Google says threat actors are breaching fully patched, end-of-life cybersecurity company SonicWall's appliances and stealing sensitive data from organizations
Threat actors are stealing sensitive data from organizations by breaching end-of-life appliances made by cybersecurity company SonicWall.
Context & Ripple Effects
SonicWall previously disclosed exploitation of a critical zero-day in its SMA 100 devices, underscoring the long-running exposure of its edge appliances to targeted attacks after the earlier SMA 100 zero-day exploitation. This report matters because the affected systems are described as fully patched yet end-of-life, shifting attention from patch deployment to product lifecycle risk.
Google’s threat reporting has also tracked a broader rise in in-the-wild zero-day exploitation as Google documented more exploited zero-days in 2023. Here, however, the immediate concern is not a newly announced patch gap but continued exposure in hardware no longer supported by its vendor.
First-order effects
- Organizations using the affected end-of-life SonicWall appliances face active data-theft risk despite having applied available patches, requiring incident assessment and removal, replacement, or isolation of those devices.
- SonicWall customers must treat vendor support status as a security control: a patched appliance can remain untenable when no further fixes or mitigations are available.
Second-order effects
- Security teams and procurement functions will place greater weight on hardware refresh plans, support-end dates, and network segmentation when evaluating perimeter products.
- Competing appliance vendors can differentiate on support longevity, migration tooling, and clear end-of-life communications as customers reassess exposure from legacy edge devices.
Third-order effects
- If exploitation of retired but patched appliances persists, vulnerability management will increasingly extend beyond patch compliance toward continuous asset lifecycle management and rapid retirement of unsupported infrastructure.
- The pattern favors ecosystem cyber defense practices in which vendors, threat researchers, and customers coordinate on identifying exposed installed bases; the effectiveness will depend on whether organizations can fund and execute replacements quickly.
The trend: This is one data point in the shift from patch-centric security toward lifecycle-driven defense for internet-facing infrastructure.