The UK National Cyber Security Centre urged vendors to make forensic observability a standard feature in firewalls, VPN gateways, and other network devices, arguing that defenders need supported access to telemetry, logs, configuration state, memory, stored data, and software transparency to investigate compromises without relying on reverse engineering or zero-day exploits. The call builds on NCSC guidance published in 2025 for digital forensics and protective monitoring, which recommends full storage acquisition through standard interfaces, clear handling of redacted volatile data, strong authentication on collection interfaces, and hardware and firmware protections such as secure boot and TPM-backed safeguards. NCSC said it is also working with international partners on a reference architecture, while CISA’s Secure by Design initiative reinforces pressure on manufacturers to build these capabilities in from the outset.
The push comes as vendors and defenders report growing pressure on edge devices from credential-based attacks. Huntress warned that a broad credential stuffing campaign hit SonicWall VPN and firewall appliances, compromising accounts at about 30 organizations after attackers tested stolen or guessed credentials against internet-facing portals from DigitalOcean-hosted infrastructure. Sophos, citing attacks on internet-facing Sophos Firewall devices and lessons from the FortiBleed campaign, said it had seen brute-force and credential-stuffing activity against user accounts but no vulnerability-driven widespread compromise; in response, it changed MFA onboarding, added expiration controls, developed dynamic brute-force lockout and MFA for SSH, and committed to improved fleet forensic capture and expanded attack telemetry aligned with NCSC guidance.

Map this exposure pattern across your cloud, code, and identities.
7 events from the most recent confirmed update back to the earliest known activity.
Sophos published a Secure by Design update describing firewall hardening work over the past year, including architectural changes, expanded Linux Sensor deployment, improved hotfix visibility, scheduled firmware updates, and AI-assisted vulnerability hunting. It also said non-volatile forensic capture remains a gap and committed to fleet forensic capture and expanded attack telemetry.
Huntress publicly warned of an active and rapidly growing credential stuffing campaign affecting SonicWall VPN and firewall appliances, with 30 organizations already seeing compromised accounts. It linked the activity to five DigitalOcean-hosted IP addresses and urged credential resets, access restrictions, log review, and MFA enforcement.
The NCSC said it is working with international partners on a reference architecture for forensic observability for network devices, aiming to make supported investigative access a standard capability.
Huntress telemetry showed the number of affected accounts and organizations increasing across 2026-07-25 to 2026-07-27, indicating a broad and opportunistic campaign targeting internet-facing SonicWall remote access portals.
Huntress first detected the credential stuffing activity on 2026-07-25 after observing an anomalous spike in successful SonicWall logins from a suspicious autonomous system.
Sophos said attacks on internet-facing Sophos Firewall devices involved credential brute-forcing and stuffing against user-level accounts, with no vulnerability involved and no signs of widespread compromise. In response, it redesigned MFA onboarding and developed additional protections including dynamic brute-force lockout and MFA for SSH.
The UK NCSC published guidance on digital forensics and protective monitoring for devices and appliances, covering volatile and non-volatile data collection, redaction, decryption, and protections against unauthorized extraction.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceitsecurityguru.org
Open sourcencsc.gov.uk
Open sourcesophos.com
Open sourcencsc.gov.uk
Open sourcethreatbear.co
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.