Akira ransomware breaching MFA-protected SonicWall VPN accounts

Even if OTP MFA is set on accounts, threat actors are still successfully entering in to SonicWall SSL VPN devices as a result of ongoing Akira ransomware attacks. Although the precise technique is still unknown, researchers believe that this might be accomplished by using OTP seeds that have already been stolen.

Researchers suspected that a zero-day vulnerability was being used to hack SonicWall SSL VPN devices after BleepingComputer revealed in July that the Akira ransomware operation was using these devices to compromise business networks.

But in the end, SonicWall connected the assaults to an incorrect access control vulnerability known as CVE-2024-40766 that was made public in September 2024.

Even after the security patches were implemented in August 2024, threat actors have persisted in using credentials that were previously taken from compromised machines.

SonicWall advised administrators to reset all SSL VPN credentials and make sure the most recent SonicOS software was loaded on their devices after connecting the attacks read more about Akira ransomware breaching MFA-protected SonicWall VPN accounts.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *