A sharp rise in internet-wide scanning activity targeting SonicWall firewall management interfaces has been detected, raising concerns about a potential pre-disclosure reconnaissance phase tied to new vulnerabilities.
Threat intelligence firm GreyNoise reported a significant surge in scanning of SonicWall SonicOS management APIs between May 9 and May 18, 2026.
The most notable spike occurred on May 12, when approximately 597,000 sessions were recorded in a single day.
This represents a roughly 46-fold increase compared to the average daily activity observed over the previous 30 days.
This marks the highest single-day volume recorded on the SonicWall SonicOS API Scanner tag over the past 90 days, indicating coordinated, large-scale reconnaissance targeting exposed firewall interfaces.
GreyNoise researchers highlight that a similar spike earlier this year preceded the disclosure of CVE-2026-0400, a SonicWall vulnerability disclosed on February 24, 2026.
Notably, the spikes on January 18, January 30, and February 14 occurred 37, 25, and 10 days before that disclosure, respectively.
While this correlation does not confirm a new vulnerability, it reflects a recurring pattern where threat actors increase probing activity before public disclosure or exploitation campaigns.
GreyNoise emphasizes that the current spike is a signal, not a prediction, but it may represent early-stage reconnaissance.
Analysis of the GreyNoise scanning traffic reveals consistent tooling and infrastructure:
Security teams using SonicWall devices should take immediate precautions to reduce exposure and prepare for potential exploitation attempts:
Immediate actions:
Short-term monitoring:
Although no new vulnerability has been confirmed, the scale and pattern of this activity suggest that defenders should treat the spike as an early warning signal.
Proactive hardening, continuous monitoring, and rapid patching readiness remain critical to mitigating potential risks associated with SonicWall infrastructure exposure.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…