Tech Notes · Security
Rapid response to reports of network attacks
How Macktez and its SOC partner Huntress responded to a reported SonicWall firewall vulnerability by suspending SSL VPN service to protect client networks.
August 22, 2025
Earlier this month, Huntress, one of our SOC partners, alerted us to a developing cybersecurity event targeting SonicWall firewalls. Here is what happened and how we responded to protect client networks.
What just happened
Huntress specializes in proactive threat hunting rather than just prevention. It was one of two companies (the other was Arctic Wolf) to first recognize a pattern of attack across a large number of SonicWall devices.
Of particular concern, attackers were able to bypass MFA on firewalls running one of the more modern and frequently used kinds of VPN to deploy ransomware. MFA (multi-factor authentication) is the layer of additional security that lets cybersecurity officers and Macktez Team Members sleep at night. In this case, evidence suggested that these firewalls — the primary point of defense for any local network — were vulnerable even with MFA enabled.
Huntress also alerted SonicWall. Though SonicWall was not able to immediately confirm the attack pattern or identify a root cause, Huntress and Arctic Wolf provided enough evidence to convince SonicWall that the threat was real and needed to be contained.
Erring on the side of security, SonicWall advised all impacted users to disable SSL VPN immediately while its investigation continued. We followed that recommendation right away for all impacted client networks: we suspended SSL VPN service to secure their environments until a permanent update was issued by SonicWall.
Why it's important
This vulnerability turned out not to be a "zero-day" exploit (a cyberattack that preys on a previously unknown vulnerability), as was initially suspected. But the overall response of the security community — and that of our security team — was decisive in identifying the service that could be exploited and shutting it down to protect clients from an active exploit. Before SonicWall could provide a more nuanced remedy, it made sense to just close down the road cyberattackers were riding.
Not every reported vulnerability requires immediate action, but in this case the potential exposure to ransomware and the strong reputations of the entities reporting on the event were enough to provoke a quick response all around.
What we learned
Partnering with the cybersecurity team at Huntress gives Macktez and our clients access to a level of cybersecurity expertise and 24/7 vigilance that would be difficult and costly to achieve independently.
By focusing on human-powered threat hunting, rapid response, and a deep understanding of the tactics used by modern adversaries, Huntress helps businesses defend against current threats and build a more resilient, secure environment.
What you should know
Malicious actors continually probe networks and devices, seeking to identify vulnerabilities. Most organizations, on their own, don't have the resources to protect themselves against all these threats. Working with a trusted partner like Macktez to help manage network, device, and identity security is a critical part of modern-day operations.
Looking for a technology partner?
Engage Macktez to identify, define, and solve business challenges with technology. Learn more on our prospective client page or contact us.