Akira ransomware crims abusing trifecta of SonicWall security holes for extortion attacks
ID: f4e71c46-ca61-5f02-83b7-b7d6dc7e1a50
STIX ID: report--f4e71c46-ca61-5f02-83b7-b7d6dc7e1a50
Feed Name: The Register (Security)
Affiliates of the Akira ransomware group are actively exploiting the critical SonicWall CVE-2024-40766 and SSLVPN misconfigurations to gain initial access and deploy ransomware; the flaw (CVSS 9.8) was previously disclosed but remains widely exploitable, with security firms reporting confirmed compromises and hundreds of thousands of SonicWall devices publicly accessible. Rapid7, ThreatLocker, Arctic Wolf and others advise applying patches, enabling MFA, and restricting access to SonicWall Virtual Office to prevent further incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
