Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices

Akira ransomware attacks have targeted SonicWall SSL VPN devices as part of a recent spike in activity noted in late July 2025.

Julian Tuin, a researcher at Arctic Wolf Labs, reported that several pre-ransomware intrusions were detected in a brief period of time among the intrusions examined, all of which used VPN connection using SonicWall SSL VPNs.

Given that some of the events included fully-patched SonicWall devices, the cybersecurity firm hypothesized that the assaults might be taking use of a zero-day vulnerability—a security fault in the appliances that has not yet been identified. Credential-based assaults for initial access haven’t been completely ruled out, though.

Although Arctic Wolf said that it has seen similar malicious VPN logins as early as October 2024, the spike in attacks affecting SonicWall SSL VPNs was initially reported read more about Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *