SonicWall urges customers to take VPN devices offline after ransomware campaign
ID: 41dfd483-1228-5bfc-8226-dbda31cf1a07
STIX ID: report--41dfd483-1228-5bfc-8226-dbda31cf1a07
Feed Name: The Record from Recorded Future News
### Executive summary Multiple incident response firms have observed a wave of intrusions targeting SonicWall Gen 7 SSL VPN appliances that appear to leverage a likely zero-day to gain access and deploy Akira ransomware; roughly 20–40 incidents were reported with evidence of MFA bypass, credential theft, lateral movement, and ransomware deployment, and SonicWall is investigating while advising customers to disable SSL VPN until mitigations or patches are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
