SonicWall Report Finds Misconfigurations Driving Surging Cyberattacks in 2025

Simple errors like default passwords and exposed admin panels fueled widespread attacks in 2025

MILPITAS, Calif. — September 16, 2025 — SonicWall today released a new threat brief, revealing that misconfigurations have fueled more than 9.5 million cyberattacks in the first half of the year. The report highlights how basic errors such as directory access misconfigurations, accidental data exposure and authentication failures continue to drive breaches despite the widespread availability of security tools.

According to the report, nearly 70% of organizations faced at least one authentication bypass attempt between January and June. Many incidents were linked to long-standing vulnerabilities like Fortra GoAnywhere MFT, which attackers continue to exploit years after its initial discovery. Consulting services firms were disproportionately impacted, accounting for 46% of all misconfiguration-related detections.

“While the cybersecurity industry often focuses on zero-day exploits and advanced persistent threats, attackers are still finding success through simple missteps,” said Doug McKee, Executive Director of Threat Research at SonicWall. “The fact that misconfigurations remain one of the leading causes of breaches shows that organizations need better visibility, consistent processes and operational support to avoid repeating the same mistakes.”

The threat brief notes that approximately 88% of misconfigurations fall into three categories:

  • Directory access misconfigurations (45%)
  • Accidental data exposure (24%)
  • Authentication failures (19%)

Gartner projects that 99% of cloud security failures will be customer-side misconfigurations by year-end, further underscoring the urgency for organizations to address configuration drift and operational discipline.

SonicWall solutions, such as its Managed Protection Security Suite (MPSS) and SonicSentry MXDR, provide 24/7 monitoring, configuration management, and rapid response for organizations that lack internal bandwidth. Combined with tools like Network Security Manager (NSM), SonicWall AI Monitoring and Insights (SAMI), and Cloud Secure Edge (CSE), customers gain unified control and Zero Trust capabilities across endpoints, networks and identity systems.

“Misconfigurations are not obscure technical flaws; they are operational challenges that persist because they are difficult to manage at scale,” continued McKee. “SonicWall is committed to helping organizations overcome these challenges with a combination of technology, people and processes that reduce complexity and strengthen protection.”

The full September 2025 Threat Brief is available here: https://www.sonicwall.com/resources/brief/sonicwall-threat-brief-2025-the-misconfiguration-epidemic

About SonicWall
SonicWall
is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides seamless protection against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit www.sonicwall.com or follow us on Twitter, LinkedIn, Facebook and Instagram

latest stories

  • SonicWall 威脅資料揭示網路攻擊深度;促進對託管服務提供商 (MSP) 的需求
    隨著威脅行為者採取多樣化策略,總體入侵嘗試量攀升 (+20%) - 全球攻擊數量增加 勒索軟體全年加劇 (2 小時內增加 +27%),在夏季達到頂峰 (+37%) 騎劫挖礦總量 – 全球激增 +659% 物聯網漏洞利用 (+15%) 和加密威脅 (+117%) 也呈上升趨勢 SonicWall 發現了 293,989 種「前所未見」的惡意程式變體 – 每天 805 種 加利...
    Read More
  • SonicWall 履行承諾,透過託管式端點服務提供更大靈活性
    Sonicwall 透過 24/7 安全運營中心 (SOC) 擴展託管式偵測及回應 (MDR) 解決方案,透過託管式解決方案套件推動合作夥伴發展 加利福尼亞州米爾皮塔斯 — 2024 年 2 月 8 日 — 根據其重要的通路合作夥伴之意見反應,Sonicwall 今日宣布其首次提供多項專為 MSP 量身定製的託管服務。SonicWall 將端點供應商新增至其託管式偵測及回應 (MDR) 解決方案,...
    Read More
  • SonicWall 加快發展 SASE 產品;收購可靠的雲端安全提供商
    SonicWall 透過收購 Banyan Security 強化其針對現代遠端辦公員工的雲端安全平台 加利福尼亞州,米爾皮塔斯 — 2024 年 1 月 3 日 — 全球網路安全領導者 SonicWall 今日宣佈收購 Banyan Security,一家為現代員工提供安全服務邊緣 (SSE) 解決方案的領先提供商。此次收購強化了 SonicWall 的產品組合,為正在替換 SSE 解決方案(包...
    Read More