Tag: Rapid7

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers
News

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers

SonicWall devices are still being targeted by threat actors connected to the Akira ransomware group in order to get initial access. According to cybersecurity company Rapid7, SonicWall appliance invasions have increased within the previous month, especially in light of indications of resurgent Akira ransomware activity from late July 2025. SonicWall later disclosed that the SSL VPN activity targeting its firewalls was caused by a security hole that had existed for a year (CVE-2024-40766, CVSS score: 9.3), in which local user passwords were not reset after the migration. According to the business, we are seeing a rise in threat activity from actors trying to brute-force user credentials. Customers should make sure Account Lockout policies are activated and enable Botnet Filtering...