Tag: SonicWall SSL VPN

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers
News

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers

SonicWall devices are still being targeted by threat actors connected to the Akira ransomware group in order to get initial access. According to cybersecurity company Rapid7, SonicWall appliance invasions have increased within the previous month, especially in light of indications of resurgent Akira ransomware activity from late July 2025. SonicWall later disclosed that the SSL VPN activity targeting its firewalls was caused by a security hole that had existed for a year (CVE-2024-40766, CVSS score: 9.3), in which local user passwords were not reset after the migration. According to the business, we are seeing a rise in threat activity from actors trying to brute-force user credentials. Customers should make sure Account Lockout policies are activated and enable Botnet Filtering...
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices
News

Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices

Akira ransomware attacks have targeted SonicWall SSL VPN devices as part of a recent spike in activity noted in late July 2025. Julian Tuin, a researcher at Arctic Wolf Labs, reported that several pre-ransomware intrusions were detected in a brief period of time among the intrusions examined, all of which used VPN connection using SonicWall SSL VPNs. Given that some of the events included fully-patched SonicWall devices, the cybersecurity firm hypothesized that the assaults might be taking use of a zero-day vulnerability—a security fault in the appliances that has not yet been identified. Credential-based assaults for initial access haven't been completely ruled out, though. Although Arctic Wolf said that it has seen similar malicious VPN logins as early as October 2024, the spik...