
The Box That Lets Your Team Work From Home Is a Target
Most businesses give staff a way to log in from home or on the road. Often that runs through a small appliance sitting at the edge of your network, quietly facing the public internet. It is easy to forget it is there. Attackers do not forget.
Security researchers at Volexity have confirmed that two flaws in SonicWall’s SMA1000 remote-access appliances were being used in real attacks from 22 June 2026, weeks before the vendor or the public knew about them. Chained together, the two issues let an attacker reach parts of the device that were never meant to be exposed, then run commands as the highest-privileged user. In short: complete control of the appliance.
Once in, the attackers installed hidden tools to keep their access and quietly watched traffic passing through the device, including staff usernames and passwords, then used those to move deeper into the network.
What This Means for Your Business
The affected models are SonicWall SMA1000 series appliances (6210, 7210 and 8200v). SonicWall has released fixed firmware in versions 12.4.3-03453 and 12.5.0-02835. If you run one of these, updating is urgent rather than routine.
If you do not run a SonicWall, the lesson still lands. Firewalls and remote-access appliances are internet-facing computers, and they need patching with the same discipline as your laptops. Because they sit between the internet and everything you own, they are exactly where a determined attacker starts.
Three questions worth asking your IT provider this week:
- What device handles our remote access, and is its firmware current?
- Who checks for security updates on it, and how often?
- Would we actually notice if someone logged into it as an administrator?
A clear answer to all three is a good sign. A pause is worth following up on.
Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.
