  • The pattern favors ecosystem cyber defense practices in which vendors, threat researchers, and customers coordinate on identifying exposed installed bases; the effectiveness will depend on whether organizations can fund and execute replacements quickly.

The trend: This is one data point in the shift from patch-centric security toward lifecycle-driven defense for internet-facing infrastructure.

Discussion

  • @jamieantisocial J⩜⃝mie Williams on x
    tricky tricky. [image]
  • @mandiant @mandiant on x
    A financially motivated threat actor, #UNC6148, is targeting fully patched, end-of-life SonicWall SMA 100 appliances. In this latest activity, they deploy a new persistent backdoor we track as OVERSTEP. 🔗 Full details and defensive recommendations: https://cloud.google.com/... [i…