Tag: Akira ransomware

Akira ransomware breaching MFA-protected SonicWall VPN accounts
News

Akira ransomware breaching MFA-protected SonicWall VPN accounts

Even if OTP MFA is set on accounts, threat actors are still successfully entering in to SonicWall SSL VPN devices as a result of ongoing Akira ransomware attacks. Although the precise technique is still unknown, researchers believe that this might be accomplished by using OTP seeds that have already been stolen. Researchers suspected that a zero-day vulnerability was being used to hack SonicWall SSL VPN devices after BleepingComputer revealed in July that the Akira ransomware operation was using these devices to compromise business networks. But in the end, SonicWall connected the assaults to an incorrect access control vulnerability known as CVE-2024-40766 that was made public in September 2024. Even after the security patches were implemented in August 2024, threat actors have ...
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
News

Akira ransomware abuses CPU tuning tool to disable Microsoft Defender

In attacks from security tools and EDRs operating on target computers, the Akira ransomware disables Microsoft Defender by misusing a genuine Intel CPU tuning driver. Threat actors register the misused driver, 'rwdrv.sys' (used by ThrottleStop), as a service in order to obtain kernel-level access. 'hlpdrv.sys,' a malicious malware that manipulates Windows Defender to disable its defenses, is probably loaded by this driver. This is an example of a "Bring Your Own Vulnerable Driver" (BYOVD) attack, in which threat actors utilize authentic signed drivers with known flaws or vulnerabilities that could be exploited to escalate privileges. A malicious tool that disables Microsoft Defender is then loaded using this driver read more about Akira ransomware abuses CPU tuning tool to disabl...
SonicWall Investigating Potential SSL VPN Zero- Day After 20+ Targeted Attacks Reported
News

SonicWall Investigating Potential SSL VPN Zero- Day After 20+ Targeted Attacks Reported

According to SonicWall, it is currently looking into claims of an increase in Akira ransomware actors in late July 2025 to see whether there is a new zero-day vulnerability. Cyber incidents utilizing Gen 7 SonicWall firewalls with SSLVPN enabled have significantly increased during the last 72 hours, according to a statement from the network security provider. To find out if these instances are related to a previously revealed vulnerability or if a new vulnerability could be to blame, we are actively looking into them. Until further notice, enterprises utilizing Gen 7 SonicWall firewalls are encouraged to take the actions listed below while SonicWall conducts further research read more about SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported. ...
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices
News

Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices

Akira ransomware attacks have targeted SonicWall SSL VPN devices as part of a recent spike in activity noted in late July 2025. Julian Tuin, a researcher at Arctic Wolf Labs, reported that several pre-ransomware intrusions were detected in a brief period of time among the intrusions examined, all of which used VPN connection using SonicWall SSL VPNs. Given that some of the events included fully-patched SonicWall devices, the cybersecurity firm hypothesized that the assaults might be taking use of a zero-day vulnerability—a security fault in the appliances that has not yet been identified. Credential-based assaults for initial access haven't been completely ruled out, though. Although Arctic Wolf said that it has seen similar malicious VPN logins as early as October 2024, the spik...
Critical Veeam Vulnerability Exploited to Spread Akira and Fog Ransomware
News

Critical Veeam Vulnerability Exploited to Spread Akira and Fog Ransomware

Threat actors are actively trying to use the Akira and Fog ransomware to take advantage of a security hole in Veeam Backup & Replication that has been addressed. According to cybersecurity provider Sophos, it has been monitoring a number of assaults over the last month that use CVE-2024-40711 and compromised VPN credentials to establish a local account and spread ransomware. The CVSS has assigned a rating of 9.8 out of 10.0 to CVE-2024-40711, which is a critical vulnerability that permits unauthenticated remote code execution. Early in September 2024, Veeam addressed it with Backup & Replication version 12.2. Security flaws have been identified and reported by Florian Hauser, a security researcher at Germany's CODE WHITE read more about Critical Veeam Vulnerability Exploi...
CISA Warning Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability
News

CISA Warning Akira Ransomware Exploiting Cisco ASA/FTD Vulnerability

Following reports that it's likely being exploited in Akira ransomware attacks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a now-patched security flaw affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software to its list of known exploited vulnerabilities (KEV) on Thursday. The high-severity information disclosure flaw in question is CVE-2020-3259 (CVSS score: 7.5), which might enable an attacker to access memory contents on a compromised device. Cisco corrected it as part of upgrades that were made available in May 2020. The cybersecurity company Truesec reported late last month that it had discovered evidence indicating that Akira ransomware attackers had used it as a weapon read more CISA Warning Akira Ransomware Exp...
US energy firm shares how Akira ransomware hacked its systems
News

US energy firm shares how Akira ransomware hacked its systems

US energy services company BHI Energy reveals, in an unusual act of openness, how the Akira ransomware operation broke into their networks and took the data during the attack. BHI Energy, a division of Westinghouse Electric Company, provides specialized engineering services and workforce solutions to support government and private-run power generation facilities, including nuclear, wind, solar, and fossil fuel units as well as transmission and distribution lines for energy. BHI Energy gives affected parties a thorough explanation of how the Akira ransomware group infiltrated its network on read more US energy firm shares how Akira ransomware hacked its systems. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of...
Akira ransomware targets Cisco VPNs to breach organizations
News

Akira ransomware targets Cisco VPNs to breach organizations

There is growing proof that the Akira ransomware uses Cisco VPN (virtual private network) equipment as an entry point into business networks in order to hack into them, steal data, and ultimately encrypt it. Launched in March 2023, the Akira ransomware operation is a relatively recent ransomware operation. Later, the organization added a Linux encryptor to target VMware ESXi virtual machines. Cisco VPN solutions are commonly used by employees who work remotely and are widely embraced across various industries to allow secure, encrypted data transmission between users and corporate networks read more Akira ransomware targets Cisco VPNs to breach organizations. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of t...